First, the name, because “horizon” is crowded. This is Horizon3.ai, the cybersecurity company founded in 2019 by Snehal Antani and Anthony Pillitiere, who met at Joint Special Operations Command, where Antani was CTO. It is not Horizon Robotics, the Chinese self-driving chip maker. It is not Meta’s Horizon VR platform, and not Horizon Media the ad agency. The “3” is part of the company name, not a version number. Everything below is about the autonomous-pentesting company.
What Horizon3 sells matters more than the funding headline, so start there. NodeZero is an “AI hacker”: a SaaS platform that a customer points at its own live network, and that then chains together weak credentials, misconfigurations, and identity gaps into a real, working attack path, the same sequence an actual attacker would walk. It runs agentless, it is meant to be safe against production, and after it finds a path it tells you what to fix first and reruns to confirm the hole is closed. The “AI hacker” label is marketing shorthand: Horizon3 hasn’t publicly detailed the internals, so read it as automated attack-path planning and orchestration over a large library of offensive tools, not a single large language model. The company says it serves roughly 7,200 customers, from managed service providers up to Fortune 10 enterprises, and it approached $100M in ARR with 120% year-over-year growth before the Series E.
That product shapes the interview. Where a company like Vanta sits on the defensive, compliance-automation side of security, Horizon3 is offensive: the code you write is the attacker. If you want to see where it lands next to other security and infrastructure startups, the AI-native company interview guides hub and the AI-startup interview difficulty index are the right context.
The funding, and why it changes the questions
In August 2026 Horizon3 raised a $250M Series E at a $2B+ valuation, co-led by returning investors NightDragon and NEA, roughly tripling where the company sat 14 months earlier. For a candidate, the money means the bar is real and hiring should expand across security research and backend roles, because the product runs unsupervised inside other companies’ production networks. A bug here is either a missed attack path (the customer thinks they are safe when they are not) or a tool that misbehaves against live infrastructure. That risk profile is what the interview is trying to screen for.
The interview loop (stages from Glassdoor, round content inferred)
Horizon3’s engineering loop is not published, and the public signal is thin. Glassdoor has about 22 interview reports across all job titles, and they skew toward sales and go-to-market roles, so engineering-specific detail is limited. One Senior Software Engineer report outlines a four-stage loop, and that outline is what the table below uses. The order and, especially, what each round actually covers are inferred from NodeZero’s problem domain and from how comparable offensive-security and infrastructure loops tend to run. Glassdoor’s aggregate puts overall difficulty around 3.2 out of 5, with most candidates describing the people as friendly.
| Stage | Likely format | What it likely screens for |
|---|---|---|
| Recruiter screen | Call on background, security interest, comp expectations | Motivation for offensive security; level and location fit (remote-first) |
| Technical round | Discussion of your past systems plus live problem-solving | Depth in networking, auth, or the language you claim; how you reason about failure |
| Hiring-manager round | Team fit, ownership, how you handle ambiguity and risk | Judgment when a mistake hits a customer’s production network |
| Technical assessment | Take-home or live build, practical over puzzle | Working, tested code; edge-case handling; clean data manipulation |
The technical round: know how attacks actually chain
The strongest thing you can bring to Horizon3’s technical round is fluency in how a real intrusion moves, because that is the product. NodeZero goes well past scanning for CVEs; it strings small weaknesses into an attack path. Be ready to reason about the moves it automates, and know what they are: credential attacks and password spraying (guessing or reusing passwords at scale), Active Directory and identity abuse such as Kerberoasting (cracking a service account’s password from its Kerberos ticket) and pass-the-hash (authenticating with a stolen password hash instead of the password), over-permissioned service accounts (machine accounts holding far more access than they need), lateral movement (hopping host to host once inside), and privilege escalation (turning a low-level foothold into admin). The throughline is how one exposed secret or misconfigured share becomes domain-wide compromise. If none of that is familiar, the public MITRE ATT&CK knowledge base is the standard reference for these techniques and how attackers chain them.
You do not need to be a red-teamer to pass, but you should be able to hold a real conversation about one attack chain end to end: what the initial foothold is, what the attacker learns from it, and how they pivot. Engineers here build the automation that reproduces that reasoning at scale, so an interviewer will care whether you understand the domain, well beyond whether you can invert a binary tree. If your data-structures and problem-solving reflexes are rusty, refresh the coding patterns cheat sheet before the round, but spend most of your time on the security substance.
Language-wise, offensive tooling and high-throughput backends often lean on Go for concurrency, so if a role names it, the Go interview questions refresher is worth a pass; Python shows up heavily on the automation and tooling side. Match your prep to the job description rather than guessing.
The system-design and assessment angle: safe automation in someone else’s prod
The most Horizon3-specific design question is the one built into the product: how do you run hundreds of offensive tools autonomously inside a customer’s live network without breaking it? Good answers treat blast-radius control as a first-class requirement, not an afterthought. Think about rate limiting and safety checks so a test does not knock over a fragile production box (the same rate limiter design problem that shows up in system-design rounds), idempotency so a rerun does not double-execute a destructive action, sandboxing and permission scoping, and a clear audit trail of exactly what was run where.
The second design theme is the attack-path graph itself. Chaining weaknesses is naturally a graph problem: nodes are hosts, credentials, and privileges; edges are the moves an attacker can make; and the output is the shortest or highest-impact path to something that matters. Prioritization is the hard part, since a customer with thousands of findings needs to know the handful of paths that actually lead to a breach. Being able to reason about graph traversal, weighting by impact, and how you keep that analysis current as the environment changes will land well. The broader system design interview guides cover the distributed-systems fundamentals underneath: queuing the work, storing results, and scaling the orchestration across thousands of customer environments.
For the take-home or live assessment, expect something practical rather than a competitive-programming puzzle: parse a messy scan result, model a small piece of the attack graph, or wire up a service that ingests and normalizes findings. Ship it with tests and sane handling of malformed input. The Glassdoor report did not say whether this stage is a take-home or a live session, so ask the recruiter which format it is and how long it runs, and prepare for that rather than guessing. Verifying remediation, rerunning a test to confirm a path is closed, is central to how NodeZero works, so an assessment that touches “did the fix actually work” would fit.
Compensation: no public engineering bands, so model the whole offer
Horizon3 is remote-first, and it does not post engineering salary ranges on a public board that I could verify, so treat any specific figure floating around Glassdoor or aggregator sites as noise rather than a quote. What you can reason about: this is a well-funded, roughly $2B private company past $100M ARR, which usually means competitive base plus meaningful equity, and the equity is where the real number lives at a company that just tripled its valuation. Model the full package, not the base, with the total-comp calculator, and go into the conversation with a plan from the salary negotiation guide. Because it repriced so recently, the strike price on your options and the current 409A matter more to your outcome than a small base difference. Some roles touch government and defense customers, so ask early whether a given position carries any US-person or clearance requirement. Horizon3 describes itself as remote-first with teammates around the globe, so distributed work is the norm, but it does not state publicly whether it sponsors work visas, so raise that with the recruiter up front too.
How to prep in a week
Budget by how much time you actually have. With five to seven hours: put up to three into security fluency, walking one full attack chain out loud from foothold to domain compromise and learning the identity and credential weaknesses NodeZero automates; one into a design rehearsal of safe automation and the attack-path graph; one into a behavioral story about shipping something where a failure had real consequences, structured the way the STAR-method behavioral guide lays out; and at least half an hour on a coding warm-up even at the five-hour floor, since the technical round and the assessment both include working code; add more coding time first if you have it. If you are a senior with almost no time, do only the first and third of those: be ready to talk through one attack chain and one high-stakes shipping story, since the technical and hiring-manager rounds lean on judgment more than trivia. For a structured runway, the study plan generator will build one around these topics, and the full company interview guides library covers the security and infrastructure peers whose loops Horizon3’s most resembles.
One thing worth sitting with before you apply: the job is to build software that attacks other companies on purpose. The founders came out of Joint Special Operations Command, and the company leans on that attacker’s-eye framing, which is a great fit for people who think like an adversary and a poor one for people who want a quiet CRUD app. If the idea of your code breaking into a Fortune 10 network every night sounds thrilling rather than terrifying, this is the rare company where that is the whole point.
Practice the behavioral round:
