
Director, Security Research
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United States.
• Lead the Sysdig Threat Research Team, responsible for adversary research and detection engineering.
• Establish the research agenda, detection content roadmap, and budget; finalize decisions regarding investigations and delivered work.
• Develop AI security research capabilities that encompass model and agent misuse, agentic tool exploitation, prompt-layer attacks, the AI supply chain, and AI-serving infrastructure.
• Convert research findings into precise detections and engaging blog posts.
• Guide and nurture a small team of researchers and engineers while maintaining a hands-on approach.
• Oversee managed rulesets, cloud and identity detections, and ensure detection quality.
• Perform adversarial validation of deployed rules to enhance coverage and resistance to evasion.
• Manage the detection platform, which includes toolchains, attack reproduction environments, behavior-based detection, and adversary-deception telemetry.
• Publish original findings, named campaigns, CVEs, conference presentations, and contributions to open-source projects.
• Collaborate with Marketing on content creation and promotional campaigns.
• Create reusable attack demonstrations, threat briefings, and advisory content for Sales Engineering and Customer Success teams.
• Work alongside Product Engineering on upcoming detection capabilities and analysis of attacker defeat strategies.
• Over 10 years of experience in security research, threat research, or detection engineering.
• More than 4 years of experience leading and developing research teams, with genuine ownership of an agenda, its results, and its budget.
• Proven record of original AI security research with published work or implemented detections in adversarial ML, agentic and tool-abuse attack paths, prompt-layer attacks, model supply chains, or attacks on AI-serving infrastructure.
• Proficiency in coding, building tools, and conducting hands-on analysis.
• Current application of agents for research purposes, along with insights into their limitations.
• Established public body of work that includes original discoveries, CVEs, named campaigns, conference presentations, or open-source tools utilized by others.
• Demonstrated ownership of detection content distributed to actual users.
• Extensive knowledge of Linux, containers, Kubernetes, and cloud internals at both the syscall and control-plane levels.
• Capacity to manage an open-ended research agenda while handling a customer-deadline-driven detection queue.
• Credibility with customers’ CISOs and researchers.
• Experience in building a research capability that previously did not exist.
• Familiarity with capable adversaries such as APT actors or advanced offensive cyber groups, including attribution tradecraft.
• Active involvement in open-source stewardship as a maintainer or significant contributor to a security project with dependent users.
• Experience with AI security frameworks such as MITRE ATLAS, OWASP Top 10 for LLM Applications, or NIST AI RMF as engineering challenges.
• Research recognized by mainstream media, CERTs, or cybersecurity defenders.
• Additional days off to focus on your well-being.
• 401(k) Retirement Savings Plan with a 3% company match.
• Maternity and Parental Leave.
• Mental health support for you and your family via the Modern Health app.
• Comprehensive health benefits package for you and your family.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.