The opportunity
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…
What you'll do
Lead, mentor, and grow a world-class engineering team. Guide senior research: engineers across endpoint internals, prevention engineering, and machine learning. Coach career development, deliver candid feedback, own the hiring pipeline, and set new engineers up to contribute quickly.
Own the roadmap and drive delivery. Decide where to invest in new visibility: and where to deepen existing protection engines, balancing efficacy, performance, and stability across millions of endpoints. Work with product managers to define requirements and land high-quality features on release timelines.
Connect your team's work to the rest of Elastic Security. Every event source: your team adds unlocks new detection and protection capabilities across the product. Invest in the joint planning, working relationships, and shared accountability that get your team's work into customers' hands.
Direct the team's machine learning work. Set direction on model development,: training data quality, and the telemetry features those models depend on, and connect that work to the broader machine learning strategy across Elastic Security.
Drive cross-platform protection parity. Bring the depth Elastic has on: Windows to macOS and Linux, keep the team ahead of new hardware architectures, and sustain the platform vendor relationships that give you early access to emerging operating system security APIs.
Represent the team externally. Support your engineers in presenting at: conferences and publishing on Elastic Security Labs, engage with customers and partners on protection capabilities, and be a credible voice for Elastic in the endpoint security community.
What they're looking for
- People-leadership experience managing senior technical individual: contributors on a globally distributed team. You lead with curiosity rather than authority, actively solicit feedback, and have a track record of growing people, not just shipping releases.
- You have been a practitioner. Substantial hands-on experience as a security: researcher before moving into leadership: analyzing attacker tactics, techniques, and procedures (TTPs), building the protections that counter them, and shipping into software that runs on customer machines at scale.
- Operating system internals knowledge , in both kernel and user mode, earned: hands-on rather than through oversight, and deep enough to reason about undocumented behavior and challenge a design on its technical merits. Windows depth is what we need most, with macOS or Linux close behind.
- Hands-on reverse engineering and malware analysis experience. You have done: this work yourself, and can still read a disassembly, assess a research finding on its merits, and judge which threats warrant investment.