Senior Manager of Attack Engineering
Horizon3 · United States
About The Role
Join our team as a Senior Manager of Attack Engineering, where you will lead our External Attack Engineering organization. You will oversee a team responsible for designing, validating, and scaling offensive capabilities within the NodeZero platform. This role requires a strong mix of technical depth, leadership experience, and a product mindset. You will set technical direction, priorities, and quality standards for external offensive capabilities, mentor engineers, and drive hiring and organizational scaling. Additionally, you will own the offensive strategy across various platforms and guide the development of end-to-end attack methodologies.
- Lead and grow a team of Attack and Full-Stack Engineers specializing in the External Attack Surface, including Commercial and SaaS platforms.
- Set technical direction, priorities, and quality standards for external offensive capabilities, and drive hiring and organizational scaling as the External Attack team expands.
- Own offensive strategy across external and public-facing platforms and infrastructure, and guide the development of end-to-end attack methodologies.
- 5+ years leading offensive security, red team, or attack engineering teams
- Proven ability to balance hands-on technical depth with strategic leadership
- Experience managing teams of 6–10+ engineers and scaling organizations
- Ability to chain attack paths end-to-end and clearly explain impact
- External/Public-facing infrastructure attack surfaces
- Complex multi-platform attack scenarios
- Enterprise SaaS platforms and externally-facing enterprise commercial software
- Deep understanding of:
- System-level compromise and lateral movement in externally-facing enterprise commercial software
- Common misconfigurations and exploitation paths in external platforms
- Identity and access abuse across diverse ecosystems
- Strong expertise in one or more:
- Strong background in software engineering (Python preferred). Experience with APIs, cloud automation, and infrastructure tooling
- Familiarity with CI/CD and infrastructure-as-code (Terraform, CloudFormation, etc.)
- Comfortable working with Git, MR workflows, and product development cycles
- Customer-first mindset with focus on real-world impact
- Strong communication skills across technical and non-technical audiences
- Experience translating offensive findings into product capabilities
- Experience across diverse environments, including cloud infrastructure, enterprise SaaS, and externally-facing enterprise commercial software
- Familiarity with AI/LLM systems and associated attack surfaces
- Experience in security tooling, red teaming, or offensive engineering products
- Relevant security certifications (e.g., OSCP, cloud or SaaS security) are a plus
- Public research, blogs, or open-source contributions related to external attack surfaces
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring