Staff Engineer- Network Security & Attack Path Intelligence
Job description
About the role
Safe is on the lookout for a seasoned technical expert to lead the design and development of systems that effectively map attack paths within intricate hybrid, cloud, and on-premises infrastructures. This role involves spearheading the advancement of our Cyber Threat Exposure Management (CTEM) platform by integrating network topology, identity, and vulnerability information to deliver actionable risk intelligence to enterprises worldwide.
Key facts
What you'll do
- Design and establish the architecture and data models necessary for analyzing network reachability, defining trust boundaries, and constructing attack paths.
- Create robust production services that handle the parsing of network configurations, calculate blast radii, and execute graph traversal operations.
- Examine real-world connectivity by analyzing routing tables, firewalls, load balancers, and segmentation policies to ensure accurate data representation.
- Develop reasoning engines that simulate attacker behaviors, including lateral movements, privilege escalation, and credential exposure scenarios.
- Formulate vendor-agnostic models that provide recommendations for enhancing security controls and improving segmentation strategies.
- Integrate the CTEM platform with essential enterprise tools such as Endpoint Detection and Response (EDR), Configuration Management Database (CMDB), Active Directory, and various firewall solutions.
- Set up validation frameworks and simulation environments to confirm attack paths without disrupting operational stability.
- Provide mentorship to engineering teams, sharing expertise in security domains, architectural best practices, and the design of complex systems.
Requirements
- A minimum of 12 years of experience in software engineering, security product development, or exposure management is essential.
- Strong programming skills in Python, Go, or Java, with a proven history of delivering production-ready software solutions.
- Extensive experience in system design, API architecture, and distributed systems is required.
- In-depth understanding of network security concepts, including VLANs, Access Control Lists (ACLs), Network Address Translation (NAT), Virtual Private Networks (VPNs), and proxy configurations.
- Familiarity with identity-based attack vectors, particularly those involving Active Directory, Kerberos, and privilege escalation techniques.
- Experience in implementing graph-based analytics or automating security processes is highly desirable.
- Capability to prototype intricate concepts and evolve them into dependable enterprise services.
Nice to have
- Familiarity with Cyber Threat Exposure Management (CTEM), microsegmentation, or network digital twin technologies would be advantageous.
- Experience with graph databases and large-scale graph computation techniques is a plus.
- Knowledge of tools such as BloodHound, Nmap, Zeek, Wireshark, or NetFlow would be beneficial.
- Background with platforms like Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, or FireMon is appreciated.
- Experience with security validation tools including Pentera, AttackIQ, Picus, or Horizon3.ai is a plus.
- Understanding of networking within cloud environments such as AWS, Azure, or Google Cloud Platform (GCP) is desirable.
- Relevant certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC would be beneficial.
- Experience with enterprise network control technologies from vendors like Cisco, Palo Alto Networks, Fortinet, Check Point, or Juniper is a plus.
- Contributions to published research, patents, or open-source projects in the field of security are highly regarded.
Skills & tools
- Proficient in programming languages such as Python, Go, and Java.
- Familiar with graph databases and their applications.
- Knowledgeable in Active Directory and its security implications.
- Understanding of the MITRE ATT&CK framework and its relevance to threat modeling.
- Proficient in network security protocols and firewall analysis techniques.
Practical notes
- Safe is a well-funded company with a Series C funding round totaling $170 million.
- The compensation package includes significant equity options for all employees, promoting a sense of ownership and investment in the company's success.
- Employees enjoy a range of benefits, including unlimited leave and comprehensive medical insurance, fostering a healthy work-life balance and overall well-being.
About the company
Safe is not just another security tool; we are the AI-powered engine solving the "Cyber Visibility Gap" for the world's most complex organizations. With $170M in Series C funding and a mission to transform how risk is quantified, we are seeking a heavyweight Regional Vice President of Sales to lead our high-growth West Region.