Full-Time

Staff Engineer - Network Security & Attack Path Intelligence

Posted on 8/1/2026

Safe Security

Safe Security

No salary listed

Bengaluru, Karnataka, India

In Person

Category
IT & Security (1)
Required Skills
Zeek
Microsoft Azure
Python
Distributed Systems
Wireshark
LDAP
Graph Databases
Threat modeling
Computer Networking
Java
AWS
Go
Data Modeling
ACLS
Google Cloud Platform
Requirements
  • 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a strong record of building and shipping production systems.
  • Strong hands-on programming experience in Python, Go, Java, or a similar backend language.
  • Recent experience writing and shipping production-quality software, not only providing architectural or advisory guidance.
  • Strong system-design, API-design, data-modeling, and distributed-systems fundamentals.
  • Experience implementing graph traversal, rule-processing, network automation, configuration analysis, or security analytics.
  • Ability to independently prototype complex ideas and evolve them into scalable production capabilities.
  • Familiarity with graph databases and graph-processing technologies.
  • Deep understanding of enterprise on-premises, cloud, and hybrid networks.
  • Strong knowledge of routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation.
  • Experience deriving effective reachability across complex network configurations.
  • Understanding of firewall-policy analysis, change validation, control effectiveness, and security misconfiguration detection.
  • Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, and lateral movement.
  • Experience with attack graphs, attack-path analysis, threat modelling, breach simulation, or exposure chaining.
  • Ability to connect vulnerabilities and misconfigurations with network reachability and attacker behaviour.
  • Familiarity with MITRE ATT&CK and common enterprise attack techniques.
  • Experience translating deep security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.
Responsibilities
  • Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths across complex enterprise environments.
  • Write production-quality code for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation.
  • Build prototypes and evolve them into reliable, enterprise-scale services.
  • Derive actual connectivity from routing tables, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and segmentation policies rather than relying only on documented topology.
  • Build reasoning systems that connect exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and access to critical assets.
  • Distinguish theoretical paths from reachable, exploitable, and business-critical attack paths.
  • Incorporate exploitability, control effectiveness, asset criticality, and business impact into prioritization.
  • Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
  • Build a vendor-neutral model for recommending segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls.
  • Define validation, approval, safety, and rollback requirements for countermeasures.
  • Ensure attack-path explanations and countermeasure recommendations are evidence-backed, explainable, technically accurate, and governed through deterministic safety policies.
  • Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks to verify attack paths and proposed countermeasures without introducing unacceptable operational risk.
  • Guide backend, graph, security, and platform engineers through architectural design, code reviews, prototypes, engineering standards, and complex security-domain decisions.
Desired Qualifications
  • Experience building attack-path, network digital-twin, microsegmentation, or Continuous Threat Exposure Management (CTEM) products.
  • Experience with graph databases and large-scale graph computation.
  • Experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, or similar technologies.
  • Experience with Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, or comparable platforms.
  • Experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, or other enterprise network-control technologies.
  • Exposure to Pentera, AttackIQ, Picus, Horizon3.ai, or other security-validation platforms.
  • Background spanning both offensive and defensive security.
  • Experience safely validating security controls in production-like environments.
  • Knowledge of Amazon Web Services, Microsoft Azure, or Google Cloud Platform networking.
  • Experience working with large, complex, and highly regulated enterprises.
  • Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC.
  • Published research, patents, open-source contributions, or previous technical leadership in security-product engineering is a strong plus.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A