> Markdown version of [/jobs/ext/2028570-manager-endpoint-protections](https://www.wearedevelopers.com/jobs/ext/2028570-manager-endpoint-protections). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Endpoint Protections - **Company:** Elastic - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Training Data, Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Apple Mac Systems, Collaborative Learning, Software Debugging, Linux, Elasticsearch, Machine Learning, Reverse Engineering, Security Information and Event Management, Unstructured Data, Malware, AI Platforms, Kibana, Operating System Security - **Published:** August 11, 2026 - **Apply:** https://jobs.elastic.co/jobs?gh_jid=8119448&gh_jid=8119448 ## About the Role * People-leadership experience managing senior technical individual contributors on a globally distributed team. You lead with curiosity rather than authority, actively solicit feedback, and have a track record of growing people, not just shipping releases. * You have been a practitioner. Substantial hands-on experience as a security researcher before moving into leadership: analyzing attacker tactics, techniques, and procedures (TTPs), building the protections that counter them, and shipping into software that runs on customer machines at scale. * Operating system internals knowledge, in both kernel and user mode, earned hands-on rather than through oversight, and deep enough to reason about undocumented behavior and challenge a design on its technical merits. Windows depth is what we need most, with macOS or Linux close behind. * Hands-on reverse engineering and malware analysis experience. You have done this work yourself, and can still read a disassembly, assess a research finding on its merits, and judge which threats warrant investment. * An adversarial instinct. You anticipate how a protection will be evaded before it ships, and hold the team to designing for resilience rather than for the proof of concept in front of them. * Clear communication skills, comfortable writing for technical and executive audiences and distilling deeply technical work for non-expert stakeholders. * Motivation to thrive in a distributed, autonomous environment, with a genuine passion for protecting customers from real-world adversaries. * Demonstrated experience leveraging AI-assisted development tools to accelerate feature development, debug complex systems, and optimize existing codebases. * You possess the ability to comfortably rotate across projects, collaborate across functions and teams, and seamlessly adapt to evolving team structures. Bonus Points * Prior ownership of an EDR, EPP, or other endpoint security product. * Personal research output: published vulnerabilities, patents, in-depth technical writing, or conference talks. * Experience leading machine learning engineers working on security problems. * Experience partnering with product engineering teams to take research prototypes through to GA release. * Conference speaking experience (e.g., Black Hat, DEF CON, CODE BLUE, Virus Bulletin). * Familiarity with the Elastic Stack (Elasticsearch, Kibana) and Elastic Security. ## Description Be an Early Applicant Remote Hiring Remotely in United States Senior level Remote Hiring Remotely in United States Senior level Lead and grow a global engineering team building endpoint visibility, prevention, and on-device ML across Windows, macOS, and Linux. Own roadmap and delivery, direct model development and telemetry, drive cross-platform protection parity, coordinate with product and partner teams, and represent the team externally through research and conferences. The summary above was generated by AI Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale - unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data - securing and protecting private information more effectively - Elastic's complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI. What is The Role The Elastic Security Endpoint Protections team builds the visibility, prevention, and on-device machine learning capabilities at the core of Elastic Defend, our endpoint and SIEM security solution. We work in kernel and user mode across Windows, macOS, and Linux, against adversaries who study how to defeat what we build. Our work reaches the security community as well as the product, through original research and conference talks. We are looking for a Senior Manager who has done this work personally and can still review a design or write code. You will lead a globally distributed team and set the tone for a group that values candid feedback, collaborative learning, and mentorship. We believe security is a team sport, and our efficacy is independently verified rather than simply claimed: in recent third-party enterprise protection testing, Elastic Security earned a perfect malware protection score with zero false alarms, the top result in the field. If you are energized by leading world-class engineers and making a measurable dent in how the industry defends the endpoint, we would love to hear from you! What You Will Be Doing * Lead, mentor, and grow a world-class engineering team. Guide senior research engineers across endpoint internals, prevention engineering, and machine learning. Coach career development, deliver candid feedback, own the hiring pipeline, and set new engineers up to contribute quickly. * Own the roadmap and drive delivery. Decide where to invest in new visibility and where to deepen existing protection engines, balancing efficacy, performance, and stability across millions of endpoints. Work with product managers to define requirements and land high-quality features on release timelines. * Connect your team's work to the rest of Elastic Security. Every event source your team adds unlocks new detection and protection capabilities across the product. Invest in the joint planning, working relationships, and shared accountability that get your team's work into customers' hands. * Direct the team's machine learning work. Set direction on model development, training data quality, and the telemetry features those models depend on, and connect that work to the broader machine learning strategy across Elastic Security. * Drive cross-platform protection parity. Bring the depth Elastic has on Windows to macOS and Linux, keep the team ahead of new hardware architectures, and sustain the platform vendor relationships that give you early access to emerging operating system security APIs. * Represent the team externally. Support your engineers in presenting at conferences and publishing on Elastic Security Labs, engage with customers and partners on protection capabilities, and be a credible voice for Elastic in the endpoint security community. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Debug a Kubernetes Operator](https://www.wearedevelopers.com/videos/487-debug-a-kubernetes-operator) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)