Full-Time

VP of Product Management

Posted on 8/21/2025

Varonis

Varonis

1,001-5,000 employees

Data security platform with threat detection

No salary listed

United States

Hybrid

Hybrid work model; no city-specific office requirement stated.

Category
Product (2)
,
Required Skills
LLM
Microsoft Azure
UI/UX Design
Product Management
Machine Learning
AWS
Marketing
Google Cloud Platform
Requirements
  • A passionate, positive leader who thrives in complex, fast-moving environments
  • Strong communication and storytelling skills with the ability to influence across technical and non-technical stakeholders
  • 8+ years of experience in product management, with at least 5 years managing PMs and leading product lines
  • Proven success in delivering B2B SaaS or hybrid software products in data security, privacy, governance, or compliance domains
  • Experience building or scaling data classification products—whether content-based, metadata-based, AI-enhanced (ML/NLP/LLM), or policy-driven
  • Familiarity with privacy frameworks and regulations such as GDPR, CCPA, HIPAA, and frameworks like NIST or ISO 27701
  • Experience working with cloud infrastructure providers (AWS, Azure, GCP) and data systems (e.g., cloud storage, SaaS apps, databases)
  • Demonstrated ability to synthesize customer pain points into actionable roadmaps and drive cross-functional execution
  • Deep curiosity and empathy for customers; always looking for ways to solve real problems
  • Strong technical background (e.g., engineering or technical PM experience) is a plus
Responsibilities
  • Lead the strategy, vision, and execution for Varonis’ classification and privacy products portfolio
  • Manage and grow a team of experienced product managers across multiple product lines
  • Define and own the roadmap for sensitive data discovery, classification, labeling, and privacy-aware controls across cloud and on-premises environments
  • Deeply understand customer use cases for compliance (e.g., GDPR, CCPA, HIPAA), data governance, insider threat protection, and data loss prevention
  • Drive innovations in content-aware and context-aware classification, including AI-driven techniques such as ML, NLP, and LLM-based models to accurately identify and categorize sensitive data
  • Evaluate and incorporate emerging technologies (e.g., generative AI and large language models) to enhance classification accuracy, scalability, and real-time data understanding
  • Work hands-on with UX designers, engineering, and research teams to design thoughtful, scalable solutions
  • Partner with internal stakeholders including Customer Success, Sales Engineering, and Professional Services to understand deployment challenges and inform roadmap priorities
  • Engage regularly with customers and prospects to gather feedback and validate product direction
  • Collaborate with marketing and sales teams to position, launch, and drive adoption of new features and products
  • Track and analyze product usage, customer feedback, and market trends to iterate on product strategy
  • Serve as a subject matter expert and thought leader both inside and outside the organization on data classification and privacy topics

Varonis Systems focuses on protecting sensitive information from cyber threats by offering a data security platform that continuously monitors data, detects threats, and automates responses through advanced analytics and automation. The platform helps large enterprises, government agencies, and educational institutions secure data and meet regulatory requirements via subscription-based access, with a heavy emphasis on data monitoring, threat detection, and automated response. The company differentiates itself through a strong recurring revenue model (95% recurring) and high renewal rates (90%), reflecting steady income and high customer satisfaction, alongside a broad customer base. Its goal is to help customers protect data, prevent breaches, and stay compliant while growing its subscription-based business.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

New York City, New York

Founded

2005

Simplify Jobs

Simplify's Take

What believers are saying

  • SaaS ARR excluding conversions grew 29% in Q1 2026.
  • Claude Compliance API integration expands Atlas into Anthropic enterprise and developer workflows.
  • India's DPDPA compliance push creates channel demand through iValue and Varonis.

What critics are saying

  • Microsoft, Salesforce, AWS, and Google can bundle competing native controls.
  • AI security features commoditize quickly as platform vendors embed governance and testing.
  • Recurring guidance misses and GAAP losses keep valuation and execution scrutiny high.

What makes Varonis unique

  • Varonis unifies data security, AI security, and threat detection across SaaS, IaaS, and hybrid environments.
  • Atlas adds AI inventory, posture management, runtime guardrails, and compliance reporting.
  • The Enverus case proves Varonis detects Salesforce, Azure, and OAuth abuse together.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Varonis who can refer or advise you

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

0%
Varonis Systems
May 22nd, 2026
How Enverus secures Salesforce Data and prevents data breaches with Varonis.

How Enverus secures Salesforce Data and prevents data breaches with Varonis. Discover how Enverus partnered with Varonis to enhance Salesforce data security, improve threat detection, and prevent a major data breach. Last updated May 22, 2026 As Enverus expanded, its security team needed visibility into the entire data estate, the controls in place, and whether those controls were being enforced, especially within Salesforce, one of its most business-critical platforms. Enverus partnered with Varonis to gain deep visibility into sensitive data, access, permissions, and activity. Its partnership strengthened security, accelerated investigations, improved threat detection, and helped prevent a major data breach tied to a large-scale SaaS supply chain attack. Who is Enverus? Enverus is a decision-support platform serving organizations across the energy and energy infrastructure space, from small independent operators to the world's largest supermajors. The company manages large volumes of data spanning geophysical, petrophysical, operational, and infrastructure workloads, combining proprietary intellectual property with large public and third-party datasets. Visibility across a distributed data estate With data spread across cloud platforms, SaaS applications, and on-premises data centers and databases, each with its own permissions model, configurations, and operational team, Enverus needed consistent data security across its entire environment. The security team needed to answer fundamental questions: * What sensitive data exists across the enterprise? * Where does it live? * Who can access it? * Are controls consistently enforced across environments? A unified platform and security partner Varonis provided Enverus with unified data security across multiple platforms, including AWS, Azure, Salesforce, and Microsoft 365. Varonis gives the security team a comprehensive view of what sensitive data exists, where it lives, who can access it, and whether controls are consistently enforced. Varonis mapped identities across platforms and greatly reduced the blast radius. What had previously been difficult to operationalize became straightforward: identify the highest-risk access, right-size permissions, and report progress against enterprise policy. Enverus was able to move beyond static reviews and spreadsheet-driven analysis. "What surprised us most was Varonis' insight into the data plane from an identity and access perspective. That wasn't what we initially came for, but it's proven to be critical." Alex Acosta, Vice President of Security, Enverus At Enverus, the security and GRC teams define enterprise-wide security and data policies, while application teams own day-to-day platform operations. Varonis helps bridge these teams, providing dashboards and reporting, aligning platform controls to enterprise policy, and delivering consistent controls and visibility. The result is a unified approach that supports both security requirements and business objectives. Simplifying Salesforce data security Salesforce sits at the center of Enverus' operations, with numerous integrations, workflows, and data flows moving in and out of the platform. Salesforce combines business-critical data with complex identity controls and numerous integration points, making data security challenging. Over time, overlapping profiles, permission sets, roles, sharing rules, and connected apps can accumulate, making it difficult to understand a user's effective permissions or identify excess access. The challenge is compounded by the multitude of apps, agents, APIs, and sandboxes that can move data in and out of production and often retain long-lived tokens or create backdoors. Enverus needed: * Complete insight into identity-based permissions within Salesforce * Clear visibility into data flows and workflows * Confidence that access controls were aligned with enterprise security and compliance policies Without a centralized view, answering these questions required manual analysis and spreadsheet-driven reviews that were difficult to operationalize. Get started with its Salesforce Data Risk Assessment. Get your assessment Applying identity security to Salesforce With Varonis, Enverus began applying identity threat detection and response (ITDR) principles directly to Salesforce and other SaaS platforms. What had once been complex, static spreadsheet reviews became: * Clear prioritization of high-risk access * Actionable insights into who and what needed remediation * Simple, repeatable reporting aligned to enterprise policy This transformation empowered both the security team and Salesforce operators to focus on what mattered most. "We now have a far more complete picture of Salesforce than we ever had before." Alex Acosta, Vice President of Security, Enverus Improved Salesforce threat detection In 2025, Enverus' security operations team processed hundreds of alerts per day across its environment. Salesforce emerged as a particularly important attack surface due to its scale, connectivity, and data sensitivity. While most observed activity aligned with legitimate business workflows, a small subset required deeper investigation. Varonis helped to improve threat detection and reduce the deluge of alerts: * Salesforce-specific detections and monitoring * Guidance from a dedicated threat research team * New detection strategies that had not previously been on Enverus' radar This partnership enabled Enverus to investigate novel activity more effectively, validate behavior, and proactively design new detections to reduce future risk. "It felt like Salesforce-specific MDR. We gained a trusted partner with deep Salesforce security expertise that we could lean on as an advisor." - Alex Acosta, Vice President of Security, Enverus Spotlight: Protecting against a large-scale SaaS supply chain attacks In early 2025, by compromising Salesloft's GitHub repos, a threat actor known UNC6395 stole the OAuth tokens that allowed Drift, a widely used chatbot owned by Salesloft, to connect to customers' Azure, Salesforce, Google Workspace, and other integrated platforms. Between August 8 and 18, UNC6395 used those tokens to impersonate the trusted Drift application, bypass MFA, and systematically exfiltrate data from more than 700 organizations including Cloudflare, Zscaler, Palo Alto Networks, and Proofpoint. For most victims, the attack went unnoticed because OAuth abuse appears as normal API traffic, and attackers deleted query jobs to cover their tracks. The majority of affected organizations only learned of the breach when Salesforce and Salesloft notified them more than two weeks after the attack. Enverus was the exception. With Varonis deployed across the environment, Enverus detected, contained, and neutralized the attack before it fully materialized: Step 1: Cross-platform detection. Varonis initially flagged Drift activity in Azure as abnormal since its OAuth token refreshes originated from unusual IP addresses and its API call volumes exceeded Drift's baseline for Enverus. As a result, Varonis issued an alert and started checking Drift activity in other systems. Step 2: Salesforce telemetry confirms the threat. Salesforce Shield Event Monitoring provided detailed logs that allowed Varonis to identify abnormal activity in Salesforce by the Drift connected app, like logins from suspicious IPs and unusual API queries. Step 3: Varonis MDDR responds. Varonis correlated the Azure and Salesforce signals, and its Managed Data Detection and Response (MDDR) team engaged alongside Enverus' security operations to immediately take a series of actions to prevent a breach: * Suspended the compromised identity and revoked OAuth tokens * Classified sensitive fields and attachments to assess potential exposure * Removed excess high-risk permissions, including Export Reports and Create Public Links * Remediated overly permissive sharing rules and misconfigured Salesforce Sites Within two hours, Enverus had full containment and forensic proof that no sensitive data had been exfiltrated. Looking ahead Following the success across Enverus' environment, the team continues to expand its partnership with Varonis. They plan to further build on Salesforce-specific detections, monitoring, and threat prevention strategies while extending visibility and governance across additional platforms. "Varonis has been highly impactful for us, and it's something we're continuing to build on moving forward," Alex shared. What should I do now? Below are three ways you can continue your journey to reduce data risk at your company: Schedule a demo with Varonis Systems, Inc. to see Varonis in action. Varonis Systems, Inc.'ll personalize the session to your org's data security needs and answer any questions. See a sample of its Data Risk Assessment and learn the risks that could be lingering in your environment. Varonis' DRA is completely free and offers a clear path to automated remediation. Follow Varonis Systems, Inc. on LinkedIn, YouTube, and X (Twitter) for bite-sized insights on all things data security, including DSPM, threat detection, AI security, and more. Nolan Necoechea Nolan Necoechea is a product marketing strategist at Varonis. He has spent more than a decade working with data and AI innovators.

Varonis Systems
May 20th, 2026
Varonis: the platform advantage for security.

Varonis: the platform advantage for security. Explore how Varonis' unified approach enhances data, AI, and email security, reduces costs, and prevents breaches through automated solutions and comprehensive visibility. Last updated May 20, 2026 What should I do now? Below are three ways you can continue your journey to reduce data risk at your company: Schedule a demo with Varonis Systems, Inc. to see Varonis in action. Varonis Systems, Inc.'ll personalize the session to your org's data security needs and answer any questions. See a sample of its Data Risk Assessment and learn the risks that could be lingering in your environment. Varonis' DRA is completely free and offers a clear path to automated remediation. Follow Varonis Systems, Inc. on LinkedIn, YouTube, and X (Twitter) for bite-sized insights on all things data security, including DSPM, threat detection, AI security, and more. Eugene Feldman Eugene Feldman is a Product Marketer at Varonis, specializing in helping customers secure their data in SaaS applications such as Salesforce, Snowflake, and other enterprise platforms. Before joining Varonis, Eugene worked as a product marketer at Salesforce and several smaller enterprise software and security companies.

Yahoo Finance
Mar 30th, 2026
William Blair downgrades Varonis Systems as AI disruption threatens infrastructure software sector

William Blair downgraded Varonis Systems from Outperform to Market Perform on 23rd March, citing concerns about AI-driven disruption in the infrastructure software sector. The firm noted that infrastructure software companies face significant shifts requiring reassessment of offerings, pricing structures and marketing tactics, with AI's disruptive effects expected to persist. Despite the downgrade, Varonis launched Varonis Atlas on 17th March, an AI security platform providing visibility and control over AI operations. The platform covers the complete AI security lifecycle, from discovery and risk assessment to runtime protection and compliance, integrating with hosted platforms, custom models and agentic frameworks. Varonis provides AI-powered data security and analytics solutions to discover, classify and protect sensitive enterprise data across cloud and on-premises environments.

Noqta
Mar 25th, 2026
RSAC 2026: agentic AI dominates the world's largest cybersecurity conference.

RSAC 2026: agentic AI dominates the world's largest cybersecurity conference. By AI Bot · March 25, 2026 The RSA Conference 2026, the world's largest cybersecurity event, is underway in San Francisco from March 23 to 26, bringing together over 700 speakers, more than 570 sessions, and upwards of 600 exhibitors. This year, one theme towers above all others: agentic AI and its profound impact on both cyber defense and cyber offense. The rise of agentic AI in security. The conference has made it clear that AI agents are no longer a future concept but a present reality reshaping enterprise security. From autonomous SOC analysts to self-healing infrastructure, vendors across the industry are racing to embed AI agents into every layer of the security stack. Varonis CEO Yaki Faitelson delivered a keynote titled "Robots vs. Robots: Stories from the Frontlines of the Agentic Revolution," sharing real-world examples of how AI is reshaping enterprise security across three critical dimensions: defense automation, threat detection, and data governance. As one industry expert put it at the conference: enterprises now need "agents for every part of your security program, from GRC to IAM to SOC, everywhere." Key announcements. AI-Native security platforms. * Booz Allen Hamilton launched Vellox, a suite of five AI-native cybersecurity tools covering malware analysis, detection engineering, adversary emulation, compliance monitoring, and autonomous remediation * Arctic Wolf announced the Aurora Agentic SOC, combining its Concierge Experience with turnkey agentic AI for automated threat response * Panther announced general availability of its AI SOC Platform, where AI agents have native access to the data lake, detection engine, and organizational knowledge * Splunk showcased its unified Agentic SOC approach, combining detection, investigation, and response into a cohesive workflow powered by natural language interaction Securing AI agents themselves. * 1Password announced Unified Access, a new agent security platform enabling organizations to securely deploy AI agents and automated workflows * Geordie AI was named Most Innovative Startup 2026 in the prestigious Innovation Sandbox contest for its security and governance platform purpose-built for AI agents Autonomous offensive security. * Assail launched Ares, an autonomous red-teaming platform designed to discover, chain, and exploit vulnerabilities across APIs, mobile applications, and web applications Geordie AI wins Innovation Sandbox. The Innovation Sandbox contest, one of the most watched events at RSAC, crowned Geordie AI as its 2026 winner. Founded by CEO Henry Comfort, the company offers a platform that gives enterprises real-time visibility into their "agentic footprint" and helps them monitor agent behavior and mitigate risks at scale. The contest has an impressive track record: over 20 years, its Top 10 finalists have collectively achieved more than 100 acquisitions and received over $50 billion in venture funding. Each 2026 finalist received $5 million in investment support. Beyond AI: other critical themes. Post-Quantum cryptography. With quantum computing timelines accelerating, discussions have shifted from theoretical to practical. Organizations are urged to inventory their cryptographic assets and develop migration strategies to quantum-resistant encryption now rather than wait. Continuous threat exposure management. Security teams are moving away from periodic vulnerability assessments toward continuous visibility into attack paths and exposures, with vendors racing to build unified CTEM platforms. North Korean ai-powered threats. Microsoft revealed at the conference that North Korean state actors are now using AI for identity fabrication and long-term persistence at scale, forging agent identities to infiltrate organizations. What this means. RSAC 2026 marks a turning point: the cybersecurity industry has fully embraced AI agents as both its greatest tool and its greatest challenge. Organizations that fail to secure their agentic operations risk creating new attack surfaces even as they automate their defenses. The race is no longer just about detecting threats but about governing an entirely new class of autonomous digital workers. Discuss your project with NOQTA. NOQTA is here to help with your web development needs. Schedule a call to discuss your project and how NOQTA can assist you. Let's find the best solutions for your needs.

Yahoo Finance
Mar 24th, 2026
SentinelOne and Varonis fall 8.8% and 6.9% as Anthropic's Claude AI computer control disrupts endpoint security model

SentinelOne and Varonis Systems shares fell 8.8% and 6.9% respectively following Anthropic's announcement that its Claude AI assistant can now control computers by imitating human keystrokes and mouse movements. This "Computer Use" capability challenges traditional endpoint security models, which historically focused on protecting human-driven activity. Investor concerns were amplified by Databricks' entry into the space with LakeWatch, which consolidates device telemetry into an AI-powered Security Lakehouse. The industry's shift toward "agentic security" frameworks has raised questions about future demand for per-seat licensing revenue in endpoint security. The market reaction reflects uncertainty about how AI agents functioning as primary workstation users, rather than humans, will impact the traditional endpoint protection platform business model and its associated threat surface.

INACTIVE