
Staff Attack Engineer – Internal/AD
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Act as the technical lead and primary subject matter expert for internal network and Active Directory attack capabilities across NodeZero.
• Investigate emerging AD and internal tradecraft and convert it into production attack content.
• Design, construct, and maintain production-grade Python applications to enable safe, enterprise-scale capabilities.
• Create attacks tailored for modern hardened environments where traditional methods are restricted.
• Set up, configure, and exploit representative AD test environments for validation, demonstration, and regression testing.
• Enhance attack-path modeling and graph data models for identity, privilege escalation, and lateral movement paths.
• Establish priorities and a coverage roadmap informed by customer environments, threat intelligence, and emerging techniques.
• Mentor and develop attack engineers.
• Elevate standards for code quality, research rigor, and operational safety.
• Collaborate with engineers, product managers, and customer-facing teams.
• Create internal documentation, external research materials, and blog posts.
• Extensive hands-on offensive experience against Active Directory and internal enterprise networks, from initial foothold to domain and enterprise compromise.
• Proficient understanding of current AD tradecraft, including credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, lateral movement, and persistence.
• Proven experience conducting attacks in modern, hardened environments, including NTLM deprecation, enforced signing, Kerberos-only, and tiered administration.
• Expert-level Python programming skills and a solid foundation in software engineering principles.
• History of delivering and maintaining production-quality code.
• Capability to independently investigate unfamiliar systems and technologies.
• Proven track record of technical leadership, setting direction, managing high-complexity and high-risk projects, and mentoring engineers.
• Strong written and verbal communication skills, including the ability to produce technical documentation.
• Enthusiasm for product development beyond merely identifying vulnerabilities.
• Over 8 years of combined offensive security and/or software engineering experience, with a significant focus on Active Directory and internal network attacks.
• OSCP, OSEP, CRTO, or equivalent offensive certification is preferred.
• Familiarity with SCCM, Windows Admin Center, and modern Windows management-plane attack surfaces is preferred.
• Experience with hybrid identity attacks, including Entra ID, Entra Connect, primary refresh tokens, seamless SSO, and on-premises-to-cloud pivots is preferred.
• Background in developing or contributing to BloodHound, Impacket, netexec, or similar offensive tools is preferred.
• Knowledge of Neo4j and attack-path analysis is preferred.
• Experience integrating security research into production, multi-tenant SaaS is preferred.
• Public contributions such as open-source tools, technical blog posts, conference talks, or published CVEs are preferred.
• Experience in building production-safe autonomous or automated offensive tools is preferred.
• Must be legally authorized to work in the United States.
• Must not require employment visa sponsorship now or in the future.
• Equity package in the form of stock options for all full-time positions.
• Health, vision, and dental insurance for you and your family.
• Flexible vacation policy.
• Generous parental leave.
• Opportunities for career development.
• An inclusive and collaborative culture.
• Remote and hybrid work models available based on role and location.
• Up to 10% travel required.
Dura Digital
Expleo Group
Stannah Group
Get handpicked remote jobs straight to your inbox weekly.