Staff Engineer- Network Security & Attack Path Intelligence
SafeIndiaFull-time1w ago
AISecuritySalesEngineeringArchitectPlatformBackendremotecurated-jd
Job description
Staff Engineer- Network Security & Attack Path Intelligence at Safe.
About the role
Safe is seeking a technical leader to architect and build systems that map attack paths across complex hybrid, cloud, and on-premises environments. You will drive the development of our CTEM platform by connecting network topology, identity, and vulnerability data to provide actionable risk intelligence for global enterprises.
Key facts
What you'll do
- Define the architecture and data models for network reachability, trust boundaries, and attack-path construction.
- Develop production-grade services for parsing network configurations, computing blast radii, and performing graph traversal.
- Analyze real-world connectivity by interpreting routing tables, firewalls, load balancers, and segmentation policies.
- Build reasoning engines that simulate attacker movement, including lateral movement, privilege escalation, and credential exposure.
- Create vendor-neutral models for recommending security controls and segmentation improvements.
- Integrate the platform with enterprise tools such as EDR, CMDB, Active Directory, and various firewall vendors.
- Establish validation frameworks and simulation environments to verify attack paths without impacting operational stability.
- Mentor engineering teams on security domain expertise, architectural standards, and complex system design.
Requirements
- 12+ years of experience in software engineering, security product development, or exposure management.
- Proficiency in Python, Go, or Java with a proven track record of shipping production software.
- Expertise in system design, API architecture, and distributed systems.
- Deep knowledge of network security, including VLANs, ACLs, NAT, VPNs, and proxies.
- Understanding of identity-based attack vectors, including Active Directory, Kerberos, and privilege escalation.
- Experience implementing graph-based analytics or security automation.
- Ability to prototype complex concepts and scale them into reliable enterprise services.
Nice to have
- Experience with CTEM, microsegmentation, or network digital-twin products.
- Proficiency with graph databases and large-scale graph computation.
- Familiarity with tools like BloodHound, Nmap, Zeek, Wireshark, or NetFlow.
- Background with platforms such as Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, or FireMon.
- Experience with security validation tools like Pentera, AttackIQ, Picus, or Horizon3.ai.
- Knowledge of AWS, Azure, or GCP networking.
- Certifications including OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC.
- Experience with enterprise network-control technologies from Cisco, Palo Alto Networks, Fortinet, Check Point, or Juniper.
- Published research, patents, or open-source contributions in security.
Skills & tools
- Python, Go, Java
- Graph databases
- Active Directory
- MITRE ATT&CK
- Network security protocols and firewall analysis
Practical notes
- Safe is a $170M Series C-funded company.
- Compensation includes meaningful equity for all employees.
- Benefits include unlimited leave and comprehensive medical insurance.