远程工作雷达

高级产品经理(XDR 与暴露管理)

Principal Product Manager (XDR & Exposure Management)

AI职能支持限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡
公司Elastic
薪资未公开
工作地点Switzerland
地域资格限定地区(需当地身份)
时区要求日间重叠约 2 小时,需偶尔早起或晚睡
用工类型permanent
发布时间22 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 Switzerland 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠约 2 小时,需偶尔早起或晚睡。

Elastic,搜索AI公司,让每个人都能实时使用所有数据找到他们需要的答案——释放企业和个人的潜力。Elastic搜索AI平台被超过50%的财富500强企业使用,将搜索的精准性和AI的智能结合,使每个人都能加速实现关键成果。通过利用所有结构化和非结构化数据——更有效地保障和保护隐私信息——Elastic基于云的搜索、安全和可观测性完整解决方案帮助组织实现AI的承诺。

**职位描述**

Elastic Security正在寻找一位高级产品经理,负责XDR以及与之融合的暴露和漏洞管理功能。最佳的检测与响应产品建立在对攻击实际发生方式和防御者实际耗时位置的清晰理解之上。这种理解变得越来越难,而不是更容易。如今,SOC的工作范围涵盖被动检测和主动暴露,这两者正以比大多数供应商能适应得更快的速度融合成一个整体。

在这个职位上,你将全面负责XDR,从检测与响应核心到现在与之融合的暴露和漏洞管理功能。XDR是核心重心。暴露和漏洞管理是主要扩展方向,而周围的表面、攻击面和云配置则是你用来增强优先级判断的信号,而不是你需要从零构建的产品。你将成为CISO信任的人,能够解释为什么一个暴露比其他一千个更重要;成为工程负责人尊重的人,因为你的需求文档质量高;成为将快速变化的市场转化为Elastic可以赢得的路线图的人。你将在产品、工程和Elastic Security Labs研究团队的交汇点工作,这个平台统一的数据层是这里能够原生融合而非后期添加的原因。

**你将负责的工作**

- 全面负责跨领域检测与响应的XDR策略和交付,涵盖终端、云、身份和网络。从相关性分析和事件构建到响应操作,以及在机器速度下运行的闭环自动化,同时不让分析师脱离流程。

- 领导Elastic的XDR扩展进入暴露和漏洞管理领域。这包括如补丁管理、高级设备控制、主机防火墙管理等功能。

查看英文原文

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

**What is The Role**

Elastic Security is looking for a Principal Product Manager to own XDR and the exposure and vulnerability capabilities converging with it. The best detection-and-response products are built on a clear read of how attacks actually unfold and where defenders actually lose time. That read is getting harder, not easier. The SOC's job now spans reactive detection and proactive exposure, and the two are collapsing into a single motion faster than most vendors can reorganize around it.

In this role you will own XDR end to end, from the detection-and-response core through the exposure and vulnerability work now converging with it. XDR is the center of gravity. Exposure and vulnerability management is the primary expansion, and the surrounding surfaces, attack surface and cloud posture, are signals you bring in to sharpen prioritization rather than products you build from scratch. You will be the person a CISO trusts to explain why one exposure matters more than a thousand others, the person an engineering lead respects for the quality of your requirements, and the person who turns a fast-moving market into a roadmap Elastic can win on. You will work at the intersection of Product, Engineering, and the Elastic Security Labs research team, on a platform whose unified data layer is the reason convergence can be native here instead of bolted on.

**What You Will Be Doing**

- Own XDR strategy and delivery across cross-domain detection and response across endpoint, cloud, identity, and network. Work from correlation and incident building through response actions and the closed-loop automation that runs at machine speed without taking the analyst out of the loop.

- Lead Elastic's XDR expansion into exposure and vulnerability management. This includes features like patch management, advanced device control, host firewall management, and remediation workflow. You'll also manage noise reduction to ensure these capabilities are used successfully.

- Draw the line between XDR, exposure, and the adjacent surfaces such as attack surface and cloud posture, bringing those signals in as inputs rather than standing up separate products.

- Partner with the Entity Analytics team on the asset criticality and entity context that exposure prioritization depends on, so the two areas compound rather than collide.

- Serve as the product voice with senior customer stakeholders, including the CISO and VP of Security Operations, and deliver roadmap direction, including deprioritizations, without losing the room.

- Become the internal authority on the competitive landscape, including major security vendors and MDR service providers, and turn that into differentiated direction rather than talking points.

- Partner with engineering leads and Security Labs to write requirements they can act on without follow-up clarification meetings, and to ground detection and exposure scoring in real threat research.

- Create the artifacts, such as roadmap trackers, decision memos, and competitive briefs, that give customers and internal stakeholders visibility without requiring a meeting.

**What You Bring**

- Extensive Experience: 7–10 years of product management experience, with at least 4 years in security or B2B enterprise software. A consistent record of owning a product area with meaningful revenue impact and of leading products from strategy through shipped, iterated outcomes.

- Endpoint Detection and Response Domain Knowledge: Hands-on knowledge of XDR, EDR, SIEM, or broader security operations, either as a product manager or as a practitioner such as a SOC analyst, detection engineer, or incident responder. You can credibly discuss correlation, response automation, and detection engineering without a solutions engineer in the room. A practitioner background before transitioning into product is a solid plus and brings credibility that is hard to teach.

- Exposure and Vulnerability Fluency: You understand the difference between raw scanning, asset inventory, and true exposure prioritization, and why exploitability and reachability beat CVSS severity. You do not need to run a scanner yourself, but you know what makes prioritization credible enough that a team acts on it.

- Analytics and Threat Understanding: A solid comprehension of the analytics and data science techniques behind detection and prioritization, and of the current cyber threat landscape these capabilities defend against. Solid understanding is required; hands-on modeling is not. Familiarity with AI security, how AI, ML, and agentic systems are attacked and defended, is a solid plus.

- Technical Credibility: You earn respect from engineering through the quality of your requirements rather than through authority, and you know enough about architecture to judge feasibility and scope on your own.

- Executive Presence: You are comfortable as the primary product voice with C-suite and VP-level customer stakeholders, and you can deliver difficult news without losing the relationship.

- Cross-functional Fluency: You have operated across Product, Engineering, Sales, and Customer Success, and you know how to advance work across all of them.

- Default to AI-Augmented Work: You use AI tooling for synthesis, research, and delivery as a regular part of your workflow, and you own the final outcomes regardless of how they were produced.

- Management and Influence: Demonstrated ability to lead across a matrixed organization, align multiple stakeholders toward a common vision, and drive execution in a dynamic, remote-first environment. You operate with the autonomy and judgment expected of a principal-level product leader.

- Flexible working styles: You collaborate successfully with different functions and teams. You easily adapt to various projects, codebases, or teams based on the business's needs. You also work autonomously. You make decisions and achieve results in a distributed team by communicating clearly, directly, and openly.

### **Additional Information - We Take Care of Our People**

As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.

We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.

- Competitive pay based on the work you do here and not your previous salary
- Health coverage for you and your family in many locations
- Ability to craft your calendar with flexible locations and schedules for many roles
- Generous number of vacation days each year
- Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
- Up to 40 hours each year to use toward volunteer projects you love
- Embracing parenthood with minimum of 16 weeks of parental leave

Different people approach problems differently. We need that. Elastic is an equal opportunity employer and is committed to creating an inclusive culture that celebrates different perspectives, experiences, and backgrounds. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.

We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email [candidate_accessibility@elastic.co](mailto:candidate_accessibility@elastic.co). We will reply to your request within 24 business hours of submission.

Applicants have rights under Federal Employment Laws, view posters linked below: [Family and Medical Leave Act (FMLA)](https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/fmlaen.pdf) Poster;[Pay Transparency Nondiscrimination Provision](https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf) Poster; [Employee Polygraph Protection Act (EPPA)](https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/eppabw.pdf) Poster and [Know Your Rights](https://www.dol.gov/sites/dolgov/files/OFCCP/regs/compliance/posters/pdf/22-088_EEOC_KnowYourRights.pdf) (Poster)

Elasticsearch develops and distributes technology and information that is subject to U.S. and other countries’ export controls and licensing requirements for individuals who are located in or are nationals of the following sanctioned countries and regions: Belarus, Cuba, Iran, North Korea, Syria, or Russia, including the Ukrainian territories annexed by Russia (The Crimea region of Ukraine, The Donetsk People's Republic (DNR), The Luhansk People's Republic (LNR), Kherson or Zaporizhzhia). If you are located in or are a national of one of the listed countries or regions, an export license may be required as a condition of your employment in this role. Please note that national origin and/or nationality do not affect eligibility for employment with Elastic.

Please see [here](https://www.elastic.co/legal/applicant-privacy-statement) for our Privacy Statement.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级安全研究工程师,SONAR

ElasticSpain€67,000 - €106,000/年permanent5 天前
开发工程限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡

渠道代表

ElasticMexicopermanent6 天前
市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位