Back to Jobs
Safe Security

Staff Engineer- Network Security & Attack Path Intelligence

Safe Security
BengaluruFull TimeSeniorPosted Today

Most boards and executives are currently flying blind when it comes to cyber risk. They are guessing. At Safe, we’ve built an AI-driven engine that finally gives the C-Suite a clear, quantified, and real-time view of their security posture. We don’t just provide data; we provide certainty.

We are a $170M Series C-funded category leader. We don’t play in the mid-market; we operate at the highest levels of global enterprise. Today, we are proud to serve 10% of the Fortune 500, protecting global icons such as Apple, Netflix, AT&T, Verizon, and Victoria’s Secret.

As we scale toward our next chapter, we are looking for high-performers who want to do the best work of their careers at the intersection of AI and Cybersecurity.

The Culture Memo: Our Operating System

Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.

  • Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.

  • The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.

  • Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.

  • Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.

  • The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.

The Perks & Ownership:

We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.

  • Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.

  • Unlimited Leaves: We don’t believe in clock-watching. We offer unlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.

  • Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.

  • Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.


As a Staff Engineer – Network Security & Attack Path Intelligence, you will define and lead the technical direction of Safe’s network reachability and attack-path intelligence capabilities across on-premises, cloud, and hybrid environments.

You will be the hands-on architect behind systems that connect network topology, identities, vulnerabilities, security controls, and business-critical assets to determine how attackers can move through an enterprise environment.

You’ll collaborate with product, backend, graph, data, AI, and platform teams to build scalable, explainable, and enterprise-ready attack-path capabilities.

This is a high-impact, hands-on technical leadership role. You will architect systems, build prototypes, write production-quality code, and help shape how Safe’s CTEM platform identifies and breaks the attack paths that pose the greatest business risk.

Core Responsibilities:

  • Architect Safe’s Attack Path Intelligence: Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths across complex enterprise environments.
  • Build Core Attack Path Capabilities: Write production-quality code for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation. Build prototypes and evolve them into reliable, enterprise-scale services.
  • Model Effective Network Reachability: Derive actual connectivity from routing tables, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and segmentation policies rather than relying only on documented topology.
  • Model Attacker Movement: Build reasoning systems that connect exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and access to critical assets.
  • Prioritize Actionable Attack Paths: Distinguish theoretical paths from reachable, exploitable, and business-critical attack paths. Incorporate exploitability, control effectiveness, asset criticality, and business impact into prioritization.
  • Enterprise Security Integrations: Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
  • Countermeasure Intelligence: Build a vendor-neutral model for recommending segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls. Define validation, approval, safety, and rollback requirements.
  • AI and Graph Integration: Partner with other engineers to ensure attack-path explanations and countermeasure recommendations are evidence-backed, explainable, technically accurate, and governed through deterministic safety policies.
  • Validation & Governance: Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks to verify attack paths and proposed countermeasures without introducing unacceptable operational risk.
  • Mentor & Multiply: Guide backend, graph, security, and platform engineers through architectural design, code reviews, prototypes, engineering standards, and complex security-domain decisions.

Minimum Qualifications:

    Experience: 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a strong record of building and shipping production systems.

    Core Technical Skills

  • Strong hands-on programming experience in Python, Go, Java, or a similar backend language
  • Recent experience writing and shipping production-quality software—not only providing architectural or advisory guidance
  • Strong system-design, API-design, data-modeling, and distributed-systems fundamentals
  • Experience implementing graph traversal, rule-processing, network automation, configuration analysis, or security analytics
  • Ability to independently prototype complex ideas and evolve them into scalable production capabilities
  • Familiarity with graph databases and graph-processing technologies
  • Network Security

  • Deep understanding of enterprise on-premises, cloud, and hybrid networks
  • Strong knowledge of routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation
  • Experience deriving effective reachability across complex network configurations
  • Understanding of firewall-policy analysis, change validation, control effectiveness, and security misconfiguration detection
  • Attack Path & Identity Security

  • Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, and lateral movement
  • Experience with attack graphs, attack-path analysis, threat modelling, breach simulation, or exposure chaining
  • Ability to connect vulnerabilities and misconfigurations with network reachability and attacker behaviour
  • Familiarity with MITRE ATT&CK and common enterprise attack techniques
  • Product Engineering: Experience translating deep security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.

Preferred Qualifications:

  •  Experience building attack-path, network digital-twin, microsegmentation, or CTEM products
  • Experience with graph databases and large-scale graph computation
  • Experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, or similar technologies
  • Experience with Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, or comparable platforms
  • Experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, or other enterprise network-control technologies
  • Exposure to Pentera, AttackIQ, Picus, Horizon3.ai, or other security-validation platforms
  • Background spanning both offensive and defensive security
  • Experience safely validating security controls in production-like environments
  • Knowledge of AWS, Azure, or GCP networking
  • Experience working with large, complex, and highly regulated enterprises
  • Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC
  • Published research, patents, open-source contributions, or previous technical leadership in security-product engineering is a strong plus
  • If you’re passionate about cyber risk, thrive in a fast-paced environment, and want to build technology that helps the world’s largest organizations identify and break critical attack paths before they are exploited, we want to hear from you! 🚀
If you’re passionate about cyber risk, thrive in a fast-paced environment, and want to be part of a team that’s redefining security, we want to hear from you! 🚀
Ready to apply? You'll be taken to Safe Security's application page.
Staff Engineer- Network Security & Attack Path Intelligence at Safe Security