R

Rapid7

Provides cloud-based security analytics and automation

Tax Manager

Full-TimeUpdated on 10/2/2026
$111.4k - $150.7k/yr+ Variable/incentive compensation + Equity
Senior
Bachelor's, Master's
Boston, MA, USA
In Person

About the job

Requirements
  • A minimum of 6 years of progressive corporate tax experience, preferably within a publicly traded company.
  • A Bachelor's degree in Accounting or Finance.
  • Advanced proficiency in OneSource Tax Provision software or similar corporate tax provisioning software.
  • Strong analytical and problem-solving skills to perform complex tax account reconciliations.
  • Clear communication skills to collaborate with internal cross-functional finance teams and external advisors.
  • Ability to work independently while adapting effectively to broader group dynamics.
Responsibilities
  • Collaborate with external tax advisors to assist in preparing and reviewing quarterly and annual ASC 740 provision calculations using OneSource Tax Provision.
  • Support the preparation of tax-related disclosures for SEC filings, including 10-Q and 10-K forms.
  • Perform detailed reconciliations of tax accounts to ensure compliance with ASC 740 and SEC reporting requirements.
  • Partner with FP&A to improve the accuracy and usability of PBT forecasting by legal entity.
  • Review international income tax returns and filings prepared by outside tax advisors while analyzing GAAP-to-statutory differences.
  • Perform cash tax reconciliations, including analysis of payments, refunds, and estimated tax payments.
  • Ensure accurate and timely recording of tax-related journal entries while maintaining documentation for tax provision processes and controls.
  • Assist with tax audits, inquiries from taxing authorities, and implementation of BEPS requirements, including CbCR, Pillar 2, and transfer pricing.
  • Drive tax controllership duties and international income tax return preparation and review.
  • Take full ownership of global tax compliance timelines and deliverables across domestic and international entities.
  • Establish decision-making processes when evaluating GAAP-to-statutory differences and return-to-provision adjustments.
  • Adapt to evolving global tax regulations, including BEPS requirements, CbCR, and Pillar 2 implementations.
  • Identify opportunities to optimize the global tax position and drive continuous process improvements.
Desired Qualifications
  • Experience within a publicly traded company.
  • CPA.
  • Master's in Taxation.

About the company

Rapid7 provides cloud-based tools for visibility, analytics, and automation to help security teams protect organizations. Its Insight Cloud collects telemetry from networks and systems to identify vulnerabilities, detect malicious activity, investigate incidents, and automate tasks. The company combines threat analytics, vulnerability management, and security automation in a single platform, sold via subscriptions to enterprises and government agencies worldwide. Unlike some competitors with separate tools, Rapid7 focuses on an integrated cloud-native platform that automates routine security work to improve efficiency and incident response.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Boston, Massachusetts

Founded

2000

Get referred to Rapid7

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 free cash flow hit $31.9 million despite 1.5% revenue decline.
  • Management targets $129 million to $133 million non-GAAP operating income in 2026.
  • Licencias OnLine expands Rapid7 distribution across Latin America starting August 2026.

What critics are saying

  • Rapid7 cut 314 jobs in August 2026, signaling demand weakness and execution strain.
  • ARR fell 2% to $824 million in Q2 2026, with Q3 guided to $812 million.
  • Microsoft, CrowdStrike, and Palo Alto bundle overlapping controls, pressuring Rapid7's standalone pricing by 2027.

What makes Rapid7 unique

  • Rapid7’s July 2026 Command Platform unifies exposure, detection, and response.
  • InsightGovCloud won GovRAMP authorization on June 23, 2026, targeting SLED buyers.
  • Rapid7 serves 11,500-plus customers with open integrations and threat-enriched risk scoring.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Unlimited Paid Time Off

Flexible Work Hours

Remote Work Options

Paid Vacation

Paid Holidays

Sabbatical Leave

Company Equity

Stock Options

401(k) Retirement Plan

401(k) Company Match

Wellness Program

Mental Health Support

Gym Membership

Professional Development Budget

Conference Attendance Budget

Training Programs

Tuition Reimbursement

Tuition Reimbursement

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 1%

2 year growth

↑ 0%
Rapid7
Sep 23rd, 2026
How dynamic application security testing validates risk at runtime.

How dynamic application security testing validates risk at runtime. Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader. Rapid7 believe the result reflects the strength of Rapid7's DAST capabilities, but the IDC MarketScape also offers a useful view of where the category is heading. DAST has developed beyond traditional web scanning into a source of runtime evidence that can help organizations validate risk across the application layer. From possible weakness to validated application risk. Code analysis and dependency scanning help teams identify weaknesses before an application is deployed. DAST provides a different view by interacting with the assembled application while it is running. It can show what happens when a particular request reaches the application, how the application responds, and whether a suspected weakness can be reproduced. This is especially valuable for APIs and AI-backed applications, where risk may emerge through interactions among models, prompts, data, tools, and permissions. Some of these behaviors cannot be fully understood from source code or a dependency manifest. They become visible when the application is exercised under runtime conditions. DAST therefore has a direct role in continuous threat exposure management (CTEM). Discovery gives teams a view of their assets and possible weaknesses, but that view alone does not tell them where to focus. Validation helps narrow the field by showing which exposures can be reached or exploited and providing evidence that teams can use to take action. For Rapid7, DAST is exposure management applied to the application layer. Web applications, APIs, and AI-backed endpoints are all part of the attack surface, so they need to be discovered, tested, prioritized, and managed alongside infrastructure, cloud, and other exposures. Why Rapid7 believe Rapid7 was named a Leader by IDC. Rapid7's DAST solution is delivered as part of the Exposure Command portfolio. Its scan engine maps an application, executes attacks against the discovered paths, and validates confirmed findings. Security teams can map a broad area of an application while limiting active attacks to an appropriate set of paths, giving them control over how testing is performed. Findings are checked against Rapid7 telemetry to help determine which issues warrant closer attention. When a finding needs action, browser-based replay reproduces the original request, the attack request, and the triggering response. Developers receive evidence they can work with, rather than a finding they must first spend time proving. Authenticated scanning can be difficult to maintain across a changing application portfolio, and a broken login sequence can leave important areas untested. Rapid7's solution can identify the affected step and support a targeted update without requiring the entire sequence to be recorded again. The connection with Surface Command adds another useful layer. Newly discovered external assets can be surfaced for application testing, helping teams close the gap between finding an application and understanding the risk it presents DAST plays a core role within Exposure Command: providing the application-layer validation teams need to prioritize risk and move from findings to remediation.

Rapid7
Aug 19th, 2026
Rapid7 and Licencias OnLine partner to accelerate cybersecurity maturity across Latin America.

Rapid7 and Licencias OnLine partner to accelerate cybersecurity maturity across Latin America. Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces. In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI - all without adding operational complexity. To help security leaders and practitioners address this complexity, Rapid7 is excited to announce a new strategic distribution partnership with Licencias OnLine (LOL) across Latin America. Helping organizations stay ahead of evolving threats. In order to keep day-to-day business operations moving, organizations need security solutions that not only protect critical assets but also support innovation, regulatory compliance, and long-term digital transformation. Rapid7's AI-powered cybersecurity operations platform helps organizations strengthen cyber resilience by unifying continuous exposure management, AI-driven threat detection and response, and security automation. By connecting security data across endpoint, cloud, identity, and infrastructure environments, organizations leverage one platform to gain the visibility to reduce risk and act with confidence. A shared commitment to partner success. Success in today's fragmented cybersecurity environments depends on a strong ecosystem of partners who can help organizations implement, optimize, and maximize the value of unified security operations. This is where Licencias OnLine comes in. With a strong, well-established presence across Latin America, deep cybersecurity expertise, and a highly specialized channel ecosystem, Licencias OnLine brings the local knowledge, technical enablement, and operational agility needed to help partners grow their cybersecurity practices and deliver greater value to customers. Together, Rapid7 and Licencias OnLine will invest in technical training, partner enablement, joint marketing initiatives, and go-to-market programs that help partners expand managed security services, strengthen customer relationships, and accelerate business growth across the region. Building cyber resilience together. As organizations across Latin America continue to modernize their IT environments, they should have access to security operations that are integrated, intelligent, and designed for today's AI-powered threat landscape. Rapid7's open platform supports this approach through hundreds of technology integrations that help organizations eliminate security silos, improve visibility across their attack surfaces, and automate response workflows. This enables security teams to reduce operational complexity while improving cybersecurity program maturity. By combining Rapid7's global cybersecurity innovation with Licencias OnLine's regional expertise and trusted partner network, this new alliance will make it easier for organizations across Latin America to strengthen cyber resilience while enabling partners to see greater success through measurable business outcomes. Rapid7 is excited to begin this next chapter together and look forward to supporting its partners as they help customers build stronger, more resilient security operations across the region. Ready to grow with Rapid7? Discover how Rapid7 and Licencias OnLine are helping partners accelerate cybersecurity maturity across Latin America.

GlobeNewswire
Aug 18th, 2026
Progress Software appoints Bridget Collins as Chief Information Officer.

Progress Software appoints Bridget Collins as Chief Information Officer. Accomplished technology executive to lead enterprise IT strategy, AI acceleration, cybersecurity and M&A integration BURLINGTON, Mass., Aug. 18, 2026 (GLOBE NEWSWIRE) - Progress Software (Nasdaq: PRGS), an AI infrastructure software leader, today announced the appointment of Bridget Collins as Chief Information Officer (CIO). A seasoned technology executive with more than 30 years of experience in enterprise IT, business transformation and AI strategy, Collins will lead the company's global IT and security organization and report directly to CEO Yogesh Gupta. "The operational excellence of our global CIO team plays a critical role in enabling our growth strategy and advancing AI across the business while mitigating risk," said Yogesh Gupta, CEO of Progress Software. "Bridget's deep expertise in enterprise technology, business transformation and cybersecurity will help us continue scaling our operations, integrating acquisitions and delivering exceptional experiences for our employees and customers. It is especially heartening to welcome Bridget back to Progress where she began her career as a software engineer." As CIO, Collins will also lead the advancement of AI across internal operations and oversee cybersecurity for the company, evaluating emerging technologies and strengthening governance frameworks for data, security and AI usage. "Progress has established itself as a leader in delivering the context and control organizations need to succeed with AI," said Collins. "I look forward to partnering across the business to further expand upon Progress' AI vision in support of our customers and employees, and to become part of the company's next phase of growth." Previously, Collins served as Chief Information and Business Transformation Officer at cybersecurity leader Rapid7, where she led global IT and operations. She has held leadership roles as Chief Transformation Officer and CIO at Cerence, a leader in AI-powered virtual assistants for the automotive market, and as Vice President of Information Technology at Nuance Communications, a pioneer in conversational artificial intelligence and speech recognition. Collins was named a 2021 BostonCIO of the Year ORBIE(R) Award winner, recognizing excellence in technology leadership. She holds a bachelor's degree from Providence College and an MBA in High Technology Management from Northeastern University. About Progress Software Progress Software (Nasdaq: PRGS) provides the context and control organizations need to reliably extract value from AI - context drawn from an organization's data, content and workflows, and control over the security, governance and cost of their AI initiatives. Learn how hundreds of thousands of businesses, powering the work of tens of millions of professionals worldwide, realize value from trusted, enterprise-ready AI at www.progress.com. Progress is a trademark or registered trademark of Progress Software Corporation and/or its subsidiaries or affiliates in the U.S. and other countries. Any other names contained herein may be trademarks of their respective owners. Press Contact: Jeff Young Progress Software +1-800-477-6473 [email protected]

CloudLink Tech
Aug 14th, 2026
Rapid7 cuts 314 jobs; Boeing 737 hack demo; fridge flaws.

Rapid7 cuts 314 jobs; Boeing 737 hack demo; fridge flaws. Rapid7 will cut 314 jobs. Researchers showed a coin-sized device can access Boeing 737 systems. Claroty found RCE flaws in Copeland XWEB Pro and Danfoss AK-SM 800A controllers, now patched. Rapid7 announced it will eliminate 314 positions, about 12% of its workforce, under a restructuring led by CEO Wael Mohamed. The company expects up to $11 million in severance and related costs and plans to refocus resources on product modernization and artificial intelligence features for its core security platform. Rapid7 outlined a goal of lifting its non-GAAP operating margin to 20% by the fourth quarter of 2026 and said operations will continue as the company implements the changes. A team of academic security researchers demonstrated that a coin-sized hardware device attached to an external aircraft port can give an attacker access to certain systems on a Boeing 737. The device was shown to spoof sensor inputs such as outside air temperature and aircraft weight and could be used to alter a flight plan. The researchers noted that existing aircraft safety systems would likely prevent direct harm during normal operations. The test involved installing a small covert implant on an external port and observing how manipulated inputs affected onboard operational data. Claroty's Team82 reported 23 vulnerabilities in Copeland XWEB Pro refrigeration controllers, including flaws that can be chained to bypass controls and achieve root-level remote code execution. In a demonstration, a compromised controller was able to change the behavior of cooling fans and compressors while concealing resulting temperature increases, creating a risk of undetected food spoilage. Team82 also identified multiple vulnerabilities, including remote code execution, in Danfoss AK-SM 800A controllers. Copeland and Danfoss released patches after the issues were reported and provided mitigation guidance for customers. The Rapid7 restructuring affects a range of roles across the company as leadership concentrates on consolidating the platform and adding AI capabilities. The aviation experiment involved physical access to an aircraft port and tested how a concealed implant could provide persistent connectivity and a foothold for further manipulation. For the refrigeration findings, vendors and researchers recommended applying available patches, segmenting control systems from enterprise networks, and restricting remote access to controllers. Each disclosure was shared with the affected parties and followed by mitigations: Rapid7 published expected costs and timing for its restructuring, the aircraft researchers made their findings available to prompt security reviews of external ports and maintenance procedures, and refrigeration vendors issued fixes and guidance to customers.

Yahoo Finance
Aug 13th, 2026
Rapid7 shares jump 27% on strong Q2 earnings beat and raised guidance despite revenue dip

Rapid7's shares surged 26.9% after the cybersecurity company reported second-quarter 2026 results that significantly exceeded profit expectations. Adjusted earnings per share of $0.44 beat the $0.35 consensus estimate, whilst adjusted EBITDA of $35.85 million topped the $31.93 million forecast. However, revenue of $210.9 million declined 1.5% year-over-year. Annual recurring revenue slipped 2% to $824 million, and billings dropped 5.7% to $202.4 million. In response, newly appointed CEO Wael Mohamed announced a 12% workforce reduction to refocus resources on core Detection and Response platforms. Management raised full-year adjusted EPS guidance by 15.7% to $1.81 at the midpoint. Rapid7 highlighted integrating OpenAI's GPT-5.5 and Anthropic's Claude Mythos model into its security workflows, emphasising AI-driven capabilities.