Elastic logo
Elastic·Verified

Principal Product Manager - Identity Threat Detection & Response

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

What is The Role

We’re looking for a Principal Product Manager to guide the vision, strategy, and execution for Identity Threat Detection and Response (ITDR) within Elastic Security. Attackers not only break in - they log in. Identity is now a major target for attacks. These attacks can happen in on-premises setups, cloud environments, or with self-directed agents. Detecting and responding to identity-based attacks is essential for any modern Security Operations Center (SOC).

In this high-impact role, you will define how Elastic detects, investigates, and responds to identity-based threats, building on our Entity Analytics and Entity Store foundation to deliver a credible, differentiated ITDR function. You will also own the roadmap for securing non-human and AI agent identities within Elastic Security, one of the fastest-growing and least-governed attack surfaces in the enterprise. You will work at the intersection of identity, detection engineering, and AI, partnering with threat researchers, data scientists, and engineers, and evangelizing our approach to a global community of security practitioners.

What You Will Be Doing

  • Define and own the vision, strategy, and roadmap for a credible ITDR function within Elastic Security, evolving our Entity Analytics and Entity Store foundation from behavioral analytics into an identity-defense outcome.
  • Manage the plan for non-human and AI agent identities in Elastic Security. This involves modeling service accounts, workloads, secrets, and self-directed agents as important identities. Each identity will have its own behavior standards, ownership, and lifecycle. You will also establish how to detect identities that operate continuously and at machine scale.
  • Work with threat research and detection engineering. Focus on identity-specific threats. These threats include credential access, privilege escalation, and identity-based lateral movement. They also involve the abuse of identity providers and tokens. Ensure that these threats relate to real-world adversary tactics.
  • Drive the response and containment strategy. Turn detections into action using identity-system integrations and automated responses while maintaining human oversight for important actions.
  • Work closely with enterprise customers, security operations teams, sales, and solution architects to understand requirements for identity attacks, discuss priorities, and clarify product needs.
  • Work with the design team to develop investigation and response experiences that emphasize identity in the analyst workflow. Integrate identity signals with endpoint, cloud, and network data in the SIEM and XDR functions of our platform.
  • Gain deep knowledge of the identity-security market, key trends, and the changing threat landscape to develop a unique strategy and engage with analysts.
  • Be the product expert and evangelize Elastic's identity capabilities through content such as blog posts, talks, and open community interaction.

What You Bring

  • Extensive Experience: 10+ years of experience in product management or solution delivery for security products such as SIEM, XDR, EDR, identity security, or detection and response. A consistent record of leading sophisticated, data-intensive products from inception through launch and iterative growth.
  • Identity Security Depth: Solid knowledge of identity-based attack techniques and the identity fabric (Active Directory, cloud identity providers, SSO, OAuth, privileged access) across on-premises and cloud environments. Knowledge of ITDR as a discipline and experience with entity behavioral analytics (UEBA).
  • Non-Human Identity Expertise: Fluency in non-human identities, including service accounts, workloads, secrets, and AI agents, and why traditional human-identity rules do not apply to them.
  • AI and ML Fluency: Deep technical comprehension of the AI/ML landscape, including behavioral analytics, anomaly detection, LLMs, and agentic systems. Comfortable working with data scientists and engineers.
  • Bias to Action: Ability to advance quickly and learn from experiments and tests, utilizing AI tools to accelerate processes and clarify decisions.
  • Management and Influence: Demonstrated ability to lead across a matrixed organization, align stakeholders toward a common vision, and drive execution in a remote-first environment.
  • Communication Excellence: Outstanding spoken and written communication skills to distill complex detection engineering and identity concepts for technical and non-technical audiences.
  • Customer Obsession: Commitment to solving real-world customer problems and advocating for security analysts and detection engineers.

Compensation & Benefits

  • Typical starting salary range: €84,300 — €109,500 EUR (Base salary only, no variable compensation component)
  • Health coverage for you and your family in many locations
  • Flexible work schedule and locations
  • Generous paid time off / vacation days
  • Up to $2,000 donation matching
  • Up to 40 hours per year for volunteer projects
  • Minimum 16 weeks of parental leave

Timezone overlap

UTC+0–+3

Open to

Europe

Sign in to track applications and earn points.

More roles at Elastic

Similar remote roles