Staff Product Manager – EDR
As a Staff Product Manager – EDR, you will be tasked with owning the alert lifecycle within SentinelOne's EDR platform, from policy configuration and detection logic through indicators, alert artifacts, exclusions and mitigation rely on every day. You combine deep technical fluency in endpoint security and detection engineering with strong product and business judgment. You should have a track record of defining product features for complex, scalable systems, balancing customer needs, technical constraints, and business goals. Your roadmap will reflect clear priorities, drive growth and deliver lasting differentiation.
What Will You Do?
Primary responsibilities include:
Join a high-performing product team with a big impact.
Deepen your understanding of how our endpoint and big data platforms operate, and shape end-to-end capabilities that deliver market differentiation.
Write PRFAQs, roadmap decks, EPICs, and user stories for the alert lifecycle domain.
Partner with Detection Engineering and Threat Research on indicator/IOC strategy and behavioral rule development, partner with Data/ML teams where detections are model-driven.
Collaborate with Console, Agents, UX/UI, QA and field teams (MDR, Support) to ship reliable, well-instrumented releases.
Engage directly with customers, SOC analysts and prospects to uncover pain points in triage and investigation, and turn them into roadmap decisions.
Define and track the success metrics for the domain (below) and report on them to leadership.
What Skills and Knowledge Will You Bring?
Ideal candidates will have:
6+ years in product management, with a track record of shipping security software at scale.
Cybersecurity product experience is required, ideally in EDR/XDR, detection engineering or SOC-facing tooling.
Working knowledge of MITRE ATT&CK and ATLAS and how it's used to reason about detection coverage.
Demonstrated experience balancing detection coverage against false-positive rate and alert fatigue - you've made and defended that tradeoff before.
Technical fluency - comfortable reading telemetry/logs, writing basic queries (SQL or similar) against event/alert data and discussing agent-level concepts (e.g., kernel drivers, ETW/syscall hooking) credibly with engineers.
Strong communicator who can tell a compelling story and present clearly to both engineers and executives.
Experience with the AI threat landscape - either AI-powered detection/ML models or AI-generated attack techniques.
Prior hands-on experience as a threat hunter, security researcher, SOC analyst, or agent developer - Advantage.
Why SentinelOne?
AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.
We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:
Equity & Rewards
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
Competitive leave benefits
Gender-neutral parental leave
Employee Assistant Program
Workout sessions and a Wellness App
Insurance & Financial Security
Medical and insurance benefits
Pension
Employee Assistance Program (EAP)
Work Perks & Flexibility
Global home office allowance
Mobile phone reimbursement
Study Fund