
Staff Engineer- Network Security & Attack Path Intelligence
Safe Security1 month ago
Bengaluru, IndiaStaff+
Responsibilities
- Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths.
- Build production-quality systems for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation.
- Derive effective connectivity from routing, VLAN, ACL, firewall, NAT, VPN, proxy, load-balancer, and segmentation configurations.
- Model attacker movement involving exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and critical assets.
- Prioritize reachable, exploitable, and business-critical attack paths using exploitability, control effectiveness, asset criticality, and business impact.
- Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
- Build vendor-neutral countermeasure intelligence for segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls.
- Partner with AI, graph, product, backend, data, and platform teams to deliver explainable attack-path analysis and recommendations.
- Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks for safe countermeasure testing.
- Mentor backend, graph, security, and platform engineers through architecture, code reviews, prototypes, and complex security decisions.
Requirements
- 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a record of shipping production systems.
- Strong hands-on programming experience in Python, Go, Java, or a similar backend language.
- Recent experience writing and shipping production-quality software rather than providing only architectural or advisory guidance.
- Strong system-design, API-design, data-modeling, and distributed-systems fundamentals.
- Experience implementing graph traversal, rule processing, network automation, configuration analysis, or security analytics.
- Familiarity with graph databases and graph-processing technologies.
- Deep understanding of enterprise on-premises, cloud, and hybrid networks, including routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation.
- Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, lateral movement, attack graphs, attack-path analysis, threat modeling, breach simulation, or exposure chaining.
- Experience translating security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.
- Preferred experience with attack-path, network digital-twin, microsegmentation, or CTEM products and large-scale graph computation.
- Preferred experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, Pentera, AttackIQ, Picus, or Horizon3.ai.
- Preferred experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, AWS, Azure, or GCP networking.
- Background spanning offensive and defensive security, including safe validation of controls in production-like environments.
- Experience with large, complex, and highly regulated enterprises is preferred.
- Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC are preferred.
- Published research, patents, open-source contributions, or previous technical leadership in security-product engineering are strong pluses.
Benefits
- Meaningful equity for every employee.
- Unlimited leave.
- Comprehensive medical insurance and wellness benefits.
- Career advancement opportunities in a rapidly growing company.