Full-Time

Account Executive

Chicago

Posted on 8/27/2025

Orca Security

Orca Security

501-1,000 employees

Agentless cloud security platform for multi-cloud

No salary listed

Company Does Not Provide H1B Sponsorship

Chicago, IL, USA

Remote

Category
Sales & Account Management (3)
, ,
Requirements
  • 3+ years of Cybersecurity enterprise sales experience and understanding of the competitive landscape
  • Executive level contacts in the region and prior sales experience hunting net new accounts
  • Repeated top performer in your region with stable record with at least 2+ years in each organization or upward growth within the same
  • Excellent communicator both written and verbal, with the ability to adeptly explain complicated concepts to a variety of audiences and skill level
  • Demonstrated experience with target account selling, solution selling, and/or consultative sales techniques. MEDDIC experience a plus
Responsibilities
  • Close new business opportunities in your region independently and cooperatively
  • Negotiate and bring to closure to customer agreements to exceed booking and revenue quota targets
  • Target key decision makers in prospect accounts and channel partners in the assigned territory
  • Establish and maintain existing relationships with key decision makers (typically at CISO level) and partners in the security industry to drive sales strategy and goal attainment
  • Cross functionally collaborate with Channel, Sales Engineering Marketing, Sales Operations, Product and Customer Success, to drive engagement at both the individual contributor and executive level
  • Report accurate pipeline and sales stage using Salesforce.com

Orca Security provides cloud security solutions through a Cloud Security Platform that unifies vulnerability management, cloud posture management, container security, cloud workload security, and multi-cloud compliance. It works by connecting to a client’s cloud environment and using its agentless CNAPP built on patented SideScanning to scan the entire cloud estate, revealing misconfigurations, vulnerabilities, identity risks, data exposure, API risks, and threats. The platform prioritizes the most significant cloud risks, identifies critical assets, and provides risk context across multi-cloud environments, enabling faster remediation. It also uses Generative AI to streamline tasks and improve understanding of the cloud landscape. Orca’s goal is to give organizations complete visibility and strong protection for all cloud-based assets across multi-cloud environments, reducing risk and simplifying security operations.

Company Size

501-1,000

Company Stage

Series C

Total Funding

$632M

Headquarters

Portland, Oregon

Founded

2019

Simplify Jobs

Simplify's Take

What believers are saying

  • TD SYNNEX distribution agreement scales North American partner ecosystem with streamlined procurement and enablement.
  • 84% of enterprises run vulnerable AI workloads; Orca's runtime AI detection addresses critical governance gap.
  • Opus acquisition enables agentic AI-powered remediation, evolving CNAPP from observation to automated fixes.

What critics are saying

  • Wiz's superior agentless scanning and faster prioritization erodes market share; 60–80% probability in 6–12 months.
  • Databricks Lakewatch undercuts CNAPP pricing 80% lower for petabyte-scale detection; 50–70% probability in 12–18 months.
  • Microsoft Agent 365 integrates natively with Azure, sidelining Orca's runtime AI detection; 70–90% probability in 12–24 months.

What makes Orca Security unique

  • Unified CNAPP platform eliminates fragmented point solutions across CSPM, CWPP, CIEM, DSPM.
  • Autonomous Threat Investigation and AppSec Triage agents reduce investigation time from hours to minutes.
  • Runtime AI detection tracks LLM calls, MCP servers, and shadow AI deployments across cloud estates.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

-1%
OpenClawAI
Mar 30th, 2026
Orca Security deploys AI agents to defend against AI agents - and that's not as recursive as it sounds.

Orca Security deploys AI agents to defend against AI agents - and that's not as recursive as it sounds. At RSAC 2026, Orca launches autonomous Threat Investigation and AppSec Triage agents, plus runtime AI detection that tracks every LLM call, MCP server, and shadow AI deployment across your cloud estate. OpenClaw Team The security industry has been talking about "AI for security" for years. But Orca Security's RSAC 2026 announcement is the first major platform release that treats AI agents as both the threat and the response - and connects them through a single data model. Two new autonomous agents, runtime AI detection that tracks every LLM call in your cloud, and a remediation workflow engine that turns findings into resolved issues. Here's what actually shipped. The Threat Investigation Agent. Security teams drown in alerts. Cloud environments generate thousands of findings, and the highest-skill, most time-consuming work isn't triaging - it's investigating. A senior analyst spends hours correlating signals across cloud logs, identity records, network flows, and application traces to determine whether an alert is a real incident or noise. Orca's Threat Investigation Agent does that work autonomously: * Ingests the alert with full context from Orca's Unified Data Model - workload metadata, identity chains, exposure details, network topology * Correlates signals across the environment, validating facts rather than making assumptions * Produces an investigation report with a verdict, evidence chain, and proposed containment actions * Explains its reasoning - every conclusion links back to the data that supported it The transparency piece is critical. Security agents that produce verdicts without explanations are useless in regulated environments. Orca's approach - transparent decision logic with visible reasoning chains - is the design pattern that enterprise security teams actually need. The practical impact: what previously took a senior analyst 2-4 hours of manual investigation now produces actionable results in minutes. Not by cutting corners, but by automating the correlation and fact-checking that consumes most investigation time. The AppSec Triage Agent. SAST scanners are notorious for false positive rates that erode developer trust. When 60-80% of your alerts are noise, developers stop looking at any of them. Orca's AppSec Triage Agent attacks this directly: * Analyzes code context of each SAST finding - not just the pattern match, but the surrounding logic * Determines false positive likelihood based on actual code behavior (e.g., "this open redirect has explicit URL validation upstream") * Automatically deprioritizes confirmed false positives by reducing risk scores * Lets humans override - every AI triage decision can be reviewed and reversed For confirmed true positives, the agent chains into Orca's existing AI-driven code remediation to generate pull requests with fixes. The full pipeline: detect | triage | fix | PR - mostly autonomous, with human review at the merge point. Runtime AI detection: the shadow AI problem gets a solution. This is the announcement with the biggest long-term implications. Orca Sensor now identifies actual runtime usage of AI across cloud environments, regardless of provider or programming language. Not static scanning. Not configuration auditing. Real-time detection of which workloads are calling which LLMs, sending what data, through which MCP servers. What Orca now tracks: | Detection | Why It Matters | | Which workloads invoke LLMs | Inventory of AI usage across the estate | | Sensitive data sent to models | Data loss prevention for AI workflows | | External MCP server connections | Shadow tool integrations | | AI provider and model identification | Vendor risk management | | Prompt injection vulnerability assessment | Application-level risk | | Internal vs. external AI interactions | Attack surface mapping | | Identity/process to AI correlation | Governance and attribution | This addresses the visibility gap that Microsoft's shadow agent research and AvePoint's AgentPulse have highlighted. You can't govern what you can't see. Orca's approach - correlating AI runtime activity with cloud context (workloads, identities, exposure, network) - produces a richer picture than AI-only governance tools. For OpenClaw users specifically: if your agent runs in a cloud environment, this is the kind of detection that will identify your MCP server connections, LLM API calls, and data flows. Understanding what enterprise security tools can see helps you build agents that play well with governance frameworks. Orca Missions: from findings to resolution. The fourth piece is less glamorous but potentially more impactful: Orca Missions groups related security findings into remediation workflows with objectives and verification steps. Instead of presenting 47 individual alerts about a misconfigured IAM role and its downstream effects, Missions creates a single workflow: "Remediate over-permissioned service account X - 47 related findings, 3 containment actions, verification criteria." Teams work through structured missions rather than swimming in alert soup. Code reachability analysis. Orca also adds code reachability analysis that determines whether vulnerable code paths are actually executed. A critical CVE in a dependency that's imported but never called is a different risk than one in a hot code path. Combining static analysis with runtime and agentless signals produces more accurate prioritization than any single method alone. The bigger picture. Orca's release fits a pattern OpenClaw has been tracking throughout RSAC 2026 pre-announcements: * Microsoft's Agent 365 governs agents at the platform level * Salt Security's Agentic Graph maps agent attack surfaces * OWASP AIVSS scores agent vulnerabilities * Orca's agents investigate threats and triage findings autonomously The stack is assembling: score risk (AIVSS), govern access (Agent 365), map attack surface (Salt), detect and respond (Orca). Each layer addresses a different aspect of the agentic security problem. The question is whether these pieces will interoperate - or whether enterprises will need to build their own integration layer. Orca is at Booth #1035 in the South Hall at Moscone, demonstrating all four capabilities live through March 26. Liked this article? Try OpenClaw. Stop reading about automation - start using it. OpenClaw connects to your email, calendar, code, and smart home from WhatsApp or Telegram. More OpenClaw guides and analysis connected by topic, tags, and content overlap. Security - Mar 30, 2026 At RSAC 2026, Splunk unveiled six specialized AI agents for Enterprise Security - from detection building to malware reversing to guided response. The SOC is no longer a human-only operation. Security - Mar 28, 2026 Proofpoint CEO Sumit Dhawan argues AI agents behave like human insiders: non-deterministic, manipulable, and capable of behavioral drift. The fix isn't firewalls - it's the same behavioral monitoring enterprises already use for employee insider risk. Security - Mar 28, 2026 Databricks enters the security market with Lakewatch - an open, agentic SIEM built on the lakehouse architecture. Backed by two acquisitions (Antimatter, SiftD.ai) and powered by Anthropic's Claude, it's designed for petabyte-scale threat detection at 80% lower cost than legacy SIEMs. Ready to try OpenClaw? Join the waitlist for managed hosting. OpenClaw'll notify you when your spot is ready. No credit card required. OpenClaw'll notify you when hosted service launches.

AiThority
Mar 16th, 2026
Orca Security Advances AI-First Cloud Defense with Autonomous Agents and Runtime AI Threat Detection

Orca Security advances ai-first cloud defense with autonomous agents and Runtime AI Threat Detection. Mar 16, 2026 Prev Next 1 of 42,811 Orca Security, the pioneer of agentless cloud security, announced major enhancements to the Orca Platform, introducing new AI-powered security agents, real-time detection of AI usage across cloud environments, remediation-focused workflows, and code reachability analysis. These innovations enable organizations to move beyond fragmented alerts to faster investigation, clearer prioritization, and measurable risk reduction in the AI-era. As enterprises accelerate AI adoption and scale across multi-cloud environments, security teams are inundated with alerts yet lack the context and prioritization needed to distinguish real, business-critical risk from background noise. Research shows that 84% of organizations now run AI workloads in the cloud, and 62% already have vulnerable AI packages in their environments. Orca's latest innovations extend its unified platform to help teams understand threats faster, focus on truly exploitable vulnerabilities, and take action with confidence. "Security teams don't need more data. They need to know what actually matters and what to do about it," said Gil Geron, CEO and co-founder of Orca Security. "These new capabilities are designed to turn complex cloud risk into clear, actionable guidance so teams can make faster decisions and reduce exposure in a measurable way. That shift from information to action is what ultimately improves security outcomes." New platform capabilities include: * Threat Investigation Agent: Orca's Threat Investigation Agent automatically analyzes risk, correlates signals across the cloud environment, and produces transparent investigation reports with recommended containment actions. * AppSec Triage Agent: The new AppSec Triage Agent analyzes SAST findings to identify false positives, reduce alert fatigue, and help teams focus on real vulnerabilities. * Runtime AI Threat Detection: Orca now identifies when workloads, identities, and processes interact with AI models, MCP servers, and third-party AI tools. This enables security teams to understand how AI is being used, detect potential exposure of sensitive data, and implement AI governance based on real runtime activity. * Orca Missions: Orca groups related findings into Missions - focused remediation initiatives with clear objectives and verification - allowing teams to resolve clusters of risk efficiently and track meaningful improvements in their security posture. * Code Reachability Analysis: Orca now analyzes whether vulnerable code paths are actually invoked in applications, in addition to identifying vulnerable packages. Combined with Orca's existing Agentless and Dynamic Reachability Analysis, this provides comprehensive context to help teams prioritize vulnerabilities that are truly exploitable. These enhancements build on Orca's agentless-first architecture, which provides deep visibility and risk prioritization across cloud infrastructure, workloads, identities, applications, and now AI systems, without requiring agents. "Cloud security tools generate an incredible amount of data, but what teams really need is help understanding what to do next," said Erika Voss, SVP, Chief Security Officer at Blue Yonder. "What stands out about Orca is the way it connects the dots. Instead of spending hours piecing together alerts, our team can see what actually happened, what's exposed, and where to focus first."

Business Wire
Mar 9th, 2026
Orca Security appoints Rachel Nislick as chief marketing officer

Orca Security has appointed Rachel Nislick as chief marketing officer. She brings over 25 years of experience building marketing organisations in cybersecurity and will lead global marketing strategy, brand development, demand generation and communications. Nislick previously served as vice president of revenue marketing at Darktrace, where she contributed to the company's growth towards $1 billion in annual recurring revenue and its acquisition by Thoma Bravo. Before that, she was vice president of growth marketing at Mimecast, helping drive growth from $150 million towards $1 billion in ARR before its acquisition by Permira. The appointment comes as Orca expands its agentless, AI-powered cloud security platform. The company is backed by Temasek, CapitalG and ICONIQ Capital.

Orca Security
Feb 17th, 2026
Orca Security: A Strong Performer in the 2026 Forrester Wave(TM) for Cloud Native Application Protection Solutions

Orca Security: A Strong Performer in the 2026 Forrester Wave(TM) for Cloud Native Application Protection Solutions. Published: Feb 17, 2026 Forrester has named Orca as a Strong Performer in The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026. In this evaluation of 14 vendors, the Orca Platform placed among the top CNAPP offerings in the market. Orca received above-average customer feedback in the evaluation process, along with the highest possible scores in 6 criteria within the current offering category: * CSPM cloud coverage * CIEM * Agentless cloud workload protection * IaC security * Agentic AI and co-pilots * Depth and breadth of third-party integrations Orca Security Ltd see these results as confirmation that its customers love Orca Security Ltd and that Orca Security Ltd is one of the best independent CNAPP solutions on the market. To Orca Security Ltd, this recognition by Forrester reinforces Orca's position at the forefront of cloud security, delivering on a strategy that is grounded in real-world, practical application. This report is an addition to its recent recognition from independent analyst firms, including being named Cloud Security Leader by Latio, and Leader in the GigaOm Radar Reports for CNAPP, Container Security, and Cloud Workload Security. Whether customers are innovating with AI, scaling growth, reducing costs, or outpacing their competitors, Orca supports their business objectives with robust CNAPP capabilities to cover everything from observation to action. "Agentless CWP is powerful for alerts on compute resources, as well as vulnerability and threat detection." The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026, by Andras Cser et al Customers that have experienced exponential growth in their cloud footprint, like Swiggy, love the quick time-to-value through agentless deployments to get a full picture of risk across their entire cloud estate. This also includes visibility into AI in running workloads, just as Autodesk has experienced while scaling their generative AI applications with AWS. The 2024 State of AI report found that 56% of organizations have adopted AI services for custom applications with integrations and data specific to their environment. When the Orca Research Pod revisited the data for the 2025 State of Cloud Security, they found that number surged to 84%. Orca Security Ltd believe as more organizations want to realize the benefits of AI in their cloud native applications, CNAPP solutions need to evolve from simply seeing issues to effectively acting on them. This means a balanced approach to agentless and sensor capabilities. Orca Sensor made its debut in this evaluation, scoring 3 out of 5 in the agent-based cloud workload protections criterion. To Orca Security Ltd, this reflects that its lightweight eBPF-based sensor is comparable to other agent-based cloud workload protections in the market. With key features like runtime privilege escalation & unusual network activity detections, file integrity monitoring, process termination through policy enforcement, and real-time detections on Window and Linux, Orca Sensor gives customers the agent-based protection they need without the performance toll that traditional agents cause. In order for security teams to act on CNAPP telemetry effectively, comprehensive data must be delivered through a well-integrated, opinionated platform. This includes analyzing, prioritizing, and mitigating attack paths that evaluate risk across identities, data sensitivity, external exposure, code origins, and real-time threats. "CIEM capabilities provide useful and visually pleasing access graphs, showing relationships between machine and human identities and data assets. Automatic revocation of excessive CSP admin roles is also ahead of the market." The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026, by Andras Cser et al At Orca, customer obsession isn't just a strategy for Orca Security Ltd - it's a mindset. It's baked into how Orca Security Ltd hire, build, and grow. Orca Security Ltd pride ourselves on a simple, transparent pricing structure that meets its customers needs for clear, reliable growth that doesn't crush their budget. Orca Security Ltd also don't just listen to its customers; Orca Security Ltd act on what Orca Security Ltd hear. Their feedback shapes its roadmap, and their success is how Orca Security Ltd measure ours. Its above-average customer feedback is reflected in the report. "Customers like the speediness of Orca Security's response to tech support cases..." The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026, by Andras Cser et al Interested in learning more about Orca? Explore the Orca Platform - the leading CNAPP solutions that supports AWS, Azure, Google Cloud, Oracle Cloud, Alibaba Cloud, and Tencent Cloud. To get a deeper look, schedule a personalized 1:1 demo. Disclaimer: Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, read about Forrester's objectivity here. Feb 16, 2026 Cloud Security Learning Feb 11, 2026 Stay in the loop. Keep up to date with everything you need to know about cloud security and its latest research

Orca Security
Jan 7th, 2026
Reduce External Exposure Risk for Cloud Native Apps with Akamai and Orca

Reduce external exposure risk for cloud native apps with Akamai and Orca. Orca Security Ltd is excited to share that Orca now integrates with Akamai, a global leader in content delivery, cloud services, and cybersecurity. This integration brings visibility from Akamai Edge DNS into the Orca Platform to extend its external exposure capabilities and protect the APIs and subdomains that are part of an organization's cloud native application. What is Akamai Edge DNS? Akamai delivers a variety of solutions to power and protect businesses online. Akamai Edge DNS is a globally distributed, highly scalable Domain Name System (DNS) service built for security and performance. Modern DNS distributed denial-of-service (DDoS) attacks are highly sophisticated and operate at massive scale. This makes it incredibly challenging to protect global businesses that depend on the 24/7/365 availability of their DNS infrastructure. Since DNS translates human-readable domains into machine-readable IP addresses, a DNS outage means your online presence goes offline - impacting websites, APIs, and applications. Akamai Edge DNS ensures resilience and speed, defending against a wide range of DNS attacks across cloud, on-premises, and hybrid environments. Know what Akamai subdomains directly impact your cloud native app in a unified view in Orca. Orca's patented SideScanning technology agentlessly inventories the web and API catalog for your cloud native applications - integrating with Akamai enriches this data by pulling in Akamai-registered domains and subdomains into a single unified inventory of cloud assets across AWS, Azure, Google Cloud, Oracle Cloud, and Alibaba Cloud. Security teams can drill into the details of an Akamai domain and its API hierarchy to quickly gauge its purpose, exposure, and risk. Security teams can also explore the graph to understand the relationships between Akamai domains and assets with other cloud service providers. The Orca Platform connects the dots between external exposure, network connections, workloads, identities, and sensitive data at risk. For example, in the image following, Orca shows how an Amazon EC2 instance is linked to an IP address hosted in AWS, but that connects to many Akamai domains, revealing a quick glimpse at the potential impact if the EC2 instance was compromised. Reduce external exposure with Akamai and Orca. The Orca Platform brings API Security, cloud workload protection, and application security under one umbrella since attacks on cloud native applications often span across multiple domains and attack vectors. With this integration, Orca's external scanner now probes all domains and subdomains discovered from Akamai, and security teams can now see alerts directly related with Akamai web and API endpoints, reducing investigation time to address misconfigurations, subdomain takeovers, and domain expiration. These alerts can be sent through existing workflow automation to the teams responsible for remediation, whether the team uses a SIEM to aggregate telemetry or ticketing workflows through Jira, ServiceNow, or other issue management systems. About the Orca Cloud Security Platform. Orca offers a unified and comprehensive cloud security platform that identifies, prioritizes, and remediates security risks and compliance issues across AWS, Azure, Google Cloud, Oracle Cloud, Alibaba Cloud, and Kubernetes. The Orca Cloud Security Platform leverages Orca's patented SideScanning(TM) technology to provide complete coverage and comprehensive risk detection. Learn more. Interested in discovering the benefits of the Orca Platform and how it can be integrated with tools like Akamai? Schedule a personalized 1:1 demo, and Orca Security Ltd'll show how you can use Orca to identify, prioritize, and remediate risks in your cloud environment. If you already use both Orca and Akamai, follow the steps in the documentation to set up the integration.

INACTIVE