Director, Security Research
@ SysdigDirector, Security Research
About the job
Sysdig is a cloud security firm creating open standards like Falco. The role focuses on AI security research, threat detection, leading a team, and publishing impactful work in a collaborative environment.
Requirements
- 10+ years security research experience
- Published AI security research
- Hands-on coding and tooling
- Experience with agents for research
- Owned detection content
Qualifications
- Experience with adversarial ML
- Depth in Linux, container, cloud
- Track record with CVEs or campaigns
- Credible with CISOs and researchers
- Experience with AI security frameworks
Full job description
What you will do
You will lead the Sysdig Threat Research Team (TRT). The department has two halves, and you own both. Adversary research is hypothesis-driven and sets its own agenda. Detection engineering is demand-driven and ships the detection content our customers and the Falco community run in production.
We are hiring for AI security research specifically, not threat research generally, and we mean that in both directions. One direction is research into AI-related threats: attacks on models, agents, and the infrastructure they run on. The other is AI-driven research methods, where agents do reproduction, analysis, and detection authoring at a scale people cannot match. We will prioritize candidates who have published original work on AI threats and are already building with AI-driven research methods.
The reach here is unusual, and you inherit real assets. Detection content this team owns ships to Sysdig customers and, through Falco, to everyone running the CNCF project we created. The team's published research is one of the largest drivers of Sysdig's inbound audience. And the evidence behind that research comes from production telemetry at scale.
What you will bring with you
- Have 10+ years in security research, threat research, or detection engineering, including 4+ years leading and developing researchers, with real ownership of an agenda, its outcomes, and its budget
- Have done original AI security research and can point to published work or shipped detections: adversarial ML, agentic and tool-abuse attack paths, prompt-layer attacks, model supply chain, or attacks on AI-serving infrastructure
- Are still hands-on: you write code, build tooling, and run the analysis yourself
- Are already using agents to do research work, and have opinions about where that fails
- Have a public body of work: original discovery, CVEs, named campaigns, conference talks, or open-source tooling that other people use
- Have owned detection content that shipped to real users, and know the difference between a rule that fires and a rule that survives an attacker who knows it exists
- Have depth in Linux, container, Kubernetes, and cloud internals at the syscall and control-plane level.
- Can run a research agenda with no clock on it alongside a detection queue with customer deadlines, without letting either starve the other
- Are credible with a customer's CISO and with your own researchers, without changing register much between them
What we look for
- Built a research capability that didn't exist before, at a company where you had to define most of it yourself
- Experience with capable adversaries such as APT actors or other sophisticated offensive cyber groups, including the tradecraft of attributing them
- Open-source stewardship: maintainer or substantial contributor on a security project with users who depend on it
- Worked against AI security frameworks such as MITRE ATLAS, the OWASP Top 10 for LLM Applications, or NIST AI RMF, as an engineering problem rather than a documentation exercise
- Research that is well received: picked up by the mainstream press, cited by CERTs, or adopted by defenders