← Back to results

Principal Product Manager - Identity Threat Detection & Response

Lead the vision and strategy for Identity Threat Detection and Response within Elastic Security, focusing on identity-based threats.

Location
United States
Compensation
$159.8k–$252.8k/yr
Level
principal
Type
full time · Hybrid

Posted by employer 1 month ago

First seen on Joblaze 1 month ago

Last verified on the company career page 21 hours ago

AI in the day-to-day

You are comfortable working closely with data scientists and engineers, and you treat AI agents both as a subject to be secured and as a tool that consumes identity context.

Requirements

Experience
10+ years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Volunteer Time Off Flexible Work Schedule Equity/Stock Options Generous Vacation Days Health Insurance Parental Leave

Joblaze summary

In the role of Principal Product Manager for Identity Threat Detection and Response at Elastic, the individual will focus on defining and executing strategies to combat identity-based threats within the company's security framework. This position requires expertise in identity security, including knowledge of attack techniques and the management of non-human identities, alongside a strong foundation in AI and machine learning. Ideal candidates will have over a decade of experience in product management within security domains, particularly in environments that demand rapid adaptation and collaboration across teams. Elastic's emphasis on innovative security solutions positions this role at th

Joblaze insights

  • Listed about a month ago — first seen on Joblaze August 13, 2026. Last confirmed on Elastic's careers page October 9, 2026.
  • This exact title is also open at 5 other locations at Elastic: Poland, Ireland, Canada, Greece, Spain.
  • Salary band is below the typical range for Product roles (median ~$184,000).
  • Starts above 12% of 26 comparable principal product roles in United States we track (median $201,850 across 18 companies).
  • XDR appears in 5.9% of 34 comparable principal product roles in United States; Identity Security appears in 2.9% of 34 comparable principal product roles in United States.

Quick facts

Is the Principal Product Manager - Identity Threat Detection & Response role remote?
It's hybrid — Elastic expects some on-site time in United States.
What's the salary range?
Elastic lists $159,800–$252,800 for this role.
How much experience is required?
At least 10 years of relevant experience for this Principal Product Manager - Identity Threat Detection & Response role.
Where is the role based?
Elastic is hiring for this position in United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, EDR, Entity Analytics, Entity Store, Identity Security, Identity Threat Detection.
What seniority level is this role?
Elastic targets principal-level candidates for this position.
Is this full-time or contract?
Full-time for this Principal Product Manager - Identity Threat Detection & Response role at Elastic.

From the original posting

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

What is The Role

We’re looking for a Principal Product Manager to guide the vision, strategy, and execution for Identity Threat Detection and Response (ITDR) within Elastic Security. Attackers not only break in - they log in. Identity is now a major target for attacks. These attacks can happen in on-premises setups, cloud environments, or with self-directed agents. Detecting and responding to identity-based attacks is essential for any modern Security Operations Center (SOC).

In this high-impact role, you will define how Elastic detects, investigates, and responds to identity-based threats, building on our Entity Analytics and Entity Store foundation to deliver a credible, differentiated ITDR function. You will also own the roadmap for securing non-human and AI agent identities within Elastic Security, one of the fastest-growing and least-governed attack surfaces in the enterprise. You will work at the intersection of identity, detection engineering, and AI, partnering with threat researchers, data scientists, and engineers, and evangelizing our approach to a global community of security practitioners.

What You Will Be Doing

  • Define and own the vision, strategy, and roadmap for a credible ITDR function within Elastic Security, evolving our Entity Analytics and Entity Store foundation from behavioral analytics into an identity-defense outcome.
  • Manage the plan for non-human and AI agent identities in Elastic Security. This involves modeling service accounts, workloads, secrets, and self-directed agents as important identities. Each identity will have its own behavior standards, ownership, and lifecycle. You will also establish how to detect identities that operate continuously and at machine scale.
  • Work with threat research and detection engineering. Focus on identity-specific threats. These threats include credential access, privilege escalation, and identity-based lateral movement. They also involve the abuse of identity providers and tokens. Ensure that these threats relate to real-world adversary tactics.
  • Drive the response and containment strategy. This is the 'R' in ITDR. Turn detections into action. Use identity-system integrations and automated responses. Make sure there is human oversight for important actions.
  • Work closely with our enterprise customers. Collaborate with security operations teams, sales, and solution architects. Your goal is to understand the requirements for identity attacks. You will also discuss priorities and clarify product needs.
  • Work with the design team to develop investigation and response experiences. These experiences will emphasize identity in the analyst workflow. Integrate identity signals with endpoint, cloud, and network data in the SIEM and XDR functions of our security operations platform.
  • Gain deep knowledge of the identity-security market. Know its major trends and the changing threat landscape. Use this information to develop a unique strategy and engage with analysts.
  • Be the product expert and evangelize Elastic's identity capabilities through content such as blog posts, talks, and open community interaction.

What You Bring

  • Extensive Experience: 10+ years of experience in product management or solution delivery for security products such as SIEM, XDR, EDR, identity security, or detection and response. A consistent record of leading sophisticated, data-intensive products from inception through launch and iterative growth.
  • Identity Security Depth: A solid knowledge of identity-based attack techniques and the identity fabric. This includes Active Directory, cloud identity providers, SSO, OAuth, and privileged access. It also involves knowing how identity threats can occur in both on-premises and cloud environments. Knowledge of ITDR as a discipline and with entity behavioral analytics (UEBA).
  • You need to be fluent in non-human identities. This includes service accounts, workloads, secrets, and AI agents. You should also understand why traditional human-identity rules don't apply to identities that act independently and continuously.
  • AI and ML Fluency: Deep technical comprehension of the AI/ML landscape, including behavioral analytics, anomaly detection, LLMs, and agentic systems. You are comfortable working closely with data scientists and engineers, and you treat AI agents both as a subject to be secured and as a tool that consumes identity context.
  • Bias to action: You are able to advance fast and quickly learn from experiments and tests. You utilize AI tools to help accelerate your processes and bring clarity to your decisions.
  • Management and Influence: Demonstrated ability to lead across a matrixed organization, align multiple stakeholders toward a common vision, and drive execution in a dynamic, remote-first environment. You operate with the autonomy and judgment expected of a principal-level product leader.
  • Communication Excellence: Outstanding spoken and written communication skills and practices. You can distill complex detection engineering and identity concepts into compelling narratives for both technical and non-technical audiences, including executive leadership.
  • Customer Obsession: An interest for industry trends and a commitment to solving real-world customer problems. You are an advocate for the security analyst and detection engineer, and you are focused on building products that help defenders stay ahead of identity-based threats.


Compensation for this role is in the form of base salary. This role does not have a variable compensation component.

The typical starting salary range for new hires in this role is listed below. In select locations (including Seattle WA, Los Angeles CA, the San Francisco Bay Area CA, and the New York City Metro Area), an alternate range may apply as specified below.

These ranges represent the lowest to highest salary we reasonably and in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the ranges may be modified in the future.

An employee's position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs.

Elastic believes that employees should have the opportunity to share in the value that we create together for our shareholders. Therefore, in addition to cash compensation, this role is currently eligible to participate in Elastic's stock program. Our total rewards package also includes a company-matched 401k with dollar-for-dollar matching up to 6% of eligible earnings, along with a range of other benefits offered with a holistic emphasis on employee well-being.

$185,600—$230,200 USD
The typical starting salary range for this role in the select locations listed above is:
$211,900—$278,000 USD

Additional Information - We Take Care of Our People

Please see here for our Privacy Statement.

Standard company text repeated across Elastic's postings is omitted here.

Similar positions