Principal Security Research Manager
Lead, mentor, and develop a team of security researchers responsible for MDASH vulnerability discovery, validation, fix generation, and quality measurement. Define the research and quality roadmap for expanding MDASH coverage across vulnerability classes, programming languages, frameworks, codebase sizes, and real-world development patterns. Establish measurable quality goals and decision criteria across recall, precision, consistency, vulnerability validation, fix correctness, and end-to-end resolution. Direct the creation and curation of representative evaluation suites and trusted ground truth drawn from purpose-built vulnerable code, public benchmarks, open-source projects, internal codebases, and production feedback, ensuring the portfolio reflects real-world customer scenarios and guides measurable improvement in MDASH. Lead systematic analysis of false negatives, false positives, inconsistent detections, validation failures, and ineffective or incorrect fixes; translate findings into prioritized improvements to the techniques, tools, agent behaviors, model configurations, and analysis methods that power MDASH. Partner with MDASH engine, evaluation infrastructure, model, applied science, and product teams to integrate research improvements, establish release gates, and connect offline measurements with customer outcomes. Communicate technical strategy, evaluation results, risks, and investment priorities to senior leaders and cross-functional partners. Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience. 3+ years people management. Deep knowledge of vulnerability classes and exploitation patterns, including memory safety, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws. Experience with manual code review, static or dynamic analysis, fuzzing, symbolic execution, taint analysis, exploit development, or variant analysis. Experience designing security benchmarks, curating ground truth, calibrating evaluators, and measuring recall, precision, false-positive rates, or fix efficacy. Experience evaluating or building AI-assisted security systems, large language model applications, AI agents, automated graders, or human-in-the-loop evaluation workflows. Experience working across multiple programming languages and software ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications. Experience with responsible vulnerability disclosure or collaboration with open-source maintainers and product security response teams.