The opportunity
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…
What you'll do
Define and own the vision, strategy, and roadmap for a credible ITDR function: within Elastic Security, evolving our Entity Analytics and Entity Store foundation from behavioral analytics into an identity-defense outcome.
Manage the plan for non-human and AI agent identities in Elastic Security.: This involves modeling service accounts, workloads, secrets, and self-directed agents as important identities. Each identity will have its own behavior standards, ownership, and lifecycle. You will also establish how to detect identities that operate continuously and at machine scale.
Work with threat research and detection engineering. Focus on: identity-specific threats. These threats include credential access, privilege escalation, and identity-based lateral movement. They also involve the abuse of identity providers and tokens. Ensure that these threats relate to real-world adversary tactics.
Drive the response and containment strategy. This is the 'R' in ITDR. Turn: detections into action. Use identity-system integrations and automated responses. Make sure there is human oversight for important actions.
Work closely with our enterprise customers. Collaborate with security: operations teams, sales, and solution architects. Your goal is to understand the requirements for identity attacks. You will also discuss priorities and clarify product needs.
Work with the design team to develop investigation and response experiences.: These experiences will emphasize identity in the analyst workflow. Integrate identity signals with endpoint, cloud, and network data in the SIEM and XDR functions of our security operations platform.
What they're looking for
- Gain deep knowledge of the identity-security market. Know its major trends: and the changing threat landscape. Use this information to develop a unique strategy and engage with analysts.
- Be the product expert and evangelize Elastic's identity capabilities through: content such as blog posts, talks, and open community interaction.
- Extensive Experience: 10+ years of experience in product management or solution delivery for security products such as SIEM, XDR, EDR, identity security, or detection and response. A consistent record of leading sophisticated, data-intensive products from inception through launch and iterative growth.
- Identity Security Depth: A solid knowledge of identity-based attack techniques and the identity fabric. This includes Active Directory, cloud identity providers, SSO, OAuth, and privileged access. It also involves knowing how identity threats can occur in both on-premises and cloud environments. Knowledge of ITDR as a discipline and with entity behavioral analytics (UEBA).