SlipstreamJobsFresh Startup & VC-Backed Jobs

Director, Security Research

Sysdig - Remote - Remote - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 245,000 - 307,000 / annual

Sysdig is seeking a Director of Security Research to lead the Threat Research Team (TRT), which combines adversary research and detection engineering. The company created Falco, the open standard for cloud threat detection, and is trusted by over 60% of the Fortune 500. In this role, you will own threat research end-to-end, including setting the research agenda, detection content roadmap, and budget. You will make AI security research a core focus—building capabilities against model and agent abuse, agentic tool misuse, prompt-layer attacks, AI supply chain threats, and infrastructure attacks. You will lead a small team of researchers and engineers, providing technical direction while staying hands-on with the work. Key responsibilities include: - Owning detection content that ships to Sysdig customers and the Falco community - Setting and executing the research agenda with final decision-making authority - Leading a team of researchers and engineers with hands-on technical involvement - Ensuring detection quality through adversarial validation and continuous improvement - Owning the detection platform, toolchain, and attack reproduction environments - Publishing original research, named campaigns, CVEs, and conference presentations - Partnering with Marketing, Product Engineering, and Sales Engineering to translate research into customer value - Building reusable attack demonstrations and threat briefings for field teams The role combines strategic leadership with hands-on technical work. You will publish research, speak at conferences, and contribute to open-source projects. Detection content quality is measured as an engineering metric, not a claim. You must balance long-term research agendas with customer-driven detection requests. REQUIREMENTS: - 10+ years in security research, threat research, or detection engineering - 4+ years leading and developing researchers with real ownership of agenda, outcomes, and budget - Original AI security research with published work or shipped detections (adversarial ML, agentic/tool-abuse attacks, prompt-layer attacks, model supply chain, or AI infrastructure attacks) - Hands-on technical skills: write code, build tooling, run analysis - Currently using AI agents for research work with informed opinions on limitations - Public body of work: original discovery, CVEs, named campaigns, conference talks, or open-source tooling - Experience owning detection content shipped to real users; understanding of rule evasion - Deep knowledge of Linux, container, Kubernetes, and cloud internals at syscall and control-plane levels - Ability to manage both open-ended research agendas and customer-deadline detection queues - Credibility with both CISOs and technical researchers PREFERRED QUALIFICATIONS: - Built a research capability from scratch at a company where you defined most of it - Experience with sophisticated adversaries (APT actors, advanced offensive groups) and attribution tradecraft - Open-source stewardship: maintainer or substantial contributor on security projects with dependent users - Experience with AI security frameworks (MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI RMF) as engineering problems - Research recognized by mainstream press, CERTs, or adopted by defenders

Similar roles