Vp, Threat Research - Security Intelligence

Elastic Elastic · Enterprise · United States · Security - Cross Team

This role leads the threat research agenda for Elastic Security, focusing on AI-driven security capabilities, detection engineering, and publishing research. It involves setting the quality bar for detections, deciding investment areas like malware and AI security, and acting as the external face of the organization. The role requires deep technical credibility in threat research, detection engineering, endpoint security, or security ML, with a focus on setting direction through expertise and influence.

What you'd actually do

  1. Define the research and detection agenda across SIEM, endpoint, threat research, and security ML
  2. Set the quality bar for what Elastic detects, prevents, and publishes
  3. Decide where the team should invest next across malware detection, ransomware and memory protections, and AI-driven security capabilities
  4. Shape the publishing strategy for Elastic Security Labs, including original research, malware analysis, and conference content
  5. Act as the external face of the organization with customers, analysts, press, and the security community

Skills

Required

  • Deep credibility in threat research, detection engineering, endpoint security, or security ML
  • Hands-on technical experience
  • Ability to operate as a senior IC leader
  • Strong public communication skills
  • Clear belief in open, transparent security and the value of publishing detections and research openly
  • Strong judgment and ability to lead through influence, expertise, and vision
  • Experience setting strategy across technical security domains
  • A thoughtful point of view on AI in security
  • Willingness to travel regularly

Nice to have

  • Experience leading or contributing to publicly recognized threat research or detection content
  • Familiarity with open detection ecosystems, GitHub-based research workflows, or community-driven security programs
  • Experience spanning both endpoint protections and SIEM detections
  • Background working with malware models, behavioral detections, or small language models in security use cases
  • Existing presence in the security community through talks, publications, or media engagement

What the JD emphasized

  • Hands-on technical experience doing the work yourself, not only leading teams
  • A thoughtful point of view on AI in security, including both its promise and its risks

Other signals

  • AI-driven security capabilities
  • AI changes both threat research and attacker behavior
  • explainable AI-driven protections