Skip to content
← Back to job listings

Staff Engineer- Network Security & Attack Path Intelligence

Safe Security · Bengaluru, India

Software DevelopmentLeadExternal listingfull-timeabout 2 hours ago

About The Role

Most boards and executives are currently flying blind when it comes to cyber risk. They are guessing. At Safe, we’ve built an AI-driven engine that finally gives the C-Suite a clear, quantified, and real-time view of their security posture. We don’t just provide data; we provide certainty.

We are a $170M Series C-funded category leader. We don’t play in the mid-market; we operate at the highest levels of global enterprise. Today, we are proud to serve 10% of the Fortune 500, protecting global icons such as Apple, Netflix, AT&T, Verizon, and Victoria’s Secret.

As we scale toward our next chapter, we are looking for high-performers who want to do the best work of their careers at the intersection of AI and Cybersecurity.

The Culture Memo: Our Operating System

Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.

Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.

The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.

Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.

Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.

The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.

The Perks & Ownership

We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.

Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.

Unlimited Leaves: We don’t believe in clock-watching. We offer unlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.

Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.

Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.

As a Staff Engineer – Network Security & Attack Path Intelligence, you will define and lead the technical direction of Safe’s network reachability and attack-path intelligence capabilities across on-premises, cloud, and hybrid environments.

You will be the hands-on architect behind systems that connect network topology, identities, vulnerabilities, security controls, and business-critical assets to determine how attackers can move through an enterprise environment.

You’ll collaborate with product, backend, graph, data, AI, and platform teams to build scalable, explainable, and enterprise-ready attack-path capabilities.

This is a high-impact, hands-on technical leadership role. You will architect systems, build prototypes, write production-quality code, and help shape how Safe’s CTEM platform identifies and breaks the attack paths that pose the greatest business risk.

Core Responsibilities

  • Architect Safe’s Attack Path Intelligence: Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths across complex enterprise environments.
  • Build Core Attack Path Capabilities: Write production-quality code for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation. Build prototypes and evolve them into reliable, enterprise-scale services.
  • Model Effective Network Reachability: Derive actual connectivity from routing tables, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and segmentation policies rather than relying only on documented topology.
  • Model Attacker Movement: Build reasoning systems that connect exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and access to critical assets.
  • Prioritize Actionable Attack Paths: Distinguish theoretical paths from reachable, exploitable, and business-critical attack paths. Incorporate exploitability, control effectiveness, asset criticality, and business impact into prioritization.
  • Enterprise Security Integrations: Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
  • Countermeasure Intelligence: Build a vendor-neutral model for recommending segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls. Define validation, approval, safety, and rollback requirements.
  • AI and Graph Integration: Partner with other engineers to ensure attack-path explanations and countermeasure recommendations are evidence-backed, explainable, technically accurate, and governed through deterministic safety policies.
  • Validation & Governance: Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks to verify attack paths and proposed countermeasures without introducing unacceptable operational risk.
  • Mentor & Multiply: Guide backend, graph, security, and platform engineers through architectural design, code reviews, prototypes, engineering standards, and complex security-domain decisions.

Minimum Qualifications

Experience: 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a strong record of building and shipping production systems.

Core Technical Skills

  • Strong hands-on programming experience in Python, Go, Java, or a similar backend language
  • Recent experience writing and shipping production-quality software—not only providing architectural or advisory guidance
  • Strong system-design, API-design, data-modeling, and distributed-systems fundamentals
  • Experience implementing graph traversal, rule-processing, network automation, configuration analysis, or security analytics
  • Ability to independently prototype complex ideas and evolve them into scalable production capabilities
  • Familiarity with graph databases and graph-processing technologies

Network Security

  • Deep understanding of enterprise on-premises, cloud, and hybrid networks
  • Strong knowledge of routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation
  • Experience deriving effective reachability across complex network configurations
  • Understanding of firewall-policy analysis, change validation, control effectiveness, and security misconfiguration detection

Attack Path & Identity Security

  • Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, and lateral movement
  • Experience with attack graphs, attack-path analysis, threat modelling, breach simulation, or exposure chaining
  • Ability to connect vulnerabilities and misconfigurations with network reachability and attacker behaviour
  • Familiarity with MITRE ATT&CK and common enterprise attack techniques

Product Engineering: Experience translating deep security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.

Preferred Qualifications

  • Experience building attack-path, network digital-twin, microsegmentation, or CTEM products
  • Experience with graph databases and large-scale graph computation
  • Experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, or similar technologies
  • Experience with Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, or comparable platforms
  • Experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, or other enterprise network-control technologies
  • Exposure to Pentera, AttackIQ, Picus, Horizon3.ai, or other security-validation platforms
  • Background spanning both offensive and defensive security
  • Experience safely validating security controls in production-like environments
  • Knowledge of AWS, Azure, or GCP networking
  • Experience working with large, complex, and highly regulated enterprises
  • Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC
  • Published research, patents, open-source contributions, or previous technical leadership in security-product engineering is a strong plus

This is an external listing. JobSpring does not represent or verify the employer. Report this listing