Director, Security Research

Sysdig, Inc.

Northern (KY)

Hybrid

USD 245,000 - 307,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Extra days off
401(k) Retirement Savings Plan with a
Parental Leave
Mental health support
Health benefits

Job summary

Sysdig, Inc. in the United States is seeking a senior AI security research leader to head the Threat Research Team. You will own the research agenda, build detection content, and drive AI threat projects from conception to production.

You will lead a hands‑on team, publish original work, and translate findings into detections and campaigns. The role blends adversarial research, model abuse detection, and enabling customers with concrete, battlefield‑ready content.

Qualifications

  • 10+ years in security research, threat research, or detection engineering.
  • 4+ years leading and developing researchers, with ownership of an agenda, outcomes, and budget.
  • Original AI security research or shipped detections: adversarial ML, agent‑abuse paths, prompt‑layer attacks.
  • Hands‑on: you write code, build tooling, and run analysis.
  • Public body of work: CVEs, named campaigns, talks, or open‑source tooling.

Responsibilities

  • Own Threat Research end‑to‑end: agenda, detection content roadmap, and budget.
  • Make AI security research the center of gravity; address model/agent abuse and AI supply chain issues.
  • Lead a small team of researchers and engineers, stay hands‑on.
  • Own the detection content and platform; ensure rule quality and robust telemetry.
  • Publish and be the public voice of this work with original discoveries and campaigns.
  • Partner with Marketing to turn research into content and campaigns.

Skills

AI security
Threat research
Detection engineering
Hands-on coding

Tools

Linux
Kubernetes
Cloud infrastructure

Job description

At Sysdig, we believe cloud security isn't a compromise - it's a promise. From the start, our mission has been clear: to help organizations secure innovation in the cloud, the right way.

We created Falco, the open standard for cloud threat detection, and continue to lead the cloud security market with runtime insights, open innovation, and agentic Al. Creators of technology trusted by over 60% of the Fortune 500, Sysdig gives teams the real-time clarity to move fast and defend what matters most.

Culture matters here. We believe diversity fuels stronger ideas, and open dialogue drives sharper decisions. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, we're here to raise the standard for what cloud security and workplace culture should be.

If you have the passion to dig deeper, the desire to challenge convention, and the curiosity to build something better, Sysdig is the right place for you.

What you will do

You will lead the Sysdig Threat Research Team (TRT). The department has two halves, and you own both. Adversary research is hypothesis-driven and sets its own agenda. Detection engineering is demand-driven and ships the detection content our customers and the Falco community run in production.

We are hiring for AI security research specifically, not threat research generally, and we mean that in both directions. One direction is research into AI-related threats: attacks on models, agents, and the infrastructure they run on. The other is AI-driven research methods, where agents do reproduction, analysis, and detection authoring at a scale people cannot match. We will prioritize candidates who have published original work on AI threats and are already building with AI-driven research methods.

The reach here is unusual, and you inherit real assets. Detection content this team owns ships to Sysdig customers and, through Falco, to everyone running the CNCF project we created. The team's published research is one of the largest drivers of Sysdig's inbound audience. And the evidence behind that research comes from production telemetry at scale.

  • Own Threat Research end-to-end. Set the research agenda, the detection content roadmap, and the budget. You are the final decision-maker on what this team investigates and what it ships.
  • Make AI security research the center of gravity. Build a standing capability against model and agent abuse, agentic tool misuse, prompt-layer attacks, the AI supply chain, and attacks on the infrastructure that hosts it all. Turn what you find into a tuned detection, and a blog post.
  • Lead a small team of researchers and engineers, hands-on. Set their technical direction, expand what each can cover, and stay close enough to the work to be credible with the people doing it.
  • Own the detection content that ships. The managed ruleset, cloud and identity detections, and the quality of all of it. Rule quality is a number this team moves, not a claim it makes.
  • Hold our own detections to the standard you would apply to someone else's product. Run adversarial validation against the rules we ship and drive what you find to closure. Coverage and evasion resistance should be engineering measurements, not an annual exercise ending in a PDF.
  • Own the detection platform. The toolchain, the attack reproduction environments, behavior-based detection, and adversary‑deception telemetry. Build in-house reproduction for every detection family we ship.
  • Publish and be the public voice of this work. Original discovery, named campaigns, CVEs, conference stages, and open-source contribution, all resourced and expected. This team's output is one of the most visible things Sysdig produces.
  • Partner with Marketing to turn research into content and campaigns that go beyond just the technical write-up.
  • Convert research into field capability. Build a library of reusable attack demonstrations, threat briefings, and advisory content, so Sales Engineering and Customer Success can carry this research into customer conversations on their own.
  • Partner with Product Engineering. Sit with Product on where detection capability goes next, and tell them how an attacker would defeat what they are about to build.
What you will bring with you
  • Have 10+ years in security research, threat research, or detection engineering, including 4+ years leading and developing researchers, with real ownership of an agenda, its outcomes, and its budget
  • Have done original AI security research and can point to published work or shipped detections: adversarial ML, agentic and tool‑abuse attack paths, prompt‑layer attacks, model supply chain, or attacks on AI‑serving infrastructure
  • Are still hands‑on: you write code, build tooling, and run the analysis yourself
  • Are already using agents to do research work, and have opinions about where that fails
  • Have a public body of work: original discovery, CVEs, named campaigns, conference talks, or open‑source tooling that other people use
  • Have owned detection content that shipped to real users, and know the difference between a rule that fires and a rule that survives an attacker who knows it exists
  • Have depth in Linux, container, Kubernetes, and cloud internals at the syscall and control‑plane level.
  • Can run a research agenda with no clock on it alongside a detection queue with customer deadlines, without letting either starve the other
  • Are credible with a customer's CISO and with your own researchers, without changing register much between them
What we look for
  • Built a research capability that didn't exist before, at a company where you had to define most of it yourself
  • Experience with capable adversaries such as APT actors or other sophisticated offensive cyber groups, including the tradecraft of attributing them
  • Open‑source stewardship: maintainer or substantial contributor on a security project with users who depend on it
  • Worked against AI security frameworks such as MITRE ATLAS, the OWASP Top 10 for LLM Applications, or NIST AI RMF, as an engineering problem rather than a documentation exercise
  • Research that is well received: picked up by the mainstream press, cited by CERTs, or adopted by defenders
When you join Sysdig, you can expect
  • Extra days off to prioritize your well‑being
  • 401(k) Retirement Savings Plan with a 3% company match
  • Maternity and Parental Leave
  • Mental health support for you and your family through the Modern Health app
  • Full health benefits package for you and your family

The U.S. annual salary range for this full-time position is between 245,000 and 307,000 USD/year. Actual offers may be higher or lower than this range based on a variety of factors, including your work location, job‑related experience and education.

Sysdig values a diverse workplace and encourages women, people of color, LGBTQIA+ individuals, people with disabilities, members of ethnic minorities, foreign‑born residents, and veterans to apply. Sysdig is an equal‑opportunity employer. Sysdig does not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity, or any other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Security Research
Director, Security Research

Sysdig • United States

On-site
USD 245,000 - 307,000
Extra days off
401(k) Retirement Savings Plan with 3%
Maternity and Parental Leave
+2
Director of Security Engineering
Director of Security Engineering

Sysdig • United States

On-site
USD 186,000 - 256,000
Extra days off
401(k) match
Parental leave
+2
Trust & Assurance Lead
Trust & Assurance Lead

Sysdig, Inc. • Northern (KY)

Hybrid
USD 144,000 - 176,000
Extra days off
401(k) match
Maternity leave
+2
Trust & Assurance Lead
Trust & Assurance Lead

Sysdig • United States

On-site
USD 160,000 - 200,000
Extra days off
401(k) match
Maternity leave
+2
Senior Customer Solutions Engineer (US East Coast)
Senior Customer Solutions Engineer (US East Coast)

Sysdig • United States

On-site
USD 130,000 - 163,000
Extra days off
401(k) with 3% match
Maternity and parental leave
+2
Enablement and Learning Program Manager
Enablement and Learning Program Manager

Sysdig, Inc. • Northern (KY)

Hybrid
USD 128,000 - 160,000
401(k) Retirement Savings Plan
Maternity and Parental Leave
Mental health support
+1
Senior AI & Product Enablement Specialist
Senior AI & Product Enablement Specialist

Sysdig • United States

Remote
USD 90,000 - 140,000
Extra days off
Mental health support
Competitive compensation
Manager, GEO & Web Strategy
Manager, GEO & Web Strategy

Sysdig, Inc. • Northern (KY)

Hybrid
USD 128,000 - 160,000
Extra days off
401(k) with 3% match
Maternity and Parental Leave
+2
Business Development Representative
Business Development Representative

Sysdig, Inc. • Northern (KY)

Hybrid
USD 64,000 - 80,000
Extra time off
401(k) with company match
Maternity/Parental Leave
+1
Senior Customer Solutions Engineer (US East Coast)
Senior Customer Solutions Engineer (US East Coast)

Socket.dev • United States

On-site
USD 130,000 - 163,000
Extra days off
401(k) Retirement Savings Plan with 3%
Maternity and Parental Leave
+2