Horizon3.ai Logo

Horizon3.ai

Senior Detection Engineer (EDR), Autonomous Defense

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in US
195K-230K Annually
Senior level
Remote
Hiring Remotely in US
195K-230K Annually
Senior level
Own detection engineering domain expertise for EDR and endpoint platforms. Define detection, effectiveness, and tuning requirements; establish acceptance criteria; validate releases; and guide Product, Engineering, AI research, and Attack teams. Administer and tune production EDR systems, evaluate vendor policy semantics, maintain detection coverage, assess false positives and negatives, and define correct remediation recommendations. Use Python, SQL, APIs, and telemetry analysis to support technical decisions and documentation.
The summary above was generated by AI

Get to Know Us

Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. 

We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.

 

What You'll Do

We're hiring a Senior Detection Engineer to be the blue team voice inside the Defensive Agent team. You'll sit between Product and Engineering as the person who defines what "correct" means. When an attack technique is detected, you decide what remediation that claim requires. Your judgment becomes the ground truth.

This is not a coding role and it is not a product management role. Product owns the roadmap, Engineering owns the implementation, and our AI researchers own how the agents reason. You own the domain truth all three depend on, and you make it concrete enough to build and measure against. If you've spent your career being the person in the room who knows how the tools really behave, this is a seat where that knowledge teaches a system instead of firefighting alerts.

PRODUCT DIRECTION & REQUIREMENTS
  • Partner with Product to turn EDR effectiveness and tuning ambitions into concrete, buildable requirements.

  • Translate blue team workflows and pain into prioritized product outcomes, and push back when a proposed feature or agent behavior would not hold up in a real SOC.

  • Define acceptance criteria for detection, effectiveness, and tuning features, and validate releases against them before customers see them.

  • Serve as the standing domain reference for Engineering and AI research: available for design reviews, technique questions, and vendor behavior questions.

EDR & DETECTION DOMAIN OWNERSHIP
  • Own deep, current knowledge of the major EDR and endpoint platforms at the console, policy, telemetry, and API level.

  • Maintain fluency in how detection logic, prevention policy, exclusions, and tuning actually work in each product, including the differences between default and hardened configurations.

  • Define the vendor-specific policy semantics, so a recommended change means the same thing across platforms that model it differently.

  • Track platform changes, new detection capabilities, and vendor guidance, and keep our coverage model current as vendors ship.

  • Define what a correct tuning recommendation looks like and grade agent output against that standard.

  • Partner with the Attack team so technique coverage and detection expectations stay grounded in current adversary tradecraft.

WHAT YOU'LL BRINGEDR & BLUE TEAM EXPERTISE
  • 6+ years in detection engineering, security operations, incident response, or threat hunting, with meaningful time spent as a practitioner rather than an advisor.

  • Hands-on operational experience administering and tuning EDR platforms in production — writing detections, managing policy and exclusions, and investigating real alerts.

  • Deep understanding of what a SOC actually does with EDR output.

  • Fluency in false positive and false negative tradeoffs, alert fatigue, and detection coverage measurement.

  • Strong working knowledge of MITRE ATT&CK and detection coverage frameworks, and a clear view of where they help and where they mislead.

  • Solid understanding of post-compromise attacker behavior and how each surfaces in endpoint and identity telemetry.

PRODUCT & COLLABORATION
  • Demonstrated experience shaping a product or platform as a domain expert, whether in a security vendor, an internal tooling team, or a detection engineering function.

  • Ability to influence without authority. You will not manage the engineers or own the roadmap, and you will still be expected to move both.

  • Exceptional technical writing. Most of your leverage here comes from written artifacts — requirements, methodology docs, labeling guides, tuning content.

  • Comfort translating between audiences: engineers, AI researchers, product managers, SOC analysts, and executives.

TECHNICAL FLUENCY
  • Enough scripting ability, ideally Python, to query APIs, inspect telemetry, and prototype an analysis.

  • Comfort with SQL and with reasoning over large volumes of event and telemetry data.

 

Perks of Horizon3

  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.

  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.

  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.

  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.

  • Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.

Compensation and Values

At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.

In accordance with various State’s transparency regulations, we provide the following salary range information for this position:

  • Base salary range: $195,000-$230,000 annually. The exact salary will be determined based on the selected candidate’s location, qualifications, experience, and relevant skills.

  • Additional compensation: All full-time roles are eligible for an equity package in the form of stock options.

You Belong Here

Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, or any other legally protected status by law.

Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth.

We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice. 

Similar Jobs

6 Minutes Ago
In-Office or Remote
167K-238K Annually
Senior level
167K-238K Annually
Senior level
Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Provides strategic legal counsel to New York Life’s Absence Management business on leave administration, disability, paid family and medical leave, workplace accommodations, employee benefits, insurance, and related products. Advises on regulatory developments, product lifecycle, operations, marketing, client arrangements, risk mitigation, and commercial contracts. Partners with cross-functional stakeholders, drafts and negotiates agreements, supports product launches, and develops scalable legal guidance and processes.
6 Minutes Ago
In-Office or Remote
100K-143K Annually
Senior level
100K-143K Annually
Senior level
Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Own the wealth experience within NYL360 by translating advisor and stakeholder needs into prototypes, user stories, acceptance criteria, and sprint-ready backlogs. Coordinate with Design, Engineering, Data, Testing, and field teams; manage dependencies and delivery; support QA and user acceptance testing; document defects and resolutions; and contribute to releases, pilots, communications, and feedback loops. The role also requires applying AI tools and simplifying complex wealth and legacy-system workflows.
Top Skills: AgileAi ToolsJIRANyl360
10 Minutes Ago
Remote
United States
275K-440K Annually
Senior level
275K-440K Annually
Senior level
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Lead Toast’s product and platform security organization, overseeing security platform engineering, application and cloud security, secure development practices, offensive security, vulnerability management, hardware security, and developer enablement. Partner with product and engineering leaders to establish secure defaults and scalable guardrails while reducing developer friction. Manage and grow a multi-team security engineering organization, expand security champions and tooling adoption, and align security posture with business and product priorities.
Top Skills: AIApplication SecurityAutomationCi/CdCloud SecurityCloud-Native SecurityContainersDetection EngineeringHardware SecurityInfrastructure As CodeMicroservicesPenetration TestingPurple TeamingRed TeamingSecure Development LifecycleSoftware Supply Chain SecurityThreat ModelingVulnerability Management

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account