Safe Security
Posted 3w ago

Staff Engineer- Network Security & Attack Path Intelligence

Safe Security
Bengaluru, Karnataka, India
OnsiteFull Time
Responsibilities
  • architecting systems
  • building prototypes
  • mentoring engineers
Requirements
  • 12+ years software engineering or security product experience
  • Hands-on in Python/Go/Java
  • Network security
  • Attack-path modeling
  • Graph processing
  • Active Directory, and production-grade system design
Technical tools mentioned
PythonGoJavaBloodHoundNmapZeekWiresharkNetFlowForward NetworksXM CyberRedSealAlgoSecTufinFireMonPalo Alto NetworksCiscoFortinetCheck PointJuniperPenteraAttackIQPicusHorizon3.aiAWSAzureGCPMITRE ATT&CK

Job description

Most boards and executives are currently flying blind when it comes to cyber risk. They are guessing. At Safe, we’ve built an AI-driven engine that finally gives the C-Suite a clear, quantified, and real-time view of their security posture. We don’t just provide data; we provide certainty.

We are a $170M Series C-funded category leader. We don’t play in the mid-market; we operate at the highest levels of global enterprise. Today, we are proud to serve 10% of the Fortune 500, protecting global icons such as Apple, Netflix, AT&T, Verizon, and Victoria’s Secret.

As we scale toward our next chapter, we are looking for high-performers who want to do the best work of their careers at the intersection of AI and Cybersecurity.

The Culture Memo: Our Operating System

Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.

  • Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.

  • The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.

  • Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.

  • Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.

  • The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.

The Perks & Ownership:

We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.

  • Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.

  • Unlimited Leaves: We don’t believe in clock-watching. We offer unlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.

  • Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.

  • Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.


As a Staff Engineer – Network Security & Attack Path Intelligence, you will define and lead the technical direction of Safe’s network reachability and attack-path intelligence capabilities across on-premises, cloud, and hybrid environments.

You will be the hands-on architect behind systems that connect network topology, identities, vulnerabilities, security controls, and business-critical assets to determine how attackers can move through an enterprise environment.

You’ll collaborate with product, backend, graph, data, AI, and platform teams to build scalable, explainable, and enterprise-ready attack-path capabilities.

This is a high-impact, hands-on technical leadership role. You will architect systems, build prototypes, write production-quality code, and help shape how Safe’s CTEM platform identifies and breaks the attack paths that pose the greatest business risk.



Core Responsibilities:
  • Architect Safe’s Attack Path Intelligence: Define the architecture and data model for network topology, effective reachability, trust boundaries, identities, vulnerabilities, controls, and attack paths across complex enterprise environments.
  • Build Core Attack Path Capabilities: Write production-quality code for network configuration parsing, reachability analysis, attack-graph construction, graph traversal, exposure chaining, and blast-radius computation. Build prototypes and evolve them into reliable, enterprise-scale services.
  • Model Effective Network Reachability: Derive actual connectivity from routing tables, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and segmentation policies rather than relying only on documented topology.
  • Model Attacker Movement: Build reasoning systems that connect exposed services, vulnerabilities, credentials, Active Directory privileges, lateral movement, privilege escalation, and access to critical assets.
  • Prioritize Actionable Attack Paths: Distinguish theoretical paths from reachable, exploitable, and business-critical attack paths. Incorporate exploitability, control effectiveness, asset criticality, and business impact into prioritization.
  • Enterprise Security Integrations: Design integrations with firewalls, routers, NAC, EDR, CMDB, Active Directory, vulnerability scanners, NetFlow, cloud platforms, and other enterprise security systems.
  • Countermeasure Intelligence: Build a vendor-neutral model for recommending segmentation, isolation, firewall-policy changes, access-control improvements, and compensating controls. Define validation, approval, safety, and rollback requirements.
  • AI and Graph Integration: Partner with other engineers to ensure attack-path explanations and countermeasure recommendations are evidence-backed, explainable, technically accurate, and governed through deterministic safety policies.
  • Validation & Governance: Build reference attack scenarios, simulation environments, regression datasets, and validation frameworks to verify attack paths and proposed countermeasures without introducing unacceptable operational risk.
  • Mentor & Multiply: Guide backend, graph, security, and platform engineers through architectural design, code reviews, prototypes, engineering standards, and complex security-domain decisions.


  • Minimum Qualifications:

    Experience: 12+ years of experience in software engineering, network security, security product engineering, exposure management, or related areas, with a strong record of building and shipping production systems.

    Core Technical Skills

  • Strong hands-on programming experience in Python, Go, Java, or a similar backend language
  • Recent experience writing and shipping production-quality software—not only providing architectural or advisory guidance
  • Strong system-design, API-design, data-modeling, and distributed-systems fundamentals
  • Experience implementing graph traversal, rule-processing, network automation, configuration analysis, or security analytics
  • Ability to independently prototype complex ideas and evolve them into scalable production capabilities
  • Familiarity with graph databases and graph-processing technologies
  • Network Security

  • Deep understanding of enterprise on-premises, cloud, and hybrid networks
  • Strong knowledge of routing, switching, VLANs, ACLs, firewalls, NAT, VPNs, proxies, load balancers, and network segmentation
  • Experience deriving effective reachability across complex network configurations
  • Understanding of firewall-policy analysis, change validation, control effectiveness, and security misconfiguration detection
  • Attack Path & Identity Security

  • Strong understanding of Active Directory, Kerberos, identity privilege paths, credential exposure, privilege escalation, and lateral movement
  • Experience with attack graphs, attack-path analysis, threat modelling, breach simulation, or exposure chaining
  • Ability to connect vulnerabilities and misconfigurations with network reachability and attacker behaviour
  • Familiarity with MITRE ATT&CK and common enterprise attack techniques
  • Product Engineering: Experience translating deep security-domain knowledge into scalable products, analytical systems, or security-platform capabilities.



    Preferred Qualifications:
  •  Experience building attack-path, network digital-twin, microsegmentation, or CTEM products
  • Experience with graph databases and large-scale graph computation
  • Experience with BloodHound, Nmap, Zeek, Wireshark, NetFlow, or similar technologies
  • Experience with Forward Networks, XM Cyber, RedSeal, AlgoSec, Tufin, FireMon, or comparable platforms
  • Experience with Palo Alto Networks, Cisco, Fortinet, Check Point, Juniper, or other enterprise network-control technologies
  • Exposure to Pentera, AttackIQ, Picus, Horizon3.ai, or other security-validation platforms
  • Background spanning both offensive and defensive security
  • Experience safely validating security controls in production-like environments
  • Knowledge of AWS, Azure, or GCP networking
  • Experience working with large, complex, and highly regulated enterprises
  • Certifications such as OSCP, OSEP, CISSP, CCIE Security, CCNP Security, or GIAC
  • Published research, patents, open-source contributions, or previous technical leadership in security-product engineering is a strong plus
  • If you’re passionate about cyber risk, thrive in a fast-paced environment, and want to build technology that helps the world’s largest organizations identify and break critical attack paths before they are exploited, we want to hear from you! 🚀


    If you’re passionate about cyber risk, thrive in a fast-paced environment, and want to be part of a team that’s redefining security, we want to hear from you! 🚀

    About Safe Security

    Provides an AI-driven platform for quantifying and managing cyber risk.

    Year founded
    2012
    Employees
    200
    Organization type
    Private
    Latest investment
    Raised $70.00M Series C (2025) — led by Sorenson Capital
    Subsidiaries
    Headquarters
    US

    Similar jobs

    Network Security Engineer roles near Bengaluru, Karnataka
    1d
    Save
    Mark Applied
    Hide
    DIGITAL SECURITY - Threat Prevention - NETWORK SECURITY - Proxy
    Hyderabad or Bengaluru or Milpitas or Seattle or Princeton or Cape Town or London or Zurich or Singapore or Mexico City
    RemoteFull Time
    Zensar
    ZensarNational Stock Exchange of India: ZENSARTECH: Global technology firm providing digital transformation and infrastructure services.
    7+ YOERequires 7+ years in network and security engineering, 4+ years with Zscaler, global enterprise experience, and a bachelor's degree or equivalent practical experience.
    Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Cloud Firewall, CASB, Browser Isolation, Data Loss Prevention (DLP), SSL Inspection, Azure AD (Entra ID), Okta, Ping Identity, Active Directory, SAML, OAuth, OpenID Connect, Multi-Factor Authentication (MFA), Python, YAML, Jira, Confluence, Ansible
    2d
    Save
    Mark Applied
    Hide
    Senior Network Security Engineer – Firewall & ZTNA
    Bangalore or Thiruvananthapuram
    OnsiteFull Time
    UST
    UST: Global provider of digital transformation and IT services.
    10+ YOERequires 10+ years in network security and enterprise infrastructure, firewall segmentation expertise, hybrid environment security, and a bachelor's degree or equivalent experience.
    Juniper, Palo Alto, Fortinet, ZTNA, Zero Trust Architecture (ZTA), VPN, SIEM, IAM, EDR/XDR, ITIL
    3d
    Save
    Mark Applied
    Hide
    Sr. Network Security Engineer with ZTNA
    Bengaluru, Karnataka, India
    OnsiteFull Time
    Birlasoft
    BirlasoftNational Stock Exchange of India: BSOFT: Provides digital transformation and IT consulting services for global enterprises.
    8+ YOERequires 8–11 years of network security experience, with mandatory hands-on ZTNA/SASE/SSE expertise, Zscaler ZIA/ZPA and Axis Security or Aruba SSE, identity integration, firewalls, SIEM, VPN, and network security architecture.
    Zscaler, ZIA, ZPA, Axis Security, Aruba SSE, Azure AD, Okta, EDR, XDR, SIEM, SOAR, SASE, SSE, SWG, CASB, DLP, SAML, OAuth, MFA, Fortinet, Palo Alto, Juniper, IDS/IPS, VPN, NAC, WAAP
    6d
    Save
    Mark Applied
    Hide
    Administrator - Networks
    Bangalore, Karnataka, India
    OnsiteFull Time
    Manhattan Associates
    Manhattan AssociatesNASDAQ: MANH: Develops software to manage supply chains and omnichannel operations.
    3+ YOERequires 3–4 years in network security engineering or operations, 1+ year in cloud security, TCP/IP and VPN expertise, Cisco security experience, and a related bachelor's degree or equivalent practical experience.
    Cisco ISE, Cisco ASA, Cisco Firepower Threat Defense (FTD), VPN, IPsec, Cisco Umbrella, Secure Access, Splunk, SIEM, Cisco Secure Cloud Analytics (XDR), Azure, ServiceNow, Microsoft cloud security integrations, TCP/IP, IDS/IPS
    1w
    Save
    Mark Applied
    Hide
    Network Security Engineer
    Bengaluru, Karnataka, India
    OnsiteFull Time
    Point72
    Point72: Global alternative investment firm managing capital and venture investments.
    5+ YOERequires 5–7 years in network security, preferably in financial services or regulated environments, with firewall, cloud networking, segmentation, SASE, NDR, compliance, and security certification experience.
    Illumio, Palo Alto Networks, GlobalProtect, Prisma Access, Cloudflare, Cisco ISE, AWS, Microsoft Azure, Google Cloud Platform (GCP), Guardicore, VMware NSX, VMware NSX-T, vArmour, Cisco ACI, ShieldX, Unisys Stealth, Zero Networks, zScaler, NetSkope, Darktrace, ExtraHop, Vectra, PCI DSS, HIPAA, GDPR
    1w
    Save
    Mark Applied
    Hide
    L2 Network Security Engineer
    Bengaluru, Karnataka, India
    OnsiteFull Time
    Systal
    Systal: Global provider of managed network, cloud, and security solutions.
    Enterprise or managed-services network security experience; networking, firewalls, VPNs, security incidents, SIEM, ServiceNow, ITIL, troubleshooting, documentation, and stakeholder communication skills.
    TCP/IP, Check Point, IDS/IPS, SIEM, syslog, SolarWinds, Splunk, ServiceNow, ITIL, Cisco CCNA Security, CompTIA Security+
    2w
    Save
    Mark Applied
    Hide
    Network Security Engineer
    Bangalore, Karnataka, India
    OnsiteFull Time
    Unisys
    UnisysNYSE: UIS: Provides enterprise-scale IT services and digital transformation solutions.
    4+ YOEBachelor's degree and 4–6 years of relevant experience, or an equivalent combination of education and experience; expertise in security controls, deployments, automation, APIs, and incident resolution.
    API
    2w
    Save
    Mark Applied
    Hide
    Network Security Engineer
    Bengaluru, Karnataka, India
    ₹350k-₹600k/yr OnsiteFull Time
    SNS India
    SNS India: Provides comprehensive cybersecurity solutions and managed security services.
    Bachelor's degree in a related field; hands-on FortiGate, FortiSwitch, or Check Point experience; Kannada proficiency; networking, troubleshooting, communication, and analytical skills.
    FortiGate, FortiSwitch, Check Point, TCP/IP, VLANs