Sailpoint
Manager, Cybersecurity Strategy and Risk
United States · Vp
Sponsorship not specified$124k-$209kDetected 30 days ago
Cloud PlatformsOAuthMachine LearningLLMsRAGAgentic AICybersecurityPenetration TestingSupply ChainCadenceCommunicationCollaboration
About the role
- A typical day: reviewing results from overnight autonomous testing campaigns, chaining minor vulnerabilities into high-impact proof-of-concept exploits, or handing validated attack playbooks to the CISO's Red Team.
- You won't write reports that sit in a queue.
- This is a greenfield offensive security unit within Product Security Engineering, reporting to the Director of Engineering Product Security.
Responsibilities
- You will translate adversarial findings into secure design improvements that change how engineering builds software.
- You will build and lead a continuous adversarial testing program against SailPoint's next-generation Atlas Platform, using frontier AI as a force multiplier, not a novelty.
- 30 Days - Assess & Design
- 60 Days - Build & Prepare
Requirements
- 5+ years of offensive security experience with at least 2 years in a team lead or management role
- Demonstrated experience with agentic or AI-powered offensive security tooling in a production program
- Hands-on proficiency in at least two of: application pen testing, source code security review, cloud security assessment, AI/LLM adversarial testing
- Bachelor's degree in a relevant field or equivalent experience
Nice to have
- authentication flow weaknesses, authorization logic flaws, entitlement calculation errors, and tenant isolation failures.
- AI/LLM attack surface expertise.
- You have tested adversarial attacks against AI systems, prompt injection, goal redirection, RAG poisoning, model supply chain compromise, or agentic scope escape.
- You know OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF as applied to offensive testing.
- Chain analysis and multi-step exploitation thinking.
- You think in attack paths, not individual findings.
- When you find a medium-severity issue, your instinct is to ask what it enables when combined, not to file it and move on.
- You write exploitation narratives that a VP of Engineering reads and acts on.
Skills
- Product Security Engineering
- About SailPoint
- SailPoint is the leader in identity security for the cloud enterprise.
Compensation
- $124,100 - $209,214.00 Base salaries for employees based in other locations are competitive for the employee's home location.
- We estimate the base salary, for
- Holidays: 8 paid holidays annually
Benefits
- As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation.
- Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
- Flexible vacation policy
- Health Savings Account (HSA) with employer contribution
- Parental support: Paid parental leave
Company info
- Complete a comprehensive review of the identity platform architecture, existing security practices, and current attack surface.
- Outline the optimal Red Team structure and identify critical hires based on the program's mandate for agentic AI and continuous testing.
- Deliver an initial strategic vision and program roadmap, clearly distinguishing this program from traditional penetration testing.
- Open recruiting pipelines and begin actively sourcing, screening, and extending offers for initial Red Team members.
- Draft rules of engagement in collaboration with Product Security and Engineering leadership.
- Complete a preliminary attack surface map of the core identity platform, prioritizing AI product features and agentic orchestration layers.
- Formalize the CISO Red Team partnership with a quarterly cadence for method transfer, tooling configurations, and attack playbooks.
- Formally define initial scope and target areas, prioritizing identity platform core and AI features.
- Select, deploy, and configure at least one agentic offensive security platform for autonomous source code analysis or vulnerability chaining.
- Plan and execute the first short-cycle adversarial campaign, establishing initial operational processes.
- Stand up preliminary threat intelligence integration for identity platforms, SaaS infrastructure, and AI/ML attack techniques.
- At least 50% of target headcount onboarded and actively contributing to adversarial campaigns with demonstrated proficiency in agentic AI tooling.
- Minimum three distinct continuous adversarial campaigns executed, including dedicated AI product feature testing, producing actionable findings.
- Minimum two detailed exploitation narratives resulting in concrete secure design improvements or SSDLC changes by engineering teams.
- CISO Red Team proving ground fully established, including at least one joint adversarial exercise completed.
- Full team operational capacity with agentic AI as a core capability, not a supplement.
- Overnight autonomous campaigns running continuously, delivering prioritized findings daily at 3-5x coverage of team size.
- Measurable reduction in high-severity vulnerabilities driven by Red Team findings feeding secure design improvements, threat model updates, and SSDLC enhancements.
- Attack methodology continuously reflecting current real-world TTPs, APT campaigns targeting identity providers, supply chain compromise vectors, and emerging AI-specific attack techniques.
- 401(k) Savings and Investment Plan with company matching
Visa & Work Authorization
- SailPoint does not discriminate on the basis of national origin or citizenship status as provided under the Immigration Reform and Control Act of 1986
Apply directly at Sailpoint →Create a free account for alerts like thisView Sailpoint immigration profile
This listing is sourced directly from Sailpoint's careers page and normalized into a canonical job model.