Staff Engineer- Network Security & Attack Path Intelligence
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Key Skills for This Role
Full Job Posting
The Culture Memo: Our Operating System
Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.
Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.
The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.
Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.
Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.
The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.
The Perks & Ownership:
We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.
Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.
Unlimited Leaves: We don’t believe in clock-watching. We offer unlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.
Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.
Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.
As a Staff Engineer – Network Security & Attack Path Intelligence, you will define and lead the technical direction of Safe’s network reachability and attack-path intelligence capabilities across on-premises, cloud, and hybrid environments.
You will be the hands-on architect behind systems that connect network topology, identities, vulnerabilities, security controls, and business-critical assets to determine how attackers can move through an enterprise environment.
You’ll collaborate with product, backend, graph, data, AI, and platform teams to build scalable, explainable, and enterprise-ready attack-path capabilities.
This is a high-impact, hands-on technical leadership role. You will architect systems, build prototypes, write production-quality code, and help shape how Safe’s CTEM platform identifies and breaks the attack paths that pose the greatest business risk.
Core Responsibilities:
Architect Safe’s Attack Path Intelligence: Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths across complex enterprise environments.
Build Core Attack Path Capabilities: Write production-quality code for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation. Build prototypes and evolve them into reliable, enterprise-scale services.
Model Effective Network Reachability: Derive actual connectivity from routing tables, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and segmentation policies rather than relying only on documented topology.
Model Attacker Movement: Build reasoning systems that connect exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and access to critical assets.
Prioritize Actionable Attack Paths: Distinguish theoretical paths from reachable, exploitable, and business-critical attack paths. Incorporate exploitability, control effectiveness, asset criticality, and business impact into prioritization.
Enterprise Security Integrations: Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
Countermeasure Intelligence: Build a vendor-neutral model for recommending segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls. Define validation, approval, safety, and rollback requirements.
AI and Graph Integration: Partner with other engineers to ensure attack-path explanations and countermeasure recommendations are evidence-backed, explainable, technically accurate, and governed through deterministic safety policies.
Validation & Governance: Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks to verify attack paths and proposed countermeasures without introducing unacceptable operational risk.
Mentor & Multiply: Guide backend, graph, security, and platform engineers through architectural design, code reviews, prototypes, engineering standards, and complex security-domain decisions.
Minimum Qualifications:
Experience: 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a strong record of building and shipping production systems.
Core Technical Skills
Strong hands-on programming experience in Python, Go, Java, or a similar backend language
Recent experience writing and shipping production-quality software—not only providing architectural or advisory guidance
Strong system-design, API-design, data-modeling, and distributed-systems fundamentals
Experience implementing graph traversal, rule-processing, network automation, configuration analysis, or security analytics
Ability to independently prototype complex ideas and evolve them into scalable production capabilities
Familiarity with graph databases and graph-processing technologies
Network Security
Deep understanding of enterprise on-premises, cloud, and hybrid networks
Strong knowledge of routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation
Experience deriving effective reachability across complex network configurations
Understanding of firewall-policy analysis, change validation, control effectiveness, and security misconfiguration detection
Attack Path & Identity Security
Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, and lateral movement
Experience with attack graphs, attack-path analysis, threat modelling, breach simulation, or exposure chaining
Ability to connect vulnerabilities and misconfigurations with network reachability and attacker behaviour
Familiarity with MITRE ATT&CK and common enterprise attack techniques
Product Engineering: Experience translating deep security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.
Preferred Qualifications:
Experience building attack-path, network digital-twin, microsegmentation, or CTEM products
Experience with graph databases and large-scale graph computation
Experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, or similar technologies
Experience with Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, or comparable platforms
Experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, or other enterprise network-control technologies
Exposure to Pentera, AttackIQ, Picus, Horizon3.ai, or other security-validation platforms
Background spanning both offensive and defensive security
Experience safely validating security controls in production-like environments
Knowledge of AWS, Azure, or GCP networking
Experience working with large, complex, and highly regulated enterprises
Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC
Published research, patents, open-source contributions, or previous technical leadership in security-product engineering is a strong plus
About Safe Security
Safe Security offers an autonomous cyber risk management platform for strategic risk quantification, exposure management, and third-party risk assessment on a unified dashboard.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Safe Security
Software Development Engineer II – Sensors / Systems & Security Engineering
Bengaluru, IND
Staff Engineer
Bengaluru, IND
Software Development Engineer I
Delhi, IND
Software Development Engineer I
Bengaluru, IND
Talent Acquisition Operations Intern
Delhi, IND
Software Development Engineer II – Sensors / Systems & Security Engineering
Bengaluru, IND
Director of Demand Generation
New York City, USA
Software Development Engineer II - Android
Bengaluru, IND
Threat Researcher II
Delhi, IND
