Sailpoint

Sailpoint

Manager, Cybersecurity Strategy and Risk

United States · Vp

Sponsorship not specified$124k-$209kDetected 30 days ago
Cloud PlatformsOAuthMachine LearningLLMsRAGAgentic AICybersecurityPenetration TestingSupply ChainCadenceCommunicationCollaboration

About the role

  • A typical day: reviewing results from overnight autonomous testing campaigns, chaining minor vulnerabilities into high-impact proof-of-concept exploits, or handing validated attack playbooks to the CISO's Red Team.
  • You won't write reports that sit in a queue.
  • This is a greenfield offensive security unit within Product Security Engineering, reporting to the Director of Engineering Product Security.

Responsibilities

  • You will translate adversarial findings into secure design improvements that change how engineering builds software.
  • You will build and lead a continuous adversarial testing program against SailPoint's next-generation Atlas Platform, using frontier AI as a force multiplier, not a novelty.
  • 30 Days - Assess & Design
  • 60 Days - Build & Prepare

Requirements

  • 5+ years of offensive security experience with at least 2 years in a team lead or management role
  • Demonstrated experience with agentic or AI-powered offensive security tooling in a production program
  • Hands-on proficiency in at least two of: application pen testing, source code security review, cloud security assessment, AI/LLM adversarial testing
  • Bachelor's degree in a relevant field or equivalent experience

Nice to have

  • authentication flow weaknesses, authorization logic flaws, entitlement calculation errors, and tenant isolation failures.
  • AI/LLM attack surface expertise.
  • You have tested adversarial attacks against AI systems, prompt injection, goal redirection, RAG poisoning, model supply chain compromise, or agentic scope escape.
  • You know OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF as applied to offensive testing.
  • Chain analysis and multi-step exploitation thinking.
  • You think in attack paths, not individual findings.
  • When you find a medium-severity issue, your instinct is to ask what it enables when combined, not to file it and move on.
  • You write exploitation narratives that a VP of Engineering reads and acts on.

Skills

  • Product Security Engineering
  • About SailPoint
  • SailPoint is the leader in identity security for the cloud enterprise.

Compensation

  • $124,100 - $209,214.00 Base salaries for employees based in other locations are competitive for the employee's home location.
  • We estimate the base salary, for
  • Holidays: 8 paid holidays annually

Benefits

  • As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation.
  • Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
  • Flexible vacation policy
  • Health Savings Account (HSA) with employer contribution
  • Parental support: Paid parental leave

Company info

  • Complete a comprehensive review of the identity platform architecture, existing security practices, and current attack surface.
  • Outline the optimal Red Team structure and identify critical hires based on the program's mandate for agentic AI and continuous testing.
  • Deliver an initial strategic vision and program roadmap, clearly distinguishing this program from traditional penetration testing.
  • Open recruiting pipelines and begin actively sourcing, screening, and extending offers for initial Red Team members.
  • Draft rules of engagement in collaboration with Product Security and Engineering leadership.
  • Complete a preliminary attack surface map of the core identity platform, prioritizing AI product features and agentic orchestration layers.
  • Formalize the CISO Red Team partnership with a quarterly cadence for method transfer, tooling configurations, and attack playbooks.
  • Formally define initial scope and target areas, prioritizing identity platform core and AI features.
  • Select, deploy, and configure at least one agentic offensive security platform for autonomous source code analysis or vulnerability chaining.
  • Plan and execute the first short-cycle adversarial campaign, establishing initial operational processes.
  • Stand up preliminary threat intelligence integration for identity platforms, SaaS infrastructure, and AI/ML attack techniques.
  • At least 50% of target headcount onboarded and actively contributing to adversarial campaigns with demonstrated proficiency in agentic AI tooling.
  • Minimum three distinct continuous adversarial campaigns executed, including dedicated AI product feature testing, producing actionable findings.
  • Minimum two detailed exploitation narratives resulting in concrete secure design improvements or SSDLC changes by engineering teams.
  • CISO Red Team proving ground fully established, including at least one joint adversarial exercise completed.
  • Full team operational capacity with agentic AI as a core capability, not a supplement.
  • Overnight autonomous campaigns running continuously, delivering prioritized findings daily at 3-5x coverage of team size.
  • Measurable reduction in high-severity vulnerabilities driven by Red Team findings feeding secure design improvements, threat model updates, and SSDLC enhancements.
  • Attack methodology continuously reflecting current real-world TTPs, APT campaigns targeting identity providers, supply chain compromise vectors, and emerging AI-specific attack techniques.
  • 401(k) Savings and Investment Plan with company matching

Visa & Work Authorization

  • SailPoint does not discriminate on the basis of national origin or citizenship status as provided under the Immigration Reform and Control Act of 1986

This listing is sourced directly from Sailpoint's careers page and normalized into a canonical job model.