About The Position

The Elastic Security Endpoint Protections team builds the visibility, prevention, and on-device machine learning capabilities at the core of Elastic Defend, our endpoint and SIEM security solution. We work in kernel and user mode across Windows, macOS, and Linux, against adversaries who study how to defeat what we build. Our work reaches the security community as well as the product, through original research and conference talks. We are looking for a Senior Manager who has done this work personally and can still review a design or write code. You will lead a globally distributed team and set the tone for a group that values candid feedback, collaborative learning, and mentorship. We believe security is a team sport, and our efficacy is independently verified rather than simply claimed: in recent third-party enterprise protection testing, Elastic Security earned a perfect malware protection score with zero false alarms, the top result in the field. If you are energized by leading world-class engineers and making a measurable dent in how the industry defends the endpoint, we would love to hear from you!

Requirements

  • People-leadership experience managing senior technical individual contributors on a globally distributed team. You lead with curiosity rather than authority, actively solicit feedback, and have a track record of growing people, not just shipping releases.
  • You have been a practitioner. Substantial hands-on experience as a security researcher before moving into leadership: analyzing attacker tactics, techniques, and procedures (TTPs), building the protections that counter them, and shipping into software that runs on customer machines at scale.
  • Operating system internals knowledge, in both kernel and user mode, earned hands-on rather than through oversight, and deep enough to reason about undocumented behavior and challenge a design on its technical merits. Windows depth is what we need most, with macOS or Linux close behind.
  • Hands-on reverse engineering and malware analysis experience. You have done this work yourself, and can still read a disassembly, assess a research finding on its merits, and judge which threats warrant investment.
  • An adversarial instinct. You anticipate how a protection will be evaded before it ships, and hold the team to designing for resilience rather than for the proof of concept in front of them.
  • Clear communication skills, comfortable writing for technical and executive audiences and distilling deeply technical work for non-expert stakeholders.
  • Motivation to thrive in a distributed, autonomous environment, with a genuine passion for protecting customers from real-world adversaries.
  • Demonstrated experience leveraging AI-assisted development tools to accelerate feature development, debug complex systems, and optimize existing codebases.
  • You possess the ability to comfortably rotate across projects, collaborate across functions and teams, and seamlessly adapt to evolving team structures.

Nice To Haves

  • Prior ownership of an EDR, EPP, or other endpoint security product.
  • Personal research output: published vulnerabilities, patents, in-depth technical writing, or conference talks.
  • Experience leading machine learning engineers working on security problems.
  • Experience partnering with product engineering teams to take research prototypes through to GA release.
  • Conference speaking experience (e.g., Black Hat, DEF CON, CODE BLUE, Virus Bulletin).
  • Familiarity with the Elastic Stack (Elasticsearch, Kibana) and Elastic Security.

Responsibilities

  • Lead, mentor, and grow a world-class engineering team. Guide senior research engineers across endpoint internals, prevention engineering, and machine learning. Coach career development, deliver candid feedback, own the hiring pipeline, and set new engineers up to contribute quickly.
  • Own the roadmap and drive delivery. Decide where to invest in new visibility and where to deepen existing protection engines, balancing efficacy, performance, and stability across millions of endpoints. Work with product managers to define requirements and land high-quality features on release timelines.
  • Connect your team's work to the rest of Elastic Security. Every event source your team adds unlocks new detection and protection capabilities across the product. Invest in the joint planning, working relationships, and shared accountability that get your team's work into customers' hands.
  • Direct the team's machine learning work. Set direction on model development, training data quality, and the telemetry features those models depend on, and connect that work to the broader machine learning strategy across Elastic Security.
  • Drive cross-platform protection parity. Bring the depth Elastic has on Windows to macOS and Linux, keep the team ahead of new hardware architectures, and sustain the platform vendor relationships that give you early access to emerging operating system security APIs.
  • Represent the team externally. Support your engineers in presenting at conferences and publishing on Elastic Security Labs, engage with customers and partners on protection capabilities, and be a credible voice for Elastic in the endpoint security community.

Benefits

  • Competitive pay based on the work you do here and not your previous salary
  • Health coverage for you and your family in many locations
  • Ability to craft your calendar with flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
  • Up to 40 hours each year to use toward volunteer projects you love
  • Embracing parenthood with minimum of 16 weeks of parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service