安全研究总监
Director, Security Research
在Sysdig,我们相信云安全不是一种妥协,而是一种承诺。从一开始,我们的使命就很明确:帮助组织以正确的方式保障云中的创新。
我们创建了Falco,这是云威胁检测的开源标准,并继续通过运行时洞察、开放创新和代理AI引领云安全市场。Sysdig的技术被超过60%的财富500强企业所信赖,为团队提供实时的清晰度,让他们快速行动并保护最重要的东西。
文化在这里至关重要。我们认为多样性能激发更强大的想法,开放对话能推动更精准的决策。连续五年被评为最佳工作场所之一,并且是德勤最快成长公司之一,我们致力于提升云安全和职场文化的标杆。
如果你有深入挖掘的热情,有挑战传统的需求,以及有构建更好事物的好奇心,那么Sysdig就是适合你的地方。
你将做什么
你将领导Sysdig威胁研究团队(TRT)。该部门分为两部分,你负责全部。对手研究是基于假设驱动的,并设定自己的议程。检测工程是需求驱动的,负责交付客户和Falco社区在生产环境中运行的检测内容。
我们特别招聘AI安全研究职位,而不是一般的威胁研究,而且我们在两个方向上都如此定义。一方面是对与AI相关的威胁进行研究:对模型、代理及其运行基础设施的攻击。另一方面是使用AI驱动的研究方法,让代理在规模上完成复现、分析和检测编写,这是人类无法匹敌的。我们将优先考虑那些已经在AI威胁方面发表过原创工作的候选人,并且已经使用AI驱动的研究方法进行开发的候选人。
这里的影响力非同寻常,你会继承真正的资产。这个团队所拥有的检测内容会交付给Sysdig客户,并通过Falco交付给所有运行我们创建的CNCF项目的用户。该团队发布的研究成果是Sysdig吸引受众的主要驱动力之一。而这些研究背后的证据来自于大规模的生产遥测数据。
全面监督威胁研究。确定研究议程、检测内容路线图和预算。你是这个团队调查什么和交付什么的最终决定者。
将AI安全研究作为核心重点。建立针对模型和代理滥用、代理工具误用、提示层攻击、AI供应链等的持续能力。
查看英文原文
At Sysdig, we believe cloud security isn't a compromise - it's a promise. From the start, our mission has been clear: to help organizations secure innovation in the cloud, the right way.
We created Falco, the open standard for cloud threat detection, and continue to lead the cloud security market with runtime insights, open innovation, and agentic Al. Creators of technology trusted by over 60% of the Fortune 500, Sysdig gives teams the real-time clarity to move fast and defend what matters most.
Culture matters here. We believe diversity fuels stronger ideas, and open dialogue drives sharper decisions. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, we're here to raise the standard for what cloud security and workplace culture should be.
If you have the passion to dig deeper, the desire to challenge convention, and the curiosity to build something better, Sysdig is the right place for you.
What you will do
You will lead the Sysdig Threat Research Team (TRT). The department has two halves, and you own both. Adversary research is hypothesis-driven and sets its own agenda. Detection engineering is demand-driven and ships the detection content our customers and the Falco community run in production.
We are hiring for AI security research specifically, not threat research generally, and we mean that in both directions. One direction is research into AI-related threats: attacks on models, agents, and the infrastructure they run on. The other is AI-driven research methods, where agents do reproduction, analysis, and detection authoring at a scale people cannot match. We will prioritize candidates who have published original work on AI threats and are already building with AI-driven research methods.
The reach here is unusual, and you inherit real assets. Detection content this team owns ships to Sysdig customers and, through Falco, to everyone running the CNCF project we created. The team's published research is one of the largest drivers of Sysdig's inbound audience. And the evidence behind that research comes from production telemetry at scale.
Oversee Threat Research end-to-end. Finalize the research agenda, the detection content roadmap, and the budget. You are the tie-breaker on what this team investigates and what it ships.
Make AI security research the center of gravity. Build a standing capability against model and agent abuse, agentic tool misuse, prompt-layer attacks, the AI supply chain, and attacks on the infrastructure that hosts it all. Turn what you find into a tuned detection, and a blog post.
Lead a small team of researchers and engineers, hands-on. Set their technical direction, expand what each can cover, and stay close enough to the work to be credible with the people doing it.
Own the detection content that ships. The managed ruleset, cloud and identity detections, and the quality of all of it. Rule quality is a number this team moves, not a claim it makes.
Hold our own detections to the standard you would apply to someone else's product. Run adversarial validation against the rules we ship and drive what you find to closure. Coverage and evasion resistance should be engineering measurements, not an annual exercise ending in a PDF.
Own the detection platform. The toolchain, the attack reproduction environments, behavior-based detection, and adversary-deception telemetry. Build in-house reproduction for every detection family we ship.
Publish and be the public voice of this work. Original discovery, named campaigns, CVEs, conference stages, and open-source contribution, all resourced and expected. This team's output is one of the most visible things Sysdig produces.
Partner with Marketing to turn research into content and campaigns that go beyond just the technical write-up.
Convert research into field capability. Build a library of reusable attack demonstrations, threat briefings, and advisory content, so Sales Engineering and Customer Success can carry this research into customer conversations on their own.
Partner with Product Engineering. Sit with Product on where detection capability goes next, and tell them how an attacker would defeat what they are about to build.
What you will bring with you
Have 10+ years in security research, threat research, or detection engineering, including 4+ years leading and developing researchers, with real ownership of an agenda, its outcomes, and its budget
Have done original AI security research and can point to published work or shipped detections: adversarial ML, agentic and tool-abuse attack paths, prompt-layer attacks, model supply chain, or attacks on AI-serving infrastructure
Are still hands-on: you write code, build tooling, and run the analysis yourself
Are already using agents to do research work, and have opinions about where that fails
Have a public body of work: original discovery, CVEs, named campaigns, conference talks, or open-source tooling that other people use
Have owned detection content that shipped to real users, and know the difference between a rule that fires and a rule that survives an attacker who knows it exists
Have depth in Linux, container, Kubernetes, and cloud internals at the syscall and control-plane level.
Can run a research agenda with no clock on it alongside a detection queue with customer deadlines, without letting either starve the other
Are credible with a customer's CISO and with your own researchers, without changing register much between them
What we look for
Built a research capability that didn't exist before, at a company where you had to define most of it yourself
Experience with capable adversaries such as APT actors or other sophisticated offensive cyber groups, including the tradecraft of attributing them
Open-source stewardship: maintainer or substantial contributor on a security project with users who depend on it
Worked against AI security frameworks such as MITRE ATLAS, the OWASP Top 10 for LLM Applications, or NIST AI RMF, as an engineering problem rather than a documentation exercise
Research that is well received: picked up by the mainstream press, cited by CERTs, or adopted by defenders
When you join Sysdig, you can expect
Extra days off to prioritize your well-being
401(k) Retirement Savings Plan with a 3% company match
Maternity and Parental Leave
Mental health support for you and your family through the Modern Health app
Full health benefits package for you and your family
The U.S. annual salary range for this full-time position is between 245,000 and 307,000 USD/year. Actual offers may be higher or lower than this range based on a variety of factors, including your work location, job-related experience and education.
We would love for you to join us! Please reach out even if your experience doesn't perfectly match the job description. We can always explore other options after starting the conversation. Your background and passion will set you apart, especially if your career path is different.
Sysdig values a diverse workplace and encourages women, people of color, LGBTQIA+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply. Sysdig is an equal-opportunity employer. Sysdig does not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity, or any other legally protected status.
#LI-FP1
#LI-Remote