Applied AI Engineer (Autonomous Defense)

Horizon3

United States

Remote

USD 140,000 - 210,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Growth opportunities
Innovation-driven culture
Flexible work environment
Inclusive and Diverse Team

Job summary

Horizon3 is seeking an AI Researcher to build autonomous agents that translate proven attack paths into concrete defender actions across production environments. You will work on systems that reason from telemetry to specific control changes, with real outcome signals from pentests and deployments.

You will design the safety and governance layers for autonomous changes, ensure changes are auditable, and collaborate with attack engineers and detection teams to learn from failures and improve

Qualifications

  • Master’s degree in CS/ML or related field with 4+ years of engineering experience.
  • Strong ML/AI background with production-grade systems.
  • Experience with security-focused AI or incident response is a plus.

Responsibilities

  • Build agents that map attack paths to actionable control changes in production environments.
  • Design and run closed-loop defense systems at enterprise scale.
  • Collaborate with attack engineers and detection teams to diagnose failures and improve safety.
  • Develop the safety architecture for autonomous changes, including dry-run, rollback, and audit trails.

Skills

ML engineering
PyTorch
Deep learning
Python
Security engineering
Distributed systems
Cloud (AWS)
Graph reasoning
Offensive security
Counterfactual inference

Education

Master's in CS/ML or related field

Tools

Neo4j
AWS
Splunk

Job description


  • We’re looking for an AI Researcher to build the agents that turn our offensive knowledge into defensive action

  • You’ll build agents that reason from a proven attack path to the specific control changes that break it - EDR policy, firewall and segmentation rules, conditional access, detection content, cloud IAM, GPO - apply or stage those changes in the customer’s environment, and then prove the fix by re-running the attack

  • That last part is why this is tractable. Most defensive AI has no ground truth and gets graded on whether its advice sounds reasonable. Ours gets graded on whether the attack still works. You will have a real outcome signal on a short loop, and hundreds of thousands of prior tests to learn from. It is also why this is hard

  • These agents run inside customer tenants and modify production security controls. A bad change is an outage or a new hole in someone’s defense. The reasoning problem and the safety problem are the same problem here, and you will own both

  • The goal is closed-loop defense: find, fix, verify, running autonomously at enterprise scale. If you want to work on agents where the feedback is real and the stakes are real, this is the job for you

  • Build the reasoning systems that map proven attack paths and exploitation telemetry to specific, applicable control changes, ranked by effectiveness against operational blast radius

  • Turn our pentest data into training and evaluation data. Extract the signal of why an attack succeeded in one environment and failed in another

  • Design and run counterfactual experiments in representative test environments: would this change have broken this attack chain, what does it cost operationally, and does it generalize beyond the tenant it was learned in

  • Design the reasoning layer over heterogeneous control planes so an agent can work across vendor APIs with different policy models without a hardcoded playbook per product

  • Design the safety architecture for autonomous change — dry-run and simulation, blast-radius classification, approval gates for high-impact actions, staged rollout, rollback, and an audit trail a customer’s change board will accept

  • Work with our attack engineers and detection engineers to define target agent behavior and diagnose failure modes: ineffective remediations, over-broad changes, business-breaking policy edits, and recommendations that look right and don’t hold on re-test

  • Own problems end to end in a 0→1 environment where requirements are ambiguous, systems move fast, and reliability matters, because the output lands in someone’s production security posture


Benefits


  • Growth Opportunities: Be part of a dynamic and growing team with numerous career advancement opportunities

  • Innovation-Driven Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking

  • Flexible Work Environment: Enjoy the convenience and work-life balance that comes with remote work

  • Inclusive and Diverse Team: We value diversity and promote an inclusive culture where everyone can thrive


Hands‑on experience with at least one of: post-training large language models (supervised fine-tuning, distillation, preference optimization, RL), or designing agentic systems with tool use, planning, and long-horizon execution that hold up outside a demoA track record of building evaluation systems for open-ended tasks where there is no clean label and success is judged by outcomeStrong ML engineering experience building, evaluating, and deploying production AI systems, with hands‑on work in deep learning, transformer models, and PyTorchAbility to independently research unfamiliar systems and rapidly become the team’s expertStrong written and verbal communication, including clear technical documentationExperience with data pipelines, distributed systems, and cloud infrastructure, preferably AWSExperience reasoning over structured, heterogeneous, messy real‑world data — configurations, graphs, logs, policy documents — rather than clean benchmark datasetsStrong software engineering fundamentals and a track record of shipping and maintaining production-quality code in Python, not just scripts and proofs of conceptAbility to work across model behavior, APIs, and infrastructure, and to collaborate closely with attack engineers, detection engineers, product, and infrastructureMaster’s in Computer Science, Machine Learning, or a related field, or equivalent practical experience, plus 4+ years of professional engineering experienceYou do not need to have been a pentester or a SOC analyst. You do need to be seriously interested in how attackers and defenders actually operate, and willing to learn it in depth. The reasoning we are building cannot be designed by someone who does not understand the domainBackground in detection engineering, purple teaming, security engineering, offensive security, or incident responseHands‑on familiarity with security control planes and their APIs and policy models: EDR (CrowdStrike, SentinelOne, Defender), firewalls and segmentation (Palo Alto, Fortinet), identity and conditional access (Entra ID, Okta), SIEM and detection content (Splunk, Sentinel), cloud IAM, WAF, MDM, and GPOExperience with causal or counterfactual inference, or with graph reasoning, planning, and search over large state spaces. Familiarity with Neo4j and attack‑path analysisExperience building automation that takes write actions in production systems, along with the safety and change‑management machinery around itExperience with adversarial robustness or prompt injection, particularly where an agent consumes untrusted input from the environment it operates inExperience integrating ML into production, multi‑tenant SaaS, or running ML systems in customer‑controlled or air‑gapped environments


Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Infrastructure Engineer
Infrastructure Engineer

Aegis AI Security • United States

On-site
USD 180,000 - 240,000
AI Defense Architect: Real-Time Threat Detection
AI Defense Architect: Real-Time Threat Detection

Foundation Capital • San Francisco (CA)

On-site
USD 120,000 - 160,000
AI Engineer - SF
AI Engineer - SF

Aegis AI • San Francisco (CA)

On-site
USD 150,000 - 200,000
AI Security Infrastructure Engineer
AI Security Infrastructure Engineer

Foundation Capital • San Francisco (CA)

On-site
USD 130,000 - 180,000
AI Engineer - NYC
AI Engineer - NYC

Aegis AI • New York (NY)

On-site
USD 150,000 - 220,000
Infrastructure Engineer
Infrastructure Engineer

Aegis AI Security • San Francisco (CA)

On-site
USD 180,000 - 280,000
Infrastructure Engineer
Infrastructure Engineer

Aegis AI Security • New York (NY)

On-site
USD 140,000 - 230,000
AI Security Engineer - Adversarial AI & Threat Detection
AI Security Engineer - Adversarial AI & Threat Detection

Foundation Capital • San Francisco (CA)

On-site
USD 150,000 - 210,000
AI Security Engineer: Real-Time Threat Detection
AI Security Engineer: Real-Time Threat Detection

Foundation Capital • New York (NY)

On-site
USD 150,000 - 210,000
Applied AI Engineer, Autonomous Defense
Applied AI Engineer, Autonomous Defense

NightDragon Acquisition Corp. • United States

On-site
USD 313,000 - 369,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2