Skip to main content
Elastic

Principal Product Manager - Identity Threat Detection & Response

RemoteIreland only
Published
Role
Fullstack
Experience
Principal
Employment
Full-time
€104.8k–€165.7k/yr
Check eligibility

Open to IE only. Set where you work from to check your eligibility.

No BS summary

We’re looking for a Principal Product Manager to guide the vision, strategy, and execution for Identity Threat Detection and Response (ITDR) within Elastic Security. Attackers not only break in - they log in. Identity is now a major target for attacks.

Core skills

Identity Threat Detection and Response (ITDR)Entity AnalyticsEntity Store

Required skills

SIEM/XDR/EDR/identity security/detection and responseActive Directory/cloud identity providers/SSO/OAuth/privileged accessentity behavioral analytics (UEBA)AI/ML/behavioral analytics/anomaly detection/LLMs/agentic systems

Required languages

English unknown

What you'll do

  • Define and own the vision, strategy, and roadmap for a credible ITDR function within Elastic Security, evolving our Entity Analytics and Entity Store foundation from behavioral analytics into an identity-defense outcome.
  • Manage the plan for non-human and AI agent identities in Elastic Security. This involves modeling service accounts, workloads, secrets, and self-directed agents as important identities. Each identity will have its own behavior standards, ownership, and lifecycle. You will also establish how to detect identities that operate continuously and at machine scale.
  • Work with threat research and detection engineering. Focus on identity-specific threats. These threats include credential access, privilege escalation, and identity-based lateral movement. They also involve the abuse of identity providers and tokens. Ensure that these threats relate to real-world adversary tactics.
  • Drive the response and containment strategy. This is the 'R' in ITDR. Turn detections into action. Use identity-system integrations and automated responses. Make sure there is human oversight for important actions.
  • Work closely with our enterprise customers. Collaborate with security operations teams, sales, and solution architects. Your goal is to understand the requirements for identity attacks. You will also discuss priorities and clarify product needs.
  • Work with the design team to develop investigation and response experiences. These experiences will emphasize identity in the analyst workflow. Integrate identity signals with endpoint, cloud, and network data in the SIEM and XDR functions of our security operations platform.
  • Gain deep knowledge of the identity-security market. Know its major trends and the changing threat landscape. Use this information to develop a unique strategy and engage with analysts.
  • Be the product expert and evangelize Elastic's identity capabilities through content such as blog posts, talks, and open community interaction.

What they require

  • 10+ years of experience in product management or solution delivery for security products such as SIEM, XDR, EDR, identity security, or detection and response. A consistent record of leading sophisticated, data-intensive products from inception through launch and iterative growth.
  • A solid knowledge of identity-based attack techniques and the identity fabric. This includes Active Directory, cloud identity providers, SSO, OAuth, and privileged access. It also involves knowing how identity threats can occur in both on-premises and cloud environments. Knowledge of ITDR as a discipline and with entity behavioral analytics (UEBA).
  • You need to be fluent in non-human identities. This includes service accounts, workloads, secrets, and AI agents. You should also understand why traditional human-identity rules don't apply to identities that act independently and continuously.
  • Deep technical comprehension of the AI/ML landscape, including behavioral analytics, anomaly detection, LLMs, and agentic systems. You are comfortable working closely with data scientists and engineers, and you treat AI agents both as a subject to be secured and as a tool that consumes identity context.
  • Bias to action: You are able to advance fast and quickly learn from experiments and tests. You utilize AI tools to help accelerate your processes and bring clarity to your decisions.
  • Demonstrated ability to lead across a matrixed organization, align multiple stakeholders toward a common vision, and drive execution in a dynamic, remote-first environment. You operate with the autonomy and judgment expected of a principal-level product leader.
  • Outstanding spoken and written communication skills and practices. You can distill complex detection engineering and identity concepts into compelling narratives for both technical and non-technical audiences, including executive leadership.
  • An interest for industry trends and a commitment to solving real-world customer problems. You are an advocate for the security analyst and detection engineer, and you are focused on building products that help defenders stay ahead of identity-based threats.

Benefits

  • Competitive pay based on the work you do here and not your previous salary
  • Health coverage for you and your family in many locations
  • Ability to craft your calendar with flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
  • Up to 40 hours each year to use toward volunteer projects you love
  • Embracing parenthood with minimum of 16 weeks of parental leave

distributed, scalable, and highly available real-time search platform with a RESTful API

TechnologyEnterpriseelastic.co/elasticsearch/

What people say about this company

3.8/ 5

€104.8k–€165.7k/yr