Full-Time

Senior Product Manager

AI Platform & Triage

Corelight

Corelight

201-500 employees

Network detection and response technology provider

Compensation Overview

$173k - $222k/yr

+ Commission + Bonus + Equity

United States

Remote

Bachelor's

Category
Product (1)
Required Skills
LLM
Agile
Product Management
RAG
Cybersecurity
REST APIs

Get referred to Corelight

See people who can refer or advise you

Requirements
  • At least 3 years of experience as a Product Manager or Product Owner owning product strategy, roadmap execution, and customer discovery for enterprise software as a service products.
  • At least 5 years of experience in cybersecurity, with exposure to Security Operations Centers, network security, asset intelligence, data enrichment, or related technologies.
  • Experience building or managing complex, technical products in artificial intelligence, cybersecurity, data platforms, or another enterprise software domain.
  • Strong understanding of AI assistants, large language model-powered workflows, retrieval-augmented generation, and contextual data for AI experiences.
  • Experience partnering with Engineering to define technical requirements, evaluate tradeoffs, and deliver products through Agile development processes.
  • Familiarity with application programming interfaces, integrations, and enterprise security ecosystems, including endpoint detection and response, identity and access management, and configuration management database platforms.
  • Ability to balance customer needs, technical complexity, and business priorities when making product decisions.
  • Ability to influence engineers, executives, customers, and cross-functional stakeholders.
Responsibilities
  • Own the strategy and roadmap for Corelight’s Knowledge Layer so contextual intelligence supports human analysts and AI-powered security workflows.
  • Define how AI-powered investigations leverage contextual data by driving the evolution of data enrichment and knowledge capabilities.
  • Lead the strategy for alert prioritization and data correlation while giving enterprise customers meaningful control and maintaining strong out-of-the-box experiences.
  • Partner with Engineering and Architecture to evaluate technical tradeoffs and deliver scalable, enterprise-grade product capabilities.
  • Define and prioritize integrations across the security ecosystem, including endpoint detection and response, configuration management database, identity and access management, and other enterprise platforms.
  • Conduct continuous customer discovery with Security Operations Center analysts, Security Operations Center managers, chief information security officers, and security teams.
  • Translate customer and market insights into product requirements, user stories, and prioritized roadmaps for Engineering.
  • Define success metrics and reporting frameworks to help customers evaluate detection quality, operational efficiency, and security outcomes.
  • Partner with user experience, Marketing, Sales, Customer Success, and other cross-functional teams to launch, position, and drive adoption of new capabilities.
  • Evaluate emerging AI technologies, evolving security workflows, and market trends to shape the direction of Corelight’s AI platform and Knowledge Layer.
Desired Qualifications
  • Experience building products for enterprise security teams or other highly technical users.
  • Familiarity with data analytics infrastructure, knowledge management, or knowledge graph concepts.
  • A bachelor's degree in Computer Science, Engineering, Cybersecurity, or a related technical field, or equivalent practical experience.

Corelight provides network detection and response (NDR) technology to improve cybersecurity. It collects and analyzes network data through the Open NDR Platform and the Cloud Sensor for AWS, giving customers visibility, aiding threat hunting, and speeding up incident response across on-premise and cloud environments. What sets Corelight apart is its open, partner-friendly approach that lets other security vendors build analytics on top of its technology, with interoperability across major vendors and a cloud-native option for AWS. The goal is to strengthen cyber defense by delivering scalable network visibility and fast detection, growing adoption through direct sales and partnerships that integrate Corelight’s Open NDR technology into other offerings.

Company Size

201-500

Company Stage

Series E

Total Funding

$309.2M

Headquarters

San Francisco, California

Founded

2013

Get referred to Corelight

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • March 2026 Agentic Triage claims 10x faster triage and 60-70% auto-triage.
  • May 6, 2026 Hatem Naguib and Jack Huffard appointments strengthen enterprise go-to-market credibility.
  • July 2026 Softprom distribution across 15 countries expands Corelight's international reach materially.

What critics are saying

  • Crowded NDR rivals like Darktrace, Vectra, and CrowdStrike compress pricing and differentiation.
  • Agentic Triage depends on analyst trust; one bad verdict damages renewals quickly.
  • No 2025-2026 funding or exit event suggests Corelight remains capital-sensitive before cash-flow positive.

What makes Corelight unique

  • Corelight's Zeek-based Open NDR turns raw traffic into defensible evidence.
  • Corelight Agentic Triage, launched March 18, 2026, exposes every query and playbook step.
  • CrowdStrike partnership and Charlotte AI integration give Corelight distribution inside major SOC workflows.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

2%
PR Newswire
Jul 27th, 2026
Corelight appoints Amanda Berger as chief customer officer

Corelight, a cybersecurity firm specialising in network evidence platforms, has appointed Amanda Berger as chief customer officer. Berger brings over 25 years of experience in customer leadership across cybersecurity and SaaS companies. In her new role, Berger will oversee Corelight's customer success organisation, managing the complete customer journey from implementation through expansion. She previously served as chief customer officer at Employ, HackerOne, Lucidworks and RichRelevance, where she developed customer retention and expansion strategies. The appointment follows recent additions to Corelight's leadership team, including cybersecurity veteran Hatem Naguib joining the board and Tenable co-founder Jack Huffard as adviser. The company recently expanded its Open NDR platform to include passive asset classification and network performance monitoring.

Renascence
Jul 27th, 2026
Corelight names Amanda Berger Chief Customer Officer.

Corelight names Amanda Berger Chief Customer Officer. Corelight has appointed Amanda Berger as CCO, elevating post-sale customer experience to board level in a signal that retention is now a revenue priority in enterprise cybersecurity. Renascence Newsdesk What happened. Corelight, a network-detection and response security firm, has appointed Amanda Berger as its new Chief Customer Officer. The announcement marks a deliberate move by the company to elevate post-sale customer experience to the executive level, signalling that customer retention and success are now board-level priorities rather than operational afterthoughts. Berger steps into the role with a remit to oversee the full customer lifecycle - from onboarding and adoption through to long-term retention and advocacy - as Corelight competes in an increasingly crowded cybersecurity market where product differentiation alone is no longer sufficient. Why it matters. The creation or elevation of a Chief Customer Officer role is one of the clearest structural signals a company can send about where it believes competitive advantage now lives. In high-complexity B2B categories such as enterprise security, the buying decision is only the beginning of the relationship; the real value - and the real risk of churn - sits in what happens after contract signature. By installing a CCO at the executive table, Corelight is acknowledging that customer experience is a revenue function, not a support function. From a behavioural economics perspective, this matters because enterprise customers are not purely rational actors. Trust, perceived effort, and the consistency of human touchpoints all shape renewal decisions as powerfully as product performance metrics. A dedicated CCO can design the rituals, cadences and recovery moments that keep customers psychologically anchored to a vendor - reducing the cognitive ease with which a competitor can displace them. The Renascence take. Most commentary on CCO appointments focuses on the individual's credentials. The more important question is whether the organisation has genuinely restructured decision-making authority around the customer, or simply added a title to the org chart without changing how trade-offs get made. The appointment of a CCO is a hypothesis, not an outcome. The real test is whether Berger has budget authority, a seat in product roadmap discussions, and the power to override revenue-quarter thinking when it conflicts with long-term customer health. In its experience, CCOs who report to the CEO and control the full post-sale motion drive measurable NPS and net revenue retention improvements; those who sit beneath a CRO frequently become sophisticated complaint handlers. Corelight's leadership should be asked, publicly, which model they have chosen - because the answer determines whether this hire changes anything at all for their customers. This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage. More in Customer Experience Stay ahead of CX Get the signal, not the noise. The stories shaping customer experience - plus the Journal and Experience Loom - in your inbox.

WeirdWare
Jul 24th, 2026
Reconsider legacy tech and remote-access security in the AI age.

Reconsider legacy tech and remote-access security in the AI age. Corelight, Dropzone AI, Scythe, SimSpace, and Sondera launch AI proving ground. 24th July 2026 Five AI companies are teaming up to boost enterprise trust in AI agents via a new consortium. Secops-focused Dropzone AI said the new AI Proving Ground Consortium (AIPGC) will rigorously train, test, and prove agentic AI defences in production-like environments. Edward Wu, founder and CEO of Dropzone AI, said enterprises need to know they can trust agentic AI. As AI takes on a bigger role, organisations need confidence on how these systems perform in real environments. "The future of the SOC is multiple AI agents working together, alongside human analysts, across investigations, threat hunting, intelligence and response," Wu said. "This consortium can help establish the benchmarks and standards organisations need to confidently adopt AI and accelerate its full operational impact on security." As a result, the first virtual event from the venture between founders Dropzone AI, Corelight, Scythe, SimSpace and Sondera was held mid-June. Peter Lee, CEO of testing platform SimSpace, the lead organiser, said AI weaponisation is a bigger problem than any organisation can handle alone. "That's why we're forming the AIPGC to pool our collective ideas and cyber expertise," Lee confirmed. "AI is transforming cybersecurity. Organisations need a way to rigorously train, test, and validate AI agents together with human cyber operators." AI agents in secops and services. Dropzone AI's agentic secops offering targets managed security services providers (MSSPs). As a result, it has rolled out AI SOC Analyst, enabling autonomous investigation of more alerts and AI Threat Hunter, which runs prebuilt or custom 'hunt' packs for SIEM, EDR, and cloud. In addition, it offers AI Threat Intel Analyst, which analyses and designs responses for the AI Threat Hunter agent. "SimSpace research found that nearly 80% of security leaders report high confidence in their AI defences," the announcement said. "Measured readiness scores can be as low as 30% before repeated simulation exercises." Additionally, many organisations rely on legacy preparation strategies, like tabletop exercises and certification courses, it said.

HiTech.Expert
Jul 13th, 2026
Softprom deploys Corelight Open NDR platform in 15 countries.

Softprom deploys Corelight Open NDR platform in 15 countries. 13.07.2026 Softprom, a leading international Value Added IT distributor, has officially announced the signing of an exclusive partnership agreement with Corelight, a recognized technology leader in the field of enabling modern artificial intelligence-based cybersecurity control centers (AI SOC). Obtaining the status of an official distributor will allow Softprom to deliver advanced network threat detection and response (NDR) solutions to the markets of Central and Eastern Europe, the Caucasus and Central Asia. The geographical scope of the agreement covers 15 countries, including: Ukraine, Poland, Romania, Hungary, Bulgaria, Greece, Cyprus, Moldova, Georgia, Azerbaijan, Armenia, Kazakhstan, Uzbekistan, Kyrgyzstan and Mongolia. Corelight technology stack. Eliminating blind spots: how Corelight Open NDR works. Today's enterprise security teams are constantly faced with a lack of clear, structured, and actionable data, leading to dangerous blind spots in enterprise networks. The Corelight Open NDR platform addresses this critical issue by transforming raw network traffic into comprehensive, real-time evidence. This enables security operations centers (SOCs) to proactively hunt for threats and eliminate sophisticated attacks before they disrupt business processes. AI functionality platforms. Protection against AI threats: features of the Agentic Triage model. In 2026, the cyber threat landscape has radically changed due to the emergence of malicious autonomous Mythos-class AI models that can automatically detect vulnerabilities and weaponize them faster than engineers can deploy security patches. In such conditions, classic Endpoint Protection becomes insufficient. The Corelight platform offers the ultimate automation tools: Comparative analysis: Corelight Open NDR platforms vs. classic EDR/XDR systems. To build comprehensive protection for a modern enterprise, it is important to clearly delineate the areas of responsibility of different classes of IS solutions. Below are the architectural differences between network threat detection (NDR) platforms and traditional endpoint protection systems (EDR/XDR): | Architectural criterion | Platforms Open NDR (Corelight) | Classic EDR/XDR systems | | Primary data source | Raw network traffic, protocol metadata (Zeek/Suricata), cloud traffic. Operating system logs, host file activity, endpoint processes. | | Deployment method | Passive network sensors, SPAN ports, network TAPs. Agentless. It is mandatory to install a local software agent on each device (host). | | Infrastructure coverage | 100% of devices on the network (including IoT, ACS hardware, MFPs, routers, and unknown AI assets). Only devices with supported OS (Windows/Linux/macOS) where the agent is physically installed. | | Resistance to hackers | Absolute. An attacker cannot disable or remove a passive network sensor. Vulnerable: Advanced attacks often start by forcibly disabling the EDR agent on the system. | | AI communications analysis | Continuous passive classification of GenAI services and autonomous AI model traffic. Monitoring local AI software launch processes, without deep analysis of the network context. | | Vendor Lock-in Effect | None (open source, native integration with any SIEM/SOAR platforms). High (tied to the ecosystem of a specific host protection software developer). | [Сирий трафік підприємства] | | [Пасивний TAP / SPAN] | [Corelight Open NDR] | 100% Видимість (IoT, ШІ, Хости) | | [Захищений Хост з ОС] | [Локальний Агент EDR] | Глибокий моніторинг процесів ОС Modern AI SOC architectures of 2026 are built on synergy, not exclusion. Corelight Open NDR provides the ultimate alert and context of what is happening "between devices," while EDR/XDR provides a detailed picture of the destruction directly inside the compromised host. HiTech Expert take. For HiTech Expert, Expert formulate an important infrastructure conclusion: the deal between Softprom and Corelight reflects the global shift of the cybersecurity market to autonomous AI investigation tools. In an era where vulnerability assessments become outdated faster than updates are released, passive real-time network signal analysis is the only way to protect critical perimeters. This step is of enormous importance for Ukraine. Against the background of the Ministry of Digital Transformation deploys 60 national registries based on the Diya.Engine constructor and prepares a full AI transition to the Agentic State model, protecting government data centers from AI attacks comes to the fore. Corelight Open NDR-class platforms will become a reliable umbrella for large national systems, including state AI employment platform "Obriy".

PR Newswire
Jun 17th, 2026
Corelight adds passive asset classification to detect AI-powered threats from Mythos-class models

Corelight, a network detection and response platform provider, has expanded its Open NDR platform to include native network performance monitoring and passive asset classification capabilities. The update enables security teams to defend against AI-powered threats from Mythos-class models that can discover and weaponise vulnerabilities faster than traditional patching programmes. The platform's Zeek-based analysis engine now continuously classifies every communicating asset and AI service from existing traffic, without requiring active polling agents or dedicated infrastructure. It automatically identifies devices including workstations, servers, IoT devices and over 180 AI services by analysing protocol fingerprints. The San Francisco-based company, founded by the creators of Zeek open-source network security technology, serves Global 2000 companies, government agencies and research universities. The platform aims to close visibility gaps in unmanaged devices, shadow IT endpoints and operational technology assets.