Vp, Threat Research - Security Intelligence

Elastic Elastic · Enterprise · United States · Security - Cross Team

This role leads the threat research agenda for Elastic Security, focusing on AI-driven security capabilities, detection engineering, and publishing research. It involves setting strategy, defining quality bars, and acting as the external voice for the organization, with a strong emphasis on the intersection of AI and cybersecurity.

What you'd actually do

  1. Define the research and detection agenda across SIEM, endpoint, threat research, and security ML
  2. Set the quality bar for what Elastic detects, prevents, and publishes
  3. Decide where the team should invest next across malware detection, ransomware and memory protections, and AI-driven security capabilities
  4. Shape the publishing strategy for Elastic Security Labs, including original research, malware analysis, and conference content
  5. Act as the external face of the organization with customers, analysts, press, and the security community

Skills

Required

  • Deep credibility in threat research, detection engineering, endpoint security, or security ML
  • Hands-on technical experience doing the work yourself
  • Ability to operate as a senior IC leader who sets direction through technical depth and strong judgment
  • Strong public communication skills and enthusiasm for customer engagement, speaking, and industry visibility
  • Clear belief in open, transparent security and the value of publishing detections and research openly
  • Strong judgment and the ability to lead through influence, expertise, and vision
  • Experience setting strategy across technical security domains and translating that into clear priorities
  • Thoughtful point of view on AI in security, including both its promise and its risks

Nice to have

  • Experience leading or contributing to publicly recognized threat research or detection content
  • Familiarity with open detection ecosystems, GitHub-based research workflows, or community-driven security programs
  • Experience spanning both endpoint protections and SIEM detections
  • Background working with malware models, behavioral detections, or small language models in security use cases
  • Existing presence in the security community through talks, publications, or media engagement

What the JD emphasized

  • AI-driven security capabilities
  • explainable AI-driven protections
  • AI changes both threat research and attacker behavior

Other signals

  • AI-driven security capabilities
  • AI changes both threat research and attacker behavior
  • explainable AI-driven protections