07 Aug
|
Atvs (india)
|
Hyderabad
07 Aug
Atvs (india)
Hyderabad
Role Summary:
We are seeking a Senior/Principal Security Engineer Attack Graph & Risk Prioritization to join our advanced security engineering team. In this role, you will lead the development of graph-based security solutions that model our large-scale cloud ecosystems and turn complex threat scenarios into actionable risk insights. You will act as a trusted partner embedded with product and platform security teams, empowering them to anticipate and prioritize risks based on attacker pathways. This role blends strategic vision with hands-on engineering: you will define long-term security strategy across interconnected systems while also building the technical frameworks (the “security graph”) that make that strategy real. The ideal candidate has a passion for attack-graph thinking, strong software engineering skills, and the leadership ability to influence without authority in a highly complex, cross-team environment.
Key Responsibilities:
- System-of-Systems Threat Modeling: Analyze and model our platform’s entire ecosystem (cloud services, identities, infrastructure, data, control planes, devops ecosystem and AI systems) as an interconnected graph. Use this model to map how attackers could chain together vulnerabilities or misconfigurations across domains, exposing potential multi-stage attack paths, privilege escalation opportunities, and blast radius scenarios.
- Attack Graph Definition & Analysis: Define critical attack graph paths for various platforms, drawing on deep understanding of their architecture and threat models. Continuously refine these paths by incorporating emerging threat intelligence, known vulnerability patterns, and insights from real incidents to ensure the graph reflects current adversary techniques.
- Graph-Centric Solution Engineering: Design and build scalable systems and pipelines to generate, ingest, and analyze graph data at cloud scale. Develop algorithms and tooling that compute attacker reachability, identify choke points, and produce prioritized risk outputs. Integrate attack-graph analytics with existing security tools and engineering workflows (CI/CD pipelines, monitoring dashboards, etc.) to seamlessly embed graph-driven insights into day-to-day development and operations.
- Security Architecture Leadership: Define and lead the security architecture for complex, large-scale platforms and shared services, using the attack graph as a foundation. This includes designing secure patterns for interconnected systems, guiding engineering teams on defense-in-depth improvements, and ensuring robust protections in scenarios that involve AI-assisted systems or automation.
- Strategic Security Planning: Set a long-term security strategy that balances rigorous risk reduction with engineering velocity and product innovation. Identify where graph analytics can best focus defensive resources for maximum impact, and shape multi-year roadmaps to drive those outcomes across multiple products/services.
- Embedded Security Partnership: Act as a trusted security advisor and champion within engineering domains. Work closely with security partner teams—often without direct authority—to influence their technical roadmaps and design decisions using data-driven evidence from attack graph insights. Provide expert guidance on secure architecture choices, process improvements, and best practices to elevate overall security posture.
- Cross-Organizational Collaboration: Partner with a broad range of stakeholders (security teams, cloud infrastructure groups, service engineering orgs, compliance and governance teams, etc.) to deliver cohesive end-to-end security outcomes. Ensure that attack-graph-driven risk prioritization is aligned with business objectives, incident response plans, and compliance requirements across the company.
- Executive and Customer Engagement: Represent the security architecture and the attack-graph approach in high-impact forums. Communicate complex security issues and trade-offs to executives, customers, and external partners in clear,
compelling terms—translating graph analysis results into narratives that drive understanding and action.
- Continuous Improvement & Innovation: Conduct ongoing security research, testing, and analysis activities. Identify recurring vulnerability patterns or architecture weaknesses revealed by the graph, and spearhead the development of mitigations or automated controls to address them proactively. Evaluate new technologies (including AI/LLM-driven security tools) and incorporate advances that enhance the graph’s capability to predict and prevent attacks.
- Mentorship and Thought Leadership: Serve as a security thought leader within and beyond the team. Mentor other engineers in threat modeling and secure design, cultivate a graph-oriented mindset across the organization, and contribute to the broader security community (e.g., via talks, publications, or standards) to establish our team’s expertise in graph-based security.
Required Qualifications:
- Education & Experience: Bachelor’s or Master’s degree in Computer Science, Engineering, Mathematics, or a related field. 8+ years of hands-on experience in security engineering or security research roles, including designing, building, and operating large-scale enterprise security solutions.
- Security Domain Knowledge: Deep understanding of software and cloud security fundamentals – including common vulnerabilities (OWASP Top 10, CWE Top 25) and secure design principles (authentication, authorization, encryption, etc.). Proven ability to analyze and root-cause complex security issues across different layers (application, infrastructure, identity).
- Graph & Threat Modeling Expertise: Exceptional skill in threat modeling and attack path analysis. Able to conceptualize systems as graphs or networks of interconnected components and reason about how attackers might exploit relationships. Familiarity with graph theory, graph databases, or similar modeling techniques to represent complex systems is highly valued.
- Full-Stack Engineering Ability: Proficiency in coding and debugging (e.g., in C#, .NET, Java, or equivalent languages). Experience developing security tools or platforms using cloud services and modern DevOps practices. Comfortable working with large datasets and building data pipelines (using technologies such as cloud data platforms or analytics frameworks) to analyze security signals at scale.
- Cloud Platform Mastery: Strong knowledge of cloud environments (Microsoft Azure preferred; AWS/GCP also valued) and their security constructs. This includes identity and access management, network architecture, compute and container services, and inter-service authentication/authorization. Practical experience securing large cloud or distributed systems is essential.
- AI/ML Security Awareness: Experience architecting or securing systems that incorporate AI/ML components (such as large language models or intelligent automation) in security-sensitive workflows. Understand how to apply governance, auditing, and safety controls to AI-driven features to prevent abuse or adversarial exploitation.
- Influence & Leadership: Demonstrated ability to lead and influence across teams and organizations without direct authority. Proven success driving alignment on security initiatives among diverse stakeholders (engineering, product, compliance, leadership) by using robust communication, evidence-based reasoning, and empathy for business goals.
- Communication Skills: Excellent written and verbal communication skills, with an aptitude for explaining complex technical security concepts and risk trade-offs to both deeply technical audiences and non-technical stakeholders.
Able to produce clear documentation and persuasive presentations that drive decision-making.
Preferred Qualifications:
- Graph Systems & Analytics: Prior experience building or operating graph-based systems – e.g., security graphs, large knowledge graphs, or social network analysis tools. Familiarity with graph query languages, graph analytics algorithms, or graph databases (such as Neo4j, Cosmos DB Gremlin, etc.) is a strong plus.
- Offensive Security Background: Hands-on background in offensive security (red teaming, advanced penetration testing, or adversary simulation) with a track record of modeling and exploiting complex attack chains. This experience helps in anticipating attacker behavior and validating the effectiveness of attack path defenses.
- Enterprise Security Platforms: Experience developing or running continuous security assurance platforms or large-scale security orchestration systems (for example, vulnerability management pipelines, incident response automation, or threat intelligence integration at scale).
- Multi-Cloud & Ecosystem Breadth: Proficiency in multiple cloud or technology ecosystems. Deep knowledge of Microsoft Azure is a plus; familiarity with AWS/GCP or hybrid-cloud environments shows adaptability. Understanding of contemporary identity models (OAuth/OIDC, token-based auth, zero-trust principles) and hands-on experience delivering production-grade software/services in these contexts.
- Thought Leadership & Research: A public track record of security innovation – such as published research, open-source security tools, or contributions to industry standards – is highly desirable. Recognition as a thought leader in security architecture or risk analytics (e.g., conference presentations, patents, or community leadership) would distinguish the candidate.
Priya and Dan JD:
Security Engineer (Vendor - IC3/IC4 Equivalent) (2 Vendors)
Overview
The SIGMA TAO (Third-party, AI and Open-source Security team) within CISO is transforming how Microsoft secures its software supply chain through AI-driven security assessments. As an AI Assessment Validator, you will provide critical human expertise to validate, augment, and enhance AI-generated security assessments for third-party applications used across Microsoft.
You’ll be part of a multi-disciplinary team of security professionals who drive key security initiatives to protect our customers and Microsoft.
Responsibilities
- Review and validate AI-generated denied assessments for third-party applications, confirming or disputing findings using security expertise
- Provide independent review of AI-generated security assessments, particularly when AI confidence scores are below 75% or for high-risk applications
- Review exception requests and assess associated security risks for denied or non-compliant applications
- Conduct security assessments of previously approved software flagged by AI continuous monitoring
- Evaluate applications for restricted software designation and support eviction backlog management
Required Qualifications
Education & Experience
- Bachelor’s degree in computer science, Cybersecurity, Information Systems, Information Security, or equivalent work experience
- Experience using AI to help accomplish tasks
- 5-7+ years of progressive experience in information security, with focus on third-party risk management, vendor security assessments, or application security
- Demonstrated experience performing security assessments, risk analysis, and exception management in enterprise environments
- Strong technical expertise in cloud security (Azure, AWS, GCP), network architecture, identity and access management, and vulnerability management
- Knowledge of threat modeling, attack techniques, and security architecture principles
- Experience augmenting automated security tools with human judgment and expertise
- Excellent verbal and written communication skills with ability to translate technical findings for non-technical audiences
- Strong analytical and problem-solving skills with attention to detail
📌 Opportunity For Security Engineer - Hyderabad/Bangalore
🏢 Atvs (india)
📍 Hyderabad