R

Recorded Future

Machine-readable threat intelligence with VAR partnerships

Channel Account Manager

Full-Time
No salary listed
Mid
Remote in India
Remote

About the job

Requirements
  • Strong understanding of cybersecurity market trends and opportunities.
  • Insights into the Southeast market, including local partner dynamics.
  • Proficiency in developing and influencing key partner relationships.
  • Expertise in crafting and implementing partner go-to-market strategies.
  • Ability to train and support partners in selling products effectively.
  • Skills in conducting thorough account reviews and strategizing for improvement.
  • Ability to leverage internal teams for optimal execution of partner strategies.
Responsibilities
  • Identify and invest in strong partners based on success, potential, and strategic alignment with company goals.
  • Develop go-to-market plans mapping partner strengths to opportunities, tailored to their business models and deal history.
  • Equip partners with tools and knowledge to effectively present and sell company products.
  • Collaborate in organizing and executing marketing events to maximize lead generation.
  • Conduct regular account reviews with partners to improve go-to-market plan effectiveness.

About the company

Recorded Future provides machine-readable threat intelligence to help organizations lower the risk of cyber attacks. Its data can be integrated with customers' existing security tools and workflows used by SOCs, IR teams, and vulnerability programs. The company grows via a partner-led model with VARs, offering training, certifications, and marketing support to help partners sell and implement the technology. Revenue comes from direct sales and VAR partnerships with recurring revenue and margins, and its goal is to help organizations detect, understand, and respond to threats more effectively.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$58.7M

Headquarters

Somerville, Massachusetts

Founded

2009

Get referred to Recorded Future

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • June 2, 2026 Wipro partnership expands managed threat intelligence across global enterprises.
  • July 28, 2026 Pentera partnership turns intelligence into validated exposure reduction at Black Hat.
  • August 2026 Automated Signature Creation and AI Alert Filtering reduce analyst toil and accelerate remediation.

What critics are saying

  • Singh v. Recorded Future filed July 9, 2026, exposes post-acquisition labor friction.
  • Mastercard integration risks product autonomy; enterprise buyers shift budgets toward platform-native security vendors by 2027.
  • Threat-intelligence commoditization compresses pricing as Microsoft, Google, and CrowdStrike bundle similar enrichment.

What makes Recorded Future unique

  • Mastercard completed Recorded Future acquisition on December 20, 2024, amplifying distribution.
  • Its Intelligence Graph spans 200 billion nodes, spanning adversaries, infrastructure, and targets.
  • September 2026 MCP connects Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional development and career advancement

Flexible work environment, be yourself

Generous vacation policy

Wellness programs

Company outings

Competitive compensation and benefits

Free snacks, drinks, and coffee in the office

Parental leave program

Environmentally conscious

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 1%

2 year growth

↑ 8%
Runtime Revolution
Oct 1st, 2026
Recorded Future launches MCP for agentic security operations.

Recorded Future launches MCP for agentic security operations. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " AI agents can now make faster, more trustworthy security decisions by directly accessing Recorded Future intelligence. * " Affected systems include AI agents and LLMs like Claude, ChatGPT, Copilot, Cursor, and Gemini CLI in security workflows. * " Security teams should evaluate Recorded Future MCP to integrate trusted intelligence directly into their agentic security operations. Recorded Future unveils Model Context Protocol (MCP) for ai-driven security. Recorded Future has announced the general availability of its Model Context Protocol (MCP), a new offering designed to seamlessly connect AI agents with Recorded Future's extensive threat intelligence. This development addresses a critical need in the cybersecurity landscape, as both threat actors and security teams increasingly leverage artificial intelligence to automate and scale their operations. MCP provides a standardized, OAuth-authenticated gateway, allowing AI agents to directly pull trusted intelligence, thereby enhancing decision-making, improving reliability, and accelerating response times. The proliferation of AI-driven attacks, from automated reconnaissance to complex exploit development, necessitates a proportional response from defenders. Many security organizations are now adopting AI agents and copilots to manage their workloads. However, the effectiveness of these agents is inherently tied to the quality and trustworthiness of the intelligence they consume. As highlighted by Recorded Future, inconsistent or unreliable responses from large language models (LLMs) can introduce uncertainty and delays, underscoring the demand for a direct conduit to verified threat intelligence. Integrating AI agents with threat intelligence via MCP. Recorded Future MCP extends the company's established role as a trusted intelligence provider for human analysts directly to AI agents. It offers a catalog of over 80 tools that expose a broad set of capabilities from the Recorded Future Platform, including threat actor profiles, Recorded Future Risk Scores, ransomware metadata, malware sandbox data, and dark web intelligence. This direct access is crucial for integrating AI agents with threat intelligence efficiently. Key features and benefits of MCP include: * Direct, Standardized Access: Agents can access intelligence via OAuth authentication, ensuring secure and consistent data retrieval. * Broad Compatibility: MCP works with popular LLM clients and AI agents, including Claude, ChatGPT Enterprise, Copilot, Cursor, and Gemini CLI. * Enhanced Decision Making: By crawling the Intelligence Graph directly, agents can find related entities and context in fewer calls, reducing latency and cost while providing comprehensive situational awareness. * Write Capabilities: Agents can now write to Watch Lists and author Platform Analyst Notes, enabling a closed-loop between analysis and configuration. This capability allows agents to automatically update intelligence based on their findings, such as keeping a tech stack Watch List current as new tools are adopted. Automating security operations with Recorded Future MCP. Through a pilot program involving over 100 enterprise customers, Recorded Future identified three primary usage patterns demonstrating the power of automated security operations with Recorded Future MCP: * Automated Enrichment and Detection Engineering: Customers are replacing manual indicator of compromise (IOC) and CVE lookups with bulk enrichment directly integrated into security information and event management (SIEM) and security orchestration, automation, and response (SOAR) logic. This ensures alerts arrive pre-enriched, facilitating automated threat-actor profiling and malware analysis. * Executive and Leadership Reporting: Automated reports on threat landscapes and risk posture can be generated, transforming time-consuming manual assemblies into recurring, low-effort briefings, including compliance-driven reports for high-risk CVEs and ransomware profiles. * Incident Response and Threat Hunting Acceleration: MCP-driven triage and escalation capabilities are integrated directly into decision points, significantly shortening the path from detection to action. This allows human responders to focus on complex aspects requiring human judgment, while agents handle the initial legwork. Recommendations for leveraging agentic security. Security professionals should consider how integrating a dedicated intelligence layer like Recorded Future MCP can enhance their agentic security operations. For existing Recorded Future customers, MCP is available if your subscription includes unlimited integrations; support resources or account directors can provide assistance. Organizations not yet leveraging Recorded Future intelligence are encouraged to request a demo to understand how this protocol can provide their AI agents with the trusted context needed to make critical security decisions at machine speed and scale. Evaluating such solutions is vital for enhancing incident response with agentic AI and staying ahead of evolving threats.

Vialynx Inc
Sep 17th, 2026
Recorded Future named a Leader in External Threat Intelligence by independent research firm.

Recorded Future named a Leader in External Threat Intelligence by independent research firm. Technology · SEP 17, 2026 PR Newswire Company Received the Highest Score Possible in Twelve Criteria and Above Average Customer Feedback BOSTON, Sept. 17, 2026 /PRNewswire/ - Recorded Future,... Company Received the Highest Score Possible in Twelve Criteria and Above Average Customer Feedback BOSTON, Sept. 17, 2026 /PRNewswire/ - Recorded Future, the world's largest threat intelligence company, today announced that it has been named a Leader in The Forrester Wave(TM): External Threat Intelligence Service Providers, Q3 2026. In this evaluation, Recorded Future received above-average customer feedback and the highest possible score in 12 criteria, including Deep and Dark Web Monitoring, Roadmap, and Third-Party and Supply Chain Intelligence. Cyber, fraud, and third-party risks increasingly converge across the same infrastructure, identities, suppliers, and financial systems. Recorded Future helps organizations understand the external environment before threat activity becomes impactful. Its platform combines proprietary collection with the Intelligence Graph(R), analysis from Insikt Group(R), AI-driven analytics, and autonomous capabilities, then connects the resulting intelligence to customer workflows across Cyber Operations, Digital Risk Protection, Third-Party Risk, and Payment Fraud. "Attackers operate across domains and at machine speed. Defenders need intelligence that gives them time to act. We believe our position as a Leader reflects the trust customers place in Recorded Future to surface relevant threats early and connect them to the decisions that protect their institutions. We are expanding that work with Mastercard across cyber, fraud, and third-party risk," said Colin Mahony, Chief Executive Officer of Recorded Future. The Intelligence Graph contains more than 200 billion nodes of specialized threat data, giving human analysts and AI systems a shared view of adversaries, infrastructure, and targets. Recorded Future is building autonomous and agentic workflows that put this context to work earlier in the decision cycle, reducing manual effort while preserving human control over consequential decisions. "The next phase of threat intelligence depends on making reliable intelligence usable by both people and agents. We are building autonomous and agentic workflows on top of proprietary collection and expert analysis so customers can move from signal to investigation and action with context, provenance, and control intact," said Jamie Zajac, Chief Product Officer of Recorded Future. Recorded Future is also extending its intelligence across fraud and payments with Mastercard. It's bringing external threat intelligence into third-party and supply chain risk to help teams identify exposure deeper in their extended ecosystem and make decisions with a more complete view of external risk. Together with RiskRecon, another Mastercard company, Recorded Future brings external threat intelligence into third-party and supply chain risk, helping teams identify exposure deeper in their extended ecosystem and make decisions with a more complete view of external risk. Access a complimentary copy of the report at: Research citation The Forrester Wave(TM): External Threat Intelligence Service Providers, Q3 2026, Forrester Research, Inc., September 17, 2026. Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester's objectivity here. About Recorded Future Recorded Future is the world's largest threat intelligence company, serving over 1,900 businesses and government organizations across 80 countries. The Recorded Future platform provides the most complete coverage of adversaries, infrastructure, and targets through the Intelligence Graph(R), which contains over 200 billion nodes of specialized threat data. By combining precise, AI-driven analytics with breakthrough autonomous capabilities, Recorded Future enables organizations to transform from manual threat intelligence limitations to Intelligence Operations that automatically operationalize threats across entire security ecosystems. Recorded Future was acquired by Mastercard (NYSE: MA) in 2024. Headquartered in Boston with offices around the world, Recorded Future continues to lead the evolution from traditional threat intelligence to automated risk mitigation. Media contact SOURCE Recorded Future Published by News Desk · WeeklyReviewer The WeeklyReviewer news desk monitors breaking developments around the clock - sourcing, verifying, and publishing real-time industry news across business, technology, politics, science, sports, and world affairs. Every story that comes through the Live Wire is reviewed for accuracy before publication, keeping our readers ahead of the curve without the noise.

Runtime Revolution
Sep 4th, 2026
Recorded Future's automated signatures combat AI exploits.

Recorded Future's automated signatures combat AI exploits. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " Immediate impact: AI-accelerated exploits shorten vulnerability exploitation windows, increasing enterprise risk. * " Affected systems: Organizations relying on manual vulnerability detection processes face significant defense challenges. * " Remediation: Automated Signature Creation rapidly generates detection logic, improving real-time vulnerability prioritization. Overview: accelerating vulnerability prioritization with automated signatures. Recorded Future has introduced Automated Signature Creation, a new capability within its Attack Surface Intelligence (ASI) platform designed to combat the escalating speed of AI-generated exploits. This enhancement aims to accelerate vulnerability detection and prioritization, allowing organizations to remediate exposures before adversaries can act. The new function automates the generation of detection logic, enabling the platform to identify specific vulnerable or exposed conditions across an organization's assets in near real-time, significantly shortening the window between vulnerability disclosure and potential exploitation, according to Recorded Future. The challenge: defending against ai-accelerated exploits. The landscape of cybersecurity threats is continuously evolving, with artificial intelligence now playing a significant role in accelerating the discovery and exploitation of vulnerabilities. Historically, the time from vulnerability discovery to exploitation has drastically decreased, from an average of 45 days in 2010 to 15 days in 2020, and currently, this window is often measured in hours. Advanced AI models are demonstrating the ability to automatically find zero-day vulnerabilities in critical software, a task once exclusive to highly specialized government units and research labs. This rapid weaponization of vulnerabilities renders traditional, manual security processes increasingly insufficient. For instance, Recorded Future previously detailed how manual signature creation for issues like CVE-2025-0994 in Trimble Cityworks, while effective, operated at a human pace. The urgency of this challenge is underscored by recent incidents, such as OpenAI's agents exploiting a zero-day vulnerability in Artifactory during the Hugging Face incident, illustrating the real-world implications of machine-speed exploitation. Technical deep dive: Automated Signature Creation vulnerability prioritization. Automated Signature Creation addresses the speed gap by generating production-ready detection signatures autonomously, often within as little as 31 minutes of a new vulnerability surfacing. This capability operationalizes detection logic by defining specific questions to ask an asset; a particular answer indicates a vulnerable state. This transforms general asset discovery into actionable intelligence on exploitable weaknesses. The system functions as a three-step early warning system, greatly increasing the number of in-platform signatures produced - a tenfold increase - and subsequently boosting detection events across customer assets. How Automated Signature Creation works. At its core, a 'signature' in this context is a piece of detection logic that queries an asset for a specific condition. If the asset's response matches a predefined pattern, it's identified as vulnerable. This is crucial for defending against AI-accelerated exploits because it shifts from reactive, human-paced analysis to proactive, machine-speed detection. For example, during one week in August 2026, automated signatures accounted for nearly 20% of all critical-severity events and over 25% of all high-severity events detected within ASI, demonstrating its impact on threat visibility and prioritization. Alignment with CISA directive vulnerability mitigation. The compressed time to exploitation has also prompted new policy directives for federal agencies, such as the CISA directive issued on June 10, 2026, which aims to improve how federal agencies prioritize vulnerability mitigation. This directive outlines specific criteria for prioritization, which directly map to Recorded Future's capabilities. Automated Signature Creation effectively operationalizes this risk-based prioritization approach, making it an invaluable tool not only for federal agencies but for any organization seeking to adopt a more proactive and risk-aligned security posture. Recommendations for defenders. Given the accelerating pace of vulnerability exploitation, security teams must evolve their defensive strategies beyond traditional, manual processes. To effectively counter AI-accelerated threats and improve automated signature creation vulnerability prioritization, consider the following: * Embrace Automated Detection: Invest in platforms that offer automated signature generation and real-time vulnerability detection to reduce the window of exposure. * Prioritize Based on Risk: Implement frameworks that align with directives like the CISA guidance, focusing on vulnerabilities with known exploitation, high impact, and broad applicability. * Maintain Comprehensive Asset Visibility: Ensure a continuous and accurate mapping of your external attack surface to identify all internet-facing assets that could be exposed. * Integrate Threat Intelligence: Leverage current threat intelligence to understand which vulnerabilities are being actively exploited in the wild and prioritize patching efforts accordingly. By adopting these strategies, organizations can better position themselves to defend against the rapid and sophisticated threats emerging from AI-driven exploitation.

Recorded Future
Aug 26th, 2026
Recorded Future Launches AI Alert Filtering

Recorded Future Launches AI Alert Filtering PUBLISHED ON 26 AUG 2026 Jess Pagonis, Product Marketing

Security Arsenal
Aug 20th, 2026
Recorded Future adds native risk ratings to Third-Party Risk: what defenders should do with it.

Recorded Future adds native risk ratings to Third-Party Risk: what defenders should do with it. Security Arsenal Team August 20, 2026 Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting external threat intelligence and point-in-time vendor risk ratings in a single workflow. For security teams drowning in questionnaire-driven vendor assessments and disconnected scoring tools, this is a meaningful architectural shift - not just a feature checkbox. Third-party compromise remains one of the most reliable initial access vectors Security Arsenal see in incident response engagements. MoveIT, the 3CX supply-chain compromise, and the steady drumbeat of managed service provider intrusions all share the same pattern: the attacker's path of least resistance ran through a vendor the victim had assessed once, on paper, and never monitored again. The 2025-2026 threat landscape has only sharpened this reality, with ransomware groups and nation-state operators alike deliberately targeting downstream dependencies to multiply their access. The defensive question this launch addresses is simple: are you scoring your vendors continuously based on real-world exposure, or are you scoring them based on what they told you in a spreadsheet 14 months ago? What Recorded Future actually shipped. Based on the announcement, the key changes to the Third-Party Risk product are: * Native risk ratings inside the Third-Party Risk workflow. Risk ratings are no longer a separate tool or data feed you pivot between - they are embedded directly where analysts perform vendor assessments and monitoring. This eliminates the swivel-chair problem between a ratings platform and an intelligence platform. * Unification of threat intelligence and ratings. Recorded Future's core strength is its intelligence graph - dark web chatter, exposed credentials, vulnerability references, infrastructure signals, and geopolitical context. Folding that intelligence directly into vendor risk ratings means a vendor's score reflects observable, current external exposure rather than static self-attestation. * A single workflow for assess-and-monitor. Practically, this means a third-party risk analyst can onboard a vendor, see its continuously updated rating, understand why the rating moved (e.g., newly observed leaked credentials, an exposed service, a mention in ransomware leak site activity), and trigger action - without leaving the product. This is not a vulnerability, CVE, or exploit - there is no patch to deploy. This is a capability launch, and the defensive value depends entirely on how your organization operationalizes it. Why this matters to defenders in 2026. Three trends make continuous, intelligence-driven third-party risk scoring operationally relevant right now: * Regulatory and contractual pressure is continuous-monitoring-shaped. NIST CSF 2.0's Govern function explicitly calls out supply chain risk management as an organizational responsibility. PCI DSS 4.0 requirements around third-party service providers (12.8.x) demand ongoing oversight, not annual attestation. Cyber insurers increasingly ask for evidence of continuous vendor monitoring during underwriting and claims. * Questionnaires don't catch compromise. A vendor can pass your SIG Lite assessment in January and be listed on a ransomware leak site in March. If your risk posture for that vendor only updates at renewal, you have an 11-month blind window - during which that vendor may still hold network access, API credentials, or your data. * Alert fatigue from disjointed tooling. Teams that bolt a security ratings service onto a separate TIP onto a separate GRC platform end up with three scores per vendor and no authoritative workflow. Consolidation into a single workflow - ratings plus the intelligence explaining the rating - is how you get analysts to actually act on score changes instead of ignoring them. Executive takeaways. Since this is a product capability announcement rather than a technical threat, the appropriate response is organizational, not signature-based. Here is what Security Arsenal recommend to clients evaluating or deploying this capability: * Inventory your third-party tiering before you buy anything. Risk ratings deliver value proportional to how well you've tiered your vendor population. Identify your critical vendors (those with network connectivity, data access, or operational dependency) and make them the mandatory scope for continuous monitoring. A rating on a vendor you can't act against is trivia. * Define response playbooks for rating changes before deployment. The most common failure mode Security Arsenal see with security ratings is alerting into a void. Decide now: what happens when a critical vendor's rating drops two grades? Who gets paged? Is there a contractual right-to-audit trigger? Can you suspend API keys or network peering while you investigate? A rating drop on a payroll provider, an MSP, or a SaaS platform holding customer data should kick off a defined workflow - vendor outreach, internal exposure assessment (what data/access does this vendor touch?), and documented risk acceptance or mitigation. * Use the intelligence behind the score, not the score itself. A letter grade is an executive communication device. The operational value sits in the drivers - leaked credentials attributed to the vendor's domain, exposed RDP or unpatched internet-facing services, mentions in criminal forums, ransomware victim listings. Train your analysts to drill into evidence and translate it into concrete questions for the vendor: "We observed credentials for yourdomain.com in a stealer log corpus on this date - confirm your remediation." * Integrate ratings into procurement and renewal gates. Third-party risk delivers the most leverage at contract time. Make the current rating and its trend line a required input for vendor onboarding and renewal decisions. Vendors respond to commercial pressure; a deteriorating score that threatens renewal gets remediation budgets approved faster than any security questionnaire. * Map coverage against your compliance obligations. If you're operating under NIST CSF 2.0, PCI DSS 4.0, HIPAA, or contractual flow-downs from customers, document exactly which third-party oversight controls this capability satisfies - and which it doesn't. Continuous external monitoring complements, but does not replace, contractual security requirements, right-to-audit clauses, and breach notification SLAs. * Plan for the fourth-party problem. A rating on your direct vendor doesn't automatically cover their subcontractors. Use the intelligence layer to identify concentration risk - multiple critical vendors dependent on the same upstream cloud, MSP, or software component - because that's where correlated failure lives. Bottom line. Recorded Future folding native risk ratings into Third-Party Risk is a sensible consolidation move that reflects where the discipline is heading: continuous, evidence-driven vendor assessment instead of point-in-time self-attestation. The tooling is the easy part. The organizations that extract real defensive value will be the ones that pair it with tiered vendor inventories, pre-built response playbooks for score degradation, and contractual teeth at procurement time. If your third-party risk program still runs on annual questionnaires and good intentions, this is the right moment to close that gap - before a vendor's incident becomes yours. Related resources. Is your security operations ready? Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.