Horizon3 Hit $2B on "AI vs AI." The Real Offensive-ML Pool Is 2.
Horizon3's $250M Series E needs offensive security plus ML engineers in four cities. Refolk's index shows 2 identified profiles in the US, 0 in EMEA/APAC.
On August 3, 2026, Horizon3 announced a $250M Series E at a $2B+ valuation and told the press the story was "AI vs AI." What the press release did not say: the specific hybrid engineer who can actually build that product, someone who reads exploits and model weights with equal fluency, barely exists as a searchable population. If you are staffing this hire in San Francisco, Amsterdam, Sydney, or Singapore, you are not competing for talent so much as manufacturing it.
What Horizon3 actually announced on August 3
Horizon3 raised a $250M Series E at a valuation north of $2B, roughly triple its $650M Series D from a year earlier, on 120% YoY growth approaching $100M ARR. The round was co-led by NightDragon and NEA, oversubscribed, and pulled in seven new investors including Acrew, Blue Cloud, Demeter, Singapore's EDBI, PSG, SAIC, and Sapphire Ventures. NodeZero, the autonomous pentest platform behind the ARR curve, now protects more than 7,200 organizations.
The hiring implication landed in the same announcement. Horizon3 opened an Amsterdam EMEA HQ in June 2026 and is standing up offices in Australia and Singapore. Per Horizon3's public company profile on Crustdata, roughly 22 reqs are live, with 73% in the US.
- 16 open reqs in the US, mostly engineering
- 4 open reqs in Singapore, mostly engineering
- 1 in the Netherlands, operations
- 1 in Italy, engineering
The named requisitions tell you what "AI vs AI" means in practice: "WebApp Offensive Security Engineer" and "Staff Attack Engineer, OCI." Both are offensive security first, but the product they build is a machine that reasons about attack surface at machine speed. You cannot ship that without engineers who hold both halves.
The pool of engineers who actually hold both halves
The precisely identified global pool of offensive security plus ML engineers is in the low single digits, not the low hundreds. In Refolk's index of professional profiles, a keyword search for "offensive security" combined with "machine learning" in the United States returns 2 people. The same search across the Netherlands, Australia, and Singapore, all three of Horizon3's new hubs, returns zero.
A stricter title-based search, "Red Team," "Offensive Security Engineer," or "Penetration Tester" combined with ML or AI keywords worldwide, returns 1.
| Segment | Identified profiles |
|---|---|
| Offensive-sec + ML keyword, United States | 2 |
| Offensive-sec + ML keyword, Netherlands + Australia + Singapore | 0 |
| Red Team / Pentester title + ML/AI keyword, global | 1 |
| Horizon3 open engineering-heavy reqs, US | 16 |
| Horizon3 open engineering-heavy reqs, Singapore | 4 |
| Ratio: US reqs to identified US hybrid candidates | 8:1 |
Both US matches sit in the SF Bay Area, one at Oracle and one at a stealth post-LLM startup. Neither is likely to move without a compelling reason, and both are already inside a 30-minute drive of Horizon3's San Francisco footprint. The mechanism is simple: the archetype requires two rare stacks fused in one head, not one rare stack, and the multiplicative rarity compounds fast.
Why "AI vs AI" hiring is a career-switch problem, not a graduate hire
The correct sourcing target is a 5 to 8 year OSCP-credentialed pentester with visible ML curiosity, not a new grad with an ML degree and a Hack The Box account. The reason is asymmetric: teaching an experienced offensive engineer MITRE ATLAS, PyRIT, and Garak takes months, while teaching an ML engineer to write reliable exploits against production infrastructure takes years. Horizon3 will lose the bidding war for the "already both" candidates. It can win the bidding war for the "offensive plus willing to learn model behavior" candidates.
The canonical example of the finished archetype is Will Pearce, who leads NVIDIA's AI Red Team and previously ran the Azure Trustworthy ML red team at Microsoft. Look at his career shape, then reverse-engineer earlier-stage versions: senior pentesters who started publishing on adversarial ML, OSCP holders with recent PyTorch commits, USENIX Security or IEEE S&P authors who pivoted from binary exploitation to model extraction.
Sourcing signals that actually work for this profile:
- HTB Certified Offensive AI Expert (COAE) on a profile that already has OSCP or OSEP
- Public commits to Garak, PyRIT, or Counterfit
- Talks at DEF CON AI Village or the NeurIPS AI Safety Workshop
- Papers at USENIX Security or IEEE S&P touching model extraction, prompt injection at the API layer, or ML supply chain
- Prior time at Microsoft AI red team, NVIDIA AI red team, Google's SAIF team, or HiddenLayer
These signals are what a recruiter should filter on before touching a keyword search. This is the exact gap Refolk closes: describe the person in plain English ("senior pentester with OSCP who has shipped Python ML tooling in the last 18 months"), get a ranked shortlist, skip the fifteen Boolean iterations.
The three new offices are net-new pool creation, not poaching
Horizon3's Amsterdam, Sydney, and Singapore offices are being planted in markets where the identified hybrid pool is zero, which means the international hiring plan is not competitive sourcing, it is pool construction. This changes the playbook.
Amsterdam
The Netherlands has strong offensive security depth via Fox-IT, EYE Security, and Northwave, plus academic ML strength at TU Delft and UvA. Neither side has meaningfully crossed over. The competing buyer is Mindgard, the UK-based automated AI red-teaming startup that is already fishing the same EMEA pond. Expect Horizon3 to relocate a US veteran to seed Amsterdam, then hire two adjacent halves per pod: one Fox-IT alum and one TU Delft ML PhD, pair-trained on NodeZero internals.
Singapore
Singapore's EDBI is a strategic investor in this round, which is not accidental. EDBI opens doors to DSTA and CSIT alumni networks, where offensive security veterans are concentrated. The identified public hybrid pool is zero, but the actual pool sits inside defense agencies with no public footprint. Autonomous pentest hiring in Singapore will run through personal introductions and defense-industry references, not job boards.
Australia
ASD (Australian Signals Directorate) alumni are the equivalent lever. Look at Penten, archTIS, and Internet 2.0 as feeder companies. The Australian ML research community around CSIRO Data61 and UNSW is where the second half of the archetype lives. Same pattern: two halves, paired, trained internally on the third skill (product engineering at NodeZero cadence).
Who Horizon3 is actually competing with on comp
Horizon3's Amsterdam and Singapore comp bands will need to clear NVIDIA, Microsoft, HiddenLayer, and 10a Labs, not local cybersecurity market norms. AI Career Finder puts AI Red Team Specialist salaries at $130K to $220K with demand growing 55% year over year, and director or CISO-level AI-security roles are clearing $250K to $500K+ at major companies. HiddenLayer is advertising fully remote mid-level LLM security roles at $125K to $150K, which sets the floor for remote EMEA and APAC bids.
The World Economic Forum says only 14% of organizations believe they have the AI security talent they need. Horizon3 just told the market it needs more of it than anyone.
The practical implication: local salary benchmarks in Amsterdam and Singapore are irrelevant. The comparable is the remote-US offer the same candidate can take from HiddenLayer or NVIDIA the following week. Underwrite that number or lose the hire.
A sourcing playbook that does not depend on keyword search
Stop searching for the combined title. It does not exist at scale, and the two people who use it are already in someone else's pipeline. The working playbook has five steps.
- Source the two halves separately, then filter for crossover. Pull senior offensive security engineers with OSCP, OSEP, or CRTO. Pull ML engineers with published adversarial ML work. Intersect on public commits and conference activity.
- Prioritize the conference circuit over job boards. DEF CON AI Village speaker lists, NeurIPS AI Safety Workshop authors, USENIX Security and IEEE S&P AI-adjacent papers. This is where the archetype publishes before it updates a title.
- Read commit graphs, not resumes. Contributions to Garak, PyRIT, Counterfit, ART, and TextAttack are the strongest live signal.
- Target defense adjacency in Singapore and Australia. DSTA, CSIT, ASD, DSTG. Use investor introductions where available.
- Underwrite career-switch candidates. The best hire is a senior pentester who has been quietly shipping ML side projects for 18 months. Build the internal MITRE ATLAS and PyRIT ramp so this person is productive on NodeZero within 90 days.
For step 3, being able to ask in plain English ("engineers who committed to Garak or PyRIT in the last year and hold OSCP or OSEP") is faster than any Boolean, which is where Refolk shortens the loop. Defense-adjacent candidates in step 4 rarely surface with keyword search either, but they surface reliably when the query describes the person rather than the title.
What to do this quarter if you are staffing against Horizon3
If you are hiring for the same archetype as Horizon3, do three things this quarter. First, stop competing on the two US profiles that match the exact keyword; you will lose to a $2B-valuation counteroffer. Second, build a target list of 40 to 60 senior pentesters who have shipped any ML tooling in the last 18 months and start relationship-first outreach now, before the Amsterdam and Singapore offices publish specific reqs. Third, budget for pair-hiring: one offensive senior plus one ML senior per pod, with a defined 90-day cross-training plan built around MITRE ATLAS, PyRIT, and Garak.
The companies that treat this as a career-switch problem will staff. The companies that keep searching for "offensive security ML engineer" as a title will still be searching in Q1.
FAQ
How small is the offensive security plus ML talent pool globally?
In Refolk's index, a keyword search combining "offensive security" and "machine learning" returns 2 identified profiles in the United States and zero across the Netherlands, Australia, and Singapore combined. A stricter title-based search across "Red Team," "Offensive Security Engineer," or "Penetration Tester" plus ML or AI keywords globally returns 1. The precisely identified pool is in the low single digits, though the practical pool once you include career-switch candidates with the right adjacencies is materially larger.
Where should I source AI red team candidates for Horizon3's new EMEA and APAC offices?
Defense-adjacent talent, not tech-industry talent. For Amsterdam, look at Fox-IT, EYE Security, and Northwave for offensive depth, and TU Delft or UvA for the ML half. For Singapore, DSTA and CSIT alumni networks, with EDBI (a new Horizon3 investor) as an introduction lever. For Australia, ASD, DSTG, Penten, archTIS, and Internet 2.0 for offensive, and CSIRO Data61 and UNSW for ML. Expect to pair-hire and cross-train.
What comp bands should I plan for AI red team hires in 2026?
AI Red Team Specialist salaries run $130K to $220K per AI Career Finder, growing 55% year over year, with director and CISO-level AI-security roles at $250K to $500K+. HiddenLayer sets a remote mid-level floor at $125K to $150K. Local market norms in Amsterdam or Singapore do not apply because the comparable is the remote-US offer the same candidate can take from NVIDIA, Microsoft, or HiddenLayer.
What are the strongest sourcing signals for the offensive-ML hybrid?
Public commits to Garak, PyRIT, Counterfit, ART, or TextAttack; OSCP or OSEP combined with recent Python ML activity; talks at DEF CON AI Village or the NeurIPS AI Safety Workshop; papers at USENIX Security or IEEE S&P on model extraction or prompt injection at the API layer; prior time at Microsoft AI red team, NVIDIA AI red team, Google SAIF, or HiddenLayer. HTB's Certified Offensive AI Expert stacked on an OSCP profile is a strong training-path signal for career-switch candidates.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.