Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Horizon3 is seeking an AI Researcher to build autonomous agents that translate proven attack paths into concrete defender actions across production environments. You will work on systems that reason from telemetry to specific control changes, with real outcome signals from pentests and deployments.
You will design the safety and governance layers for autonomous changes, ensure changes are auditable, and collaborate with attack engineers and detection teams to learn from failures and improve
Hands‑on experience with at least one of: post-training large language models (supervised fine-tuning, distillation, preference optimization, RL), or designing agentic systems with tool use, planning, and long-horizon execution that hold up outside a demoA track record of building evaluation systems for open-ended tasks where there is no clean label and success is judged by outcomeStrong ML engineering experience building, evaluating, and deploying production AI systems, with hands‑on work in deep learning, transformer models, and PyTorchAbility to independently research unfamiliar systems and rapidly become the team’s expertStrong written and verbal communication, including clear technical documentationExperience with data pipelines, distributed systems, and cloud infrastructure, preferably AWSExperience reasoning over structured, heterogeneous, messy real‑world data — configurations, graphs, logs, policy documents — rather than clean benchmark datasetsStrong software engineering fundamentals and a track record of shipping and maintaining production-quality code in Python, not just scripts and proofs of conceptAbility to work across model behavior, APIs, and infrastructure, and to collaborate closely with attack engineers, detection engineers, product, and infrastructureMaster’s in Computer Science, Machine Learning, or a related field, or equivalent practical experience, plus 4+ years of professional engineering experienceYou do not need to have been a pentester or a SOC analyst. You do need to be seriously interested in how attackers and defenders actually operate, and willing to learn it in depth. The reasoning we are building cannot be designed by someone who does not understand the domainBackground in detection engineering, purple teaming, security engineering, offensive security, or incident responseHands‑on familiarity with security control planes and their APIs and policy models: EDR (CrowdStrike, SentinelOne, Defender), firewalls and segmentation (Palo Alto, Fortinet), identity and conditional access (Entra ID, Okta), SIEM and detection content (Splunk, Sentinel), cloud IAM, WAF, MDM, and GPOExperience with causal or counterfactual inference, or with graph reasoning, planning, and search over large state spaces. Familiarity with Neo4j and attack‑path analysisExperience building automation that takes write actions in production systems, along with the safety and change‑management machinery around itExperience with adversarial robustness or prompt injection, particularly where an agent consumes untrusted input from the environment it operates inExperience integrating ML into production, multi‑tenant SaaS, or running ML systems in customer‑controlled or air‑gapped environments