Full-Time

Associate Customer Success Manager

Customer Success Team

Filigran

Filigran

201-500 employees

Open-source cybersecurity platform for threat management

No salary listed

Remote in USA + 1 more

More locations: Remote in Canada

Remote

Applicants must be based in the United States or Canada.

Category
Customer Experience & Support (1)
Required Skills
Cybersecurity
Data Analysis

Get referred to Filigran

See people who can refer or advise you

Requirements
  • At least 1 year of experience in Customer Success, Account Management, or a similar client-facing role in SaaS or technology, or experience in cyber threat intelligence or all-source intelligence with cyber experience.
  • Based in the United States or Canada with experience supporting national and regional customers.
  • Strong technical aptitude and the ability to work with tools such as OpenCTI or OpenBAS.
  • Experience with customer relationship management or customer success management tools, customer journey tracking, and success metrics, or willingness to learn them.
  • Familiarity with the cybersecurity sector, including threat intelligence and each step of the intelligence cycle.
  • Fluency in French and English.
  • Ability to work in a remote, asynchronous-first culture.
Responsibilities
  • Continuously expand knowledge of the Customer Success Manager role, including each step of the customer lifecycle.
  • Become proficient in OpenCTI and OpenAEV under the guidance of a senior Customer Success Manager.
  • Own and manage the full customer lifecycle, including onboarding, adoption, training, and renewal.
  • Build strong, proactive relationships with customers in the Americas.
  • Identify and support upsell and cross-sell opportunities in partnership with Sales.
  • Coordinate with internal teams to resolve customer issues quickly and effectively.
  • Collaborate with Customer Support Engineers to ensure seamless communication and delivery in response to support tickets.
  • Collect and share customer feedback to improve product and service quality.
  • Track success metrics and use data to inform customer strategy and engagement.
  • Collaborate cross-functionally with Customer Support Engineering, Sales, Product, Engineering, and regional teams to support customer satisfaction and retention.

Filigran builds an extended threat management (XTM) cybersecurity platform based on open-source principles, combining threat intelligence, breach-and-attack simulation, and risk management. Its core products include OpenCTI for consolidating and visualizing threat knowledge, OpenAEV for testing security controls against real-world attack scenarios, and OpenGRC for threat-informed risk management. The company operates a dual model with free open-source community editions and enterprise editions that add advanced features, managed hosting, and professional services such as support and training. Its goal is to help organizations anticipate and reduce cyber risk with a scalable, proactive security platform and agentic AI to automate threat analysis.

Company Size

201-500

Company Stage

Series C

Total Funding

$115.8M

Headquarters

Asnières-sur-Seine, France

Founded

2022

Get referred to Filigran

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • June 2026 surveys show 41% of security teams fear AI attacks most.
  • April 2026 Japan launch targets government, infrastructure, and finance buyers.
  • North American ARR grew nearly 4x in 2026, with 119% net revenue retention.

What critics are saying

  • Open-source rivals can copy features quickly, compressing Filigran margins by 2027.
  • XTM One’s AI automation raises false-output risk, especially for regulated buyers.
  • If OpenCTI communities stagnate, Filigran loses its top-of-funnel and becomes a services vendor.

What makes Filigran unique

  • OpenCTI and OpenAEV share one open-source workflow, cutting tool switching.
  • Filigran combines threat intelligence, adversarial validation, and OpenGRC into XTM.
  • Samuel Hassine and Julien Richard give credible ANSSI-era and data-engineering leadership.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Remote Work Options

Flexible Work Hours

401(k) Retirement Plan

401(k) Company Match

Stock Options

Equity

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

1%

2 year growth

3%
Associated Press
Sep 1st, 2026
Filigran launches Attack Chaining in OpenAEV v3 for autonomous penetration testing

Filigran has launched Attack Chaining, a capability that automates penetration testing and red teaming through its OpenAEV product. The feature, part of OpenAEV v3, validates attack paths by chaining techniques based on real-time discoveries rather than running isolated tests. The Paris-based company's research found 97% of organisations struggle to determine if exposures are exploitable, whilst 88% rely on manual processes for attack simulation. Attack Chaining addresses this by discovering findings like credentials or open ports and feeding them as inputs to subsequent actions, adapting as controls block progress. The system offers configurable logic, real-time attack path graphs, and both operator-led and AI agent-driven orchestration modes. OpenAEV v3 also includes an Adversarial Exposure Command Centre dashboard, AI red-teaming injectors for testing LLM-powered systems, and automated PDF reporting. Attack Chaining is available in OpenAEV Enterprise Edition.

SiliconANGLE Media
Sep 1st, 2026
Filigran adds attack chaining to OpenAEV for automated penetration testing.

Filigran adds attack chaining to OpenAEV for automated penetration testing. French cybersecurity company Filigran SAS today launched Attack Chaining, a capability in its OpenAEV exposure validation product that links individual attack simulations into a single running path. It ships with OpenAEV v3, out today. Real intrusions rarely stop at one technique. Reconnaissance finds a target, a credential dump hands over a password and that password opens the next machine, with every step depending on whatever the last one turned up. Single-technique tests and prewritten scenarios catch specific weaknesses well enough. Neither adjusts to what an attacker finds partway through. Each action feeds the next one. OpenAEV logs what an action turns up as a structured record, whether that is a password, an open port or a set of permissions, and the engine reads it at runtime to work out the next move. A working credential pushes the run deeper into the network. The runs branch where more than one route forward exists, and any control that blocks a step ends the chain there. Teams can assemble that logic themselves out of techniques, payloads or custom actions, then set conditions on each hop. The run appears on an interactive graph while it happens, tracking pivots and branches from the first action through to the objective. Drilling into a finding shows why an action fired. Filigran said the graph is meant to expose chokepoints, the single step whose removal collapses an entire path, so a team can fix one control instead of triaging the whole chain. Two modes sit on the same engine. An operator can build the logic and step through execution manually. In agent-led mode the objective and scope are set in plain language, and an artificial intelligence agent builds and adapts the chain itself, generating phishing emails and landing pages for social engineering steps. "Security validation has to evolve with the way attackers operate," said co-founder Julien Richard. "The goal is no longer just to prove that we can block individual techniques; it is to understand whether those techniques can be combined into a path that leads to a real compromise." Jean-Philippe Salles, vice president of product management at the company, said a validation outcome is "only actionable when security teams can trace the logic that generated it." Filigran's "State of Threat Management" survey of 550 security decision-makers and practitioners found 88% relying on manual processes for offensive attack simulation. The company said 97% also have difficulty working out whether their exposures can be exploited at all. Four other additions come with v3. A redesigned home dashboard called the Adversarial Exposure Command Center pulls posture, simulation results and detection coverage into a single view. An Adversarial Exposure Score aggregates validation results across exposure sources. New red-teaming injectors run adversary simulations against chatbots and agents built on large language models, using the same engine that validates endpoint and email defenses. Reporting is now one click to a PDF. OpenAEV v3 is available to all users today. Attack Chaining is limited to the Enterprise Edition. Founded in 2022, Filigran has raised more than $100 million in funding, including rounds of $35 million in October 2024 and $58 million in October 2025. Investors in the company include Eurazeo SE, Insight Partners LP, Accel Partners LP and Deutsche Telekom AG. Image: Filigran. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from its Marketplace portal page and links: https://siliconangle.com/aws-marketplace/. About SiliconANGLE Media. SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Tech Ascension Awards
Aug 17th, 2026
Filigran CTO on building an award-winning, ai-native Threat Management platform.

Filigran CTO on building an award-winning, ai-native Threat Management platform. Filigran was recently recognized with the Most Innovative Security Solution award for its eXtended Threat Management (XTM) Platform, an open, AI-native ecosystem that unifies threat intelligence, adversarial exposure validation, and risk governance. Tech Ascension Awards sat down with Julien Richard, CTO and Co-Founder of Filigran, to talk about the company's mission and how the XTM Platform is helping security teams move from reactive alert-chasing to continuous, threat-informed defense. For readers who may not be familiar with Filigran, can you introduce the company and what it does? A: Filigran is a European company, founded in 2022 by its CEO, Samuel Hassine, and me. Tech Ascension Awards started the company because Tech Ascension Awards saw the same gap everywhere: security teams had more tools and more data than ever, but no real way to turn that into fast, confident action. Its mission is to empower defense teams to be proactive through open-source solutions that uncover threats and drive action. Tech Ascension Awards began with OpenCTI, a platform to centralize and structure threat intelligence, and have since expanded into OpenAEV for continuous exposure validation, with OpenGRC (risk governance and quantification) coming next. Together, these form its XTM Platform. At its center is XTM One, an agentic AI layer that connects intelligence, validation, and response into one workflow. Everything Tech Ascension Awards build starts as open source. Tech Ascension Awards is backed by a global community of more than 6,500 practitioners who build alongside Tech Ascension Awards. What's the biggest challenge you see security teams facing today? A: It isn't a lack of data. Organizations have more visibility into their environments than ever. The real challenge is separating signal from noise. A large security team can receive thousands of alerts a day, but only a small fraction of them represent a genuine, exploitable threat. Its State of Threat Management report found that security teams spend an average of 42% of their time investigating risks that later prove low priority or non-exploitable. In a 40-hour week, that's about 17 hours per analyst. That's not just an efficiency problem. It's a retention problem, and it hits some of the most skilled people in the industry. How does the XTM Platform help organizations address that problem? A: Tech Ascension Awards help organizations move from reactive to proactive security, following what the industry calls CTEM: Continuous Threat Exposure Management. Instead of a point-in-time assessment, it's a continuous cycle: understand the threat landscape, prioritize the exposures that actually matter to you, validate whether your defenses hold up against realistic attacks, and act on what you find. Then repeat. That's exactly what its platform is built to deliver. Being secure today doesn't mean you're secure tomorrow. Threats evolve, and systems change, so defenses need to be tested continuously, not once a year during an audit. What role does AI play in Filigran's approach? A: AI helps teams keep pace with the volume and speed of modern threats, but the goal isn't to replace the analyst. It's to remove the low-value work that keeps analysts from focusing on what matters. Through XTM One, teams can ask direct questions of their own data, automate repetitive investigation steps, and get straight to the context they need, while humans stay in control of the decisions that count. The point of AI here isn't automation for its own sake. It's giving skilled people back the time to do the work only they can do. Why is open source such a core part of Filigran's model? A: Cybersecurity is built on trust, and trust requires transparency. When your security stack is open source, you can see exactly how it works, adapt it to your environment, and keep control of your own data. That matters enormously for organizations handling sensitive information, and increasingly for anyone thinking about digital sovereignty and long-term control of their systems. It also means Tech Ascension Awards build alongside its community of practitioners and contributors instead of behind closed doors. That community is a big part of why its products keep improving as fast as the threat landscape does. What's next for Filigran, and what excites you most right now? A: Tech Ascension Awards is focused on closing the gap between knowing about a risk and acting on it in time. That means connecting threat intelligence, exposure validation, and, risk governance and quantification. The goal is for security and business leaders to finally work from the same picture instead of several disconnected ones. What excites me most is that this isn't just a technology shift. It's a mindset shift, from managing alerts to managing outcomes. The organizations that make that shift are the ones that will actually get ahead of attackers, instead of constantly chasing them.

Filigran
Jul 31st, 2026
Intelligence Approval Workflows: ensure data quality and streamline processes.

Intelligence Approval Workflows: ensure data quality and streamline processes. Organizations collect intelligence from many different sources, but not all data arrives in a consistent format or through automated feeds. Manual submissions, file imports, and form-based contributions often require review before becoming part of a trusted intelligence repository. Previously, draft content in OpenCTI could typically move between two simple states: Open or Validated. While effective for basic use cases, organizations often need greater visibility into the review status of a draft and who's responsible for the next action. This is precisely the gap that Filigran is addressing with its new draft intelligence workflows. Tl;dr. * Configurable multi-step approval workflows: OpenCTI now lets organizations build custom review chains for draft intelligence with fine-grained RBAC, keeping quality control and governance transparent and easy to set up. * Workflows can be applied to any draft intelligence: Unstructured, human-sourced intelligence (analyst notes, tips, customer reports) via manual creation, file import, form intake, or the browser extension. * Granular RBAC at status and transition level: Control who can view, edit, manage, or advance a draft, including dynamic roles and cross-organization sharing, for full accountability at every stage. * Built for scale and governance: ISACs, MSSPs, large enterprises, government bodies, and teams handling external intelligence all benefit from consistent, auditable review before data is published. Organizations can now configure multi-step approval workflows with fine grained role-based user access (RBAC) to ensure quality control and data governance, while keeping the process transparent and easy to implement. Whether it's an ISAC collecting member-submitted observations, an MSSP fielding incident reports from customers, or internal teams contributing their own intelligence, draft workflows ensure ingestion processes are consistent and scalable. Watch the video for an introduction to draft approval workflows in OpenCTI: Manual vs automated intelligence. Automated and manual threat intelligence serve very different purposes, and organizations need both. Whereas automated feeds are built for scale, continuously ingesting structured, pre-vetted data like indicators and reports from trusted sources, manual intelligence is built for context, capturing what only a person can observe. For instance an analyst's investigation notes, a partner's tip-off, or a customer's description of an incident, arriving unstructured and unvetted. That difference is exactly why manual submissions can't simply flow into the same pipeline as automated feeds: they require a review step that automated sources have often already earned. Submitting manual intelligence in OpenCTI. In OpenCTI manual submissions are saved in 'Draft' mode, so they can first be reviewed before entering the knowledge base. There are a few ways manual intelligence can be submitted in OpenCTI: * Manual draft creation: Analysts can create a draft directly in OpenCTI and populate it from scratch, building out entities and relationships within the isolated workspace before review. * File import: When importing a file, users can select draft validation mode so the system automatically generates a draft and routes the extracted results into it for review, instead of writing directly to the main knowledge base. * Form intake: Contributors can submit structured input via form toggles on entity list pages (Reports, Incidents, Threat Actors, Indicators, and more), the 'Import using a Form' option in the standard import dialog, or a shared form link distributed to external or non-expert contributors (e.g., ISAC members, MSSP customers) who need to submit incidents or observations without direct platform access. * XTM browser extension: With the Filigran browser plugin, analysts can capture intelligence while browsing, flagging web pages, articles, or indicators encountered in the field, and send them straight into a draft for review, streamlining collection at the source without leaving the browser. Flexible workflows to meet any organization's needs. Every organization has its own intelligence processes. Some may require only a few straightforward review steps, while others need detailed approval chains involving analysts, managers, and specialized teams. The new Draft Workflows can easily be adapted to your organization's needs. Administrators can create custom statuses, connect them through transitions, and define how drafts move from one stage to the next. Workflows can be kept simple, or expanded to support complex operational processes. With intelligence approval workflows, organizations can: * Define custom review and approval stages * Control which users or roles can move a draft forward * Restrict editing rights at specific stages * Maintain visibility into the status of intelligence submissions * Ensure only properly reviewed intelligence enters the platform Applying role-based access control to workflows. For organizations that require additional governance, workflows can incorporate role-based controls that determine who can perform specific actions or approvals. This provides a structured way to manage collaboration while preserving accountability throughout the review process. RBAC within a workflow can be controlled at two different levels: * 1/ Status: This setting controls who can view, edit or manage the draft content. Access control can be applied when the user enters or exits the draft. * 2/ Transition: This setting controls which user(s) can transition to the next step: * Who can trigger the transition (who can move the draft to the next status, regardless of editing rights on the draft). * Who can view, edit or manage the draft content. * Provide other organizations access to the draft content in the context of cross organization work. Built-in validation checks help ensure workflows remain coherent before publication, providing administrators with guidance during configuration. Playbooks can also be configured to run automatically when the new intelligence has completed the approval process. Key use cases. Organizations that manage high volumes of intelligence submissions or operate in highly regulated environments can particularly benefit from intelligence approval workflows, including: * Information Sharing and Analysis Centers (ISACs): Information-sharing communities that need controlled submission and approval processes. With members submitting intelligence from varied sources and skill levels, a formal review step ensures only vetted, actionable data reaches the wider community. * Managed security service providers (MSSPs): Coordinating intelligence between teams and customers. Approval workflows give MSSPs a consistent way to validate findings before they're passed to clients, protecting both accuracy and client trust. * Large enterprises: With multiple teams and review layers. Draft workflows let intelligence move through the right chain of stakeholders, from analysts to leadership, without bottlenecking day-to-day operations. * Government and public-sector organizations: These environments often require auditable, multi-stage sign-off before intelligence can inform decisions, especially when countering foreign information manipulation and interference (FIMI) campaigns. * Teams collecting intelligence from external sources: External submissions can vary widely in reliability, so a review layer helps confirm credibility and context before intelligence is acted upon or shared further. Community versus Enterprise Edition. Basic workflow management is included in the Community Edition, including the ability to define multiple steps in the approval workflow and perform the review process without having to leave the platform. The following advanced features are included in the Enterprise Edition: * Enforce RBAC at each step: Define who can view, edit, or manage a draft at every stage. Authorized members can be specific users, groups, or organizations, or dynamic roles like "the draft creator" or "the draft's author organization," ensuring only the right people can act on it at each point. * Control who can advance each step: Independent of edit rights, you can specify exactly which user, group, or organization can push a draft to its next step. For example, you can specify that only managers can move the draft forward. * Enable cross-organization collaboration: When platform segregation applies, drafts can be shared with other organizations before specific edit rights are assigned. You can pre-define which organizations automatically receive the draft at a given step, or leave it open so the user chooses who to share with when that step is reached. Conclusion. At its core, Draft Approval Workflows help organizations improve the quality of their intelligence. By introducing structured review gates before intelligence is published, teams can validate submissions, verify context, and ensure data meets internal standards before it enters the platform. The result: higher-quality intelligence, stronger governance, and a more consistent process for collecting, reviewing, and approving data before it enters your platform. Would you like to see Draft Approval Workflows in action? Book a demo with one of its threat intelligence experts, or start a free 30-day trial of OpenCTI Enterprise Edition.

Filigran
Jun 17th, 2026
AI-Powered attacks become top concern for security professionals, new Filigran survey reveals.

AI-Powered attacks become top concern for security professionals, new Filigran survey reveals. A survey of cybersecurity professionals at Infosecurity Europe finds organisations struggling to prioritise risks, validate threats and prepare for AI-driven attacks LONDON, UK - 17th June 2026 - AI-powered attacks have emerged as the biggest cybersecurity concern among security professionals, according to new research conducted by Filigran during Infosecurity Europe 2026. The survey of 168 cybersecurity professionals across various industry sectors found that 41% identified AI-powered attacks at scale as their biggest security concern, nearly double the number citing supply chain risk (21%) or unknown threats (21%). AI-driven threats and what security professionals are doing about them is also the top concern for nearly one in three boards (32%). The findings suggest that organisations are entering a new phase of threat-informed defence, where security teams are focused on being armed with the intelligence and context to figure out which threats pose genuine business risk in order to make informed and accurate decisions quickly... "Organisations have access to more security data than ever before, but turning that information into action remains difficult," said Julien Richard, CTO at Filigran. "The challenge is determining which exposures actually matter, which can be exploited in their environment, and whether their existing controls will stop them. That's where many organisations are still struggling." Security teams continue to lose time to operational inefficiencies. When asked what wastes the most time in their security team, the most common response was chasing false positives and low-priority alerts (26%). A further 25% cited validating whether risks are real, while 17% said manually stitching together data from multiple security tools and 13% pointed to delays waiting for other teams to act on findings. The results suggest that security teams are spending a significant proportion of their time validating findings, correlating information and coordinating remediation efforts. As organisations face growing volumes of threat intelligence, vulnerabilities and security alerts, the challenge lies not in collecting more data, but in reducing complexity and accelerating decision-making across the security workflow. Boardrooms increasingly focused on AI-driven risk. When questioned on what boards ask about most, respondents selected AI-driven threats and organisational preparedness as the top issue, cited by 32% of security professionals. This placed AI ahead of more established boardroom cyber priorities, including regulatory compliance such as NIS2 and DORA (19%), supply chain and third-party risk (16%), and cloud and infrastructure exposure (15%). The findings indicate that boards are increasingly looking for reassurance that their organisations understand how AI could change the threat landscape, whether existing controls are fit for purpose, and how prepared security teams are to respond. For security leaders, this creates a growing need to translate AI risk into clear business terms, moving beyond technical discussion to explain exposure, readiness and resilience. Organisations struggle to turn threat intelligence into action. The survey found that while threat intelligence plays an increasingly important role in security operations, many organisations still struggle to translate intelligence into clear actionable priorities. Only 19% of respondents said they completely trust threat intelligence to tell them what to fix first. More than half (52%) said it helps inform decisions but still requires significant human judgement, while 21% said the volume of information often creates more noise than clarity. This challenge is reflected in automation priorities. When asked what they would automate tomorrow, the most common response was turning threat intelligence into actionable priorities, selected by 27% of respondents. Security pros remain cautious about autonomous AI. While AI-powered attacks topped the list of concerns, respondents showed significant caution when it came to using AI for security decision-making. Only 8% said they would trust AI to make security decisions without human approval. By comparison: * 44% said a human should always remain in the loop * 38% would trust AI only for low-risk, routine decisions * 11% said they are still experimenting with AI-driven decision-making This suggests that, for now, the most credible role for AI in cybersecurity is as an analyst accelerator rather than an independent decision-maker: helping teams move faster while keeping accountability and final judgement with human experts. CTEM adoption remains in its early stages. The survey also examined adoption of Continuous Threat Exposure Management (CTEM), a growing framework for prioritising and validating cyber risk. Only 28% of respondents described their organisation as having a continuous, proactive exposure management programme in place. The remainder reported either operating reactive security programmes, running disconnected initiatives, or being unfamiliar with CTEM altogether. "The findings from this research tell a consistent story: security professionals know they need to be more proactive, but the tools and processes around them create constraints and siloes," said Neena Sharma, Head of Customer and Product Marketing at Filigran. "The volume of findings is high but with no clear way to determine what matters, what's exploitable, and whether their defenses are working as expected to do so. That's the promise of Continuous Threat Exposure Management. It's not a single product; it's a discipline that allows security teams to unify threat signals, take faster, better-informed remediation decisions and show that the actions they're taking are actually reducing risk." About the research. The research was conducted by Filigran at Infosecurity Europe 2026. A total of 168 cybersecurity professionals participated in the survey, representing organisations of varying sizes across technology, financial services, government, healthcare, energy, manufacturing, communications, legal and other sectors. About Filigran Filigran, a cybersecurity company, offers an open-source, AI-powered, threat-informed approach to Continuous Threat Exposure Management (CTEM). Its eXtended Threat Management (XTM) platform delivers threat intelligence, exposure validation, and cyber risk reduction. Learn more: Website - Blog - LinkedIn - X