We are seeking a Senior/Principal Security Engineer Attack Graph & Risk Prioritization to join our advanced security engineering team. In this role, you will lead the development of graph-based security solutions that model our large-scale cloud ecosystems and turn complex threat scenarios into actionable risk insights. You will act as a trusted partner embedded with product and platform security teams, empowering them to anticipate and prioritize risks based on attacker pathways. This role blends strategic vision with hands-on engineering: you will define long-term security strategy across interconnected systems while also building the technical frameworks (the “security graph”) that make that strategy real. The ideal candidate has a passion for attack-graph thinking, strong software engineering skills, and the leadership ability to influence without authority in a highly complex, cross-team setting.
Key Responsibilities:
- System-of-Systems Threat Modeling: Analyze and model our platform’s entire ecosystem (cloud services, identities, infrastructure, data,
control planes, devops ecosystem and AI systems) as an interconnected graph. Use this model to map how attackers could chain together vulnerabilities or misconfigurations across domains, exposing potential multi-stage attack paths, privilege escalation opportunities, and blast radius scenarios.
- Attack Graph Definition & Analysis: Define critical attack graph paths for various platforms, drawing on deep understanding of their architecture and threat models. Continuously refine these paths by incorporating emerging threat intelligence, known vulnerability patterns, and insights from real incidents to ensure the graph reflects current adversary techniques.
- Graph-Centric Solution Engineering: Design and build scalable systems and pipelines to generate, ingest, and analyze graph data at cloud scale. Develop algorithms and tooling that compute attacker reachability, identify choke points, and p