402,911open jobs
14,044companies
78,108added this week
Browse all
Salary
$46k – $99k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Staff · 12+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Headquartered in Palo Alto, California, Safe Security is a cybersecurity technology company specializing in digital business risk quantification and continuous threat exposure management. The company’s AI-powered platform aggregates real-time technical signals across an organization's ecosystem to dynamically predict breach likelihood and estimate potential financial risk.

As a Staff Engineer - Network Security & Attack Path Intelligence, you will define and lead the technical direction of Safe’s network reachability and attack-path intelligence capabilities across on-premises, cloud, and hybrid environments.

You will be the hands-on architect behind systems that connect network topology, identities, vulnerabilities, security controls, and business-critical assets to determine how attackers can move through an enterprise environment.

You’ll collaborate with product, backend, graph, data, AI, and platform teams to build scalable, explainable, and enterprise-ready attack-path capabilities.

This is a high-impact, hands-on technical leadership role. You will architect systems, build prototypes, write production-quality code, and help shape how Safe’s CTEM platform identifies and breaks the attack paths that pose the greatest business risk.

Core Responsibilities:

  • Architect Safe’s Attack Path Intelligence: Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths across complex enterprise environments.
  • Build Core Attack Path Capabilities: Write production-quality code for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation. Build prototypes and evolve them into reliable, enterprise-scale services.
  • Model Effective Network Reachability: Derive actual connectivity from routing tables, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and segmentation policies rather than relying only on documented topology.
  • Model Attacker Movement: Build reasoning systems that connect exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and access to critical assets.
  • Prioritize Actionable Attack Paths: Distinguish theoretical paths from reachable, exploitable, and business-critical attack paths. Incorporate exploitability, control effectiveness, asset criticality, and business impact into prioritization.
  • Enterprise Security Integrations: Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
  • Countermeasure Intelligence: Build a vendor-neutral model for recommending segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls. Define validation, approval, safety, and rollback requirements.
  • AI and Graph Integration: Partner with other engineers to ensure attack-path explanations and countermeasure recommendations are evidence-backed, explainable, technically accurate, and governed through deterministic safety policies.
  • Validation & Governance: Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks to verify attack paths and proposed countermeasures without introducing unacceptable operational risk.
  • Mentor & Multiply: Guide backend, graph, security, and platform engineers through architectural design, code reviews, prototypes, engineering standards, and complex security-domain decisions.

Minimum Qualifications:

    Experience: 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a strong record of building and shipping production systems.

    Core Technical Skills

  • Strong hands-on programming experience in Python, Go, Java, or a similar backend language
  • Recent experience writing and shipping production-quality software-not only providing architectural or advisory guidance
  • Strong system-design, API-design, data-modeling, and distributed-systems fundamentals
  • Experience implementing graph traversal, rule-processing, network automation, configuration analysis, or security analytics
  • Ability to independently prototype complex ideas and evolve them into scalable production capabilities
  • Familiarity with graph databases and graph-processing technologies
  • Network Security

  • Deep understanding of enterprise on-premises, cloud, and hybrid networks
  • Strong knowledge of routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation
  • Experience deriving effective reachability across complex network configurations
  • Understanding of firewall-policy analysis, change validation, control effectiveness, and security misconfiguration detection
  • Attack Path & Identity Security

  • Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, and lateral movement
  • Experience with attack graphs, attack-path analysis, threat modelling, breach simulation, or exposure chaining
  • Ability to connect vulnerabilities and misconfigurations with network reachability and attacker behaviour
  • Familiarity with MITRE ATT&CK and common enterprise attack techniques
  • Product Engineering: Experience translating deep security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.

Preferred Qualifications:

  • Experience building attack-path, network digital-twin, microsegmentation, or CTEM products
  • Experience with graph databases and large-scale graph computation
  • Experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, or similar technologies
  • Experience with Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, or comparable platforms
  • Experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, or other enterprise network-control technologies
  • Exposure to Pentera, AttackIQ, Picus, Horizon3.ai, or other security-validation platforms
  • Background spanning both offensive and defensive security
  • Experience safely validating security controls in production-like environments
  • Knowledge of AWS, Azure, or GCP networking
  • Experience working with large, complex, and highly regulated enterprises
  • Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC
  • Published research, patents, open-source contributions, or previous technical leadership in security-product engineering is a strong plus
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
402,911 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$148k – $265k per year • Equity • In office • Full-Time • 7+ years exp • United States
Java
Node JS
Python
TypeScript
JavaScript
Databases
Apache Kafka
DynamoDB
Kafka
DevOps
Amazon CloudWatch
Amazon EC2
Amazon EKS
Amazon Kinesis
Amazon S3
API Gateway
ArgoCD
AWS
AWS CDK
AWS Lambda
CI/CD
FinOps
GitHub
GitHub Actions
GitOps
Helm
Incident Management
Jenkins
Kubernetes
Platform Engineering
Terraform
Cybersecurity
SOC 2
Apply
$230k – $280k per year • Equity • Remote/Hybrid • Full-Time • 6+ years exp • San Francisco
Python
Databases
DynamoDB
AI/ML
LLM
DevOps
Amazon CloudWatch
Amazon ECS
Amazon EKS
Amazon S3
AWS
AWS Lambda
CI/CD
Kubernetes
Cybersecurity
HIPAA
Apply
$160k – $220k per year • Equity • Remote/Hybrid • Full-Time • 6+ years exp • San Francisco
Node JS
Python
TypeScript
JavaScript
Frontend
React.js
DevOps
AWS
Rest API
Cybersecurity
HIPAA
Apply
In office • Full-Time • Singapore
Python
Analytics
Tableau
Apply
In office • 12+ years exp • Bachelor's Degree
Python
TypeScript
JavaScript
Databases
BigQuery
Databricks
Google BigQuery
Frontend
Angular
React.js
DevOps
Amazon CloudWatch
AWS
CI/CD
Datadog
Docker
GCP
Grafana
Kubernetes
Terraform
Management
Confluence
Jira
Apply
$22k – $56k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
C++
Go
Python
DevOps
Docker
Kubernetes
Cybersecurity
CVE
CVSS
Apply
$12k – $39k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • New Delhi
JavaScript
Python
TypeScript
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
CI/CD
Docker
Kubernetes
Self-Healing
Amazon S3
API Gateway
Apply
Remote • Full-Time • 4+ years exp • London
Apply
$150k – $160k per year • Remote • Full-Time • 4+ years exp
Apply
$150k – $160k per year • Remote • Full-Time • 4+ years exp • Los Angeles
Apply
$24k – $59k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
DevOps
Azure
Azure DevOps
CI/CD
GitHub
IAM
Management
Confluence
Jira
Apply
$20k – $46k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Cybersecurity
GDPR
Apply
In office • Full-Time • 3+ years exp • Bengaluru
Python
SQL
Databases
Amazon Redshift
BigQuery
Google BigQuery
Snowflake
Mobile
Firebase
Web3
Bitcoin
Analytics
Metabase
Power BI
Tableau
Marketing
Mixpanel
Apply
$41k – $61k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bengaluru
Web3
Bitcoin
Management
Outlook
Apply
$24k – $53k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • Bengaluru
Web3
Bitcoin
Marketing
Google Ads
Meta Ads
Mixpanel
YouTube
Apply
See all jobs
This is one of many
402,911 more open roles from verified company boards, updated every day.