Full-Time
Updated on 9/4/2026
Open XDR platform for security operations
$120k - $215k/yr
Remote in USA
Remote
See people who can refer or advise you
Stellar Cyber offers an Open XDR platform that unifies security data from multiple tools for enterprises, MSSPs, and public sector organizations. The product uses a scalable data lake to collect and transform data from different security tools, creating a single view for faster investigation and response, and it automates detection and response to speed up actions against threats. The company differentiates itself by providing end-to-end visibility across a wide toolset and cross-tool workflow automation, with a subscription-based software model plus services like threat hunting and security consulting. Its goal is to help customers reduce risk and shorten detection and response times without adding burden to security teams.
Company Size
51-200
Company Stage
Late Stage VC
Total Funding
$112.8M
Headquarters
Santa Clara, California
Founded
2015
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Stock Options
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Employee Assistance Program
Employee Discount Program
Paid Vacation
Referral Program
Rewards and Recognition Program
"Stellar Cyber" recognized as a "Progressive Company" in MarketsandMarkets' latest 360Quadrant for the Network Detection and Response (NDR) Market. Sep 03, 2026, 10:45 ET DELRAY BEACH, Fla., Sept. 3, 2026 /PRNewswire/ - Stellar Cyber, a cybersecurity provider, is recognized as a Progressive Company in the Network Detection and Response (NDR) market by MarketsandMarkets' 360Quadrants platform. Stellar Cyber demonstrates a strong product footprint and market position, reflecting its capabilities in AI-driven network detection, threat analysis, security operations, and integrated response. The increasing complexity of distributed network environments, including IT, OT, cloud, and remote infrastructure, is making it more challenging for security teams to maintain visibility and identify threats moving across network environments. Organizations are increasingly seeking NDR capabilities that can collect network telemetry, identify lateral movement, and provide actionable information for investigation and response. Capabilities such as Deep Packet Inspection, machine-learning-based detection, automated correlation, and integrated response are further strengthening the role of NDR solutions in modern security operations. Through its NDR solution, Stellar Cyber provides an integrated portfolio for network detection and response. Its physical and virtual sensors combine Deep Packet Inspection (DPI), Machine Learning Intrusion Detection System (ML-IDS), and a malware sandbox, while its Data Lake aggregates security data for analysis. The platform also incorporates built-in threat intelligence and AI-powered detections and correlations to help security teams identify, investigate, and respond to network threats. The company's broader approach focuses on integrating NDR with the existing security infrastructure rather than requiring organizations to operate it as an isolated layer. Stellar Cyber supports integrations with next-generation firewalls, EDR, identity and access technologies, and other security tools through connectors, log forwarders, and APIs. This allows organizations to extend network detection across their existing security environment while using established technologies for data collection and response. Stellar Cyber's positioning as a Progressive Company in the NDR market reflects its ability to combine network detection with an integrated approach to security operations. The company's focus on AI-driven NDR, open integrations, and support for existing security infrastructure strengthens its ability to extend network visibility and response capabilities without requiring organizations to operate NDR in isolation. This approach supports Stellar Cyber's ability to address evolving network detection and response requirements across enterprise, IT, OT, and cloud environments. Research Methodology 360Quadrants provides an in-depth evaluation and comparison of each key market player based on various techno-commercial inputs provided by industry experts, customers, vendors, and other stakeholders, along with secondary research that includes product brochures, analyst notes, company publications, business articles, white papers, trade sources, and various other databases. A well-defined methodology is adopted to provide detailed ratings for each market player concerning various parameters as outlined below: * Shortlisting of 25+ prominent market players & start-ups * Relevant portfolio mapping at the regional level * Key growth initiatives undertaken at the regional level * Revenue analysis at a regional and category level * Strategic collaborations with governments, patient/customer groups, etc. * Other industry-relevant parameters About 360Quadrants 360Quadrants is the largest marketplace looking to disrupt over USD 3.7 trillion of technology spend and is the only rating platform for vendors in the technology space. The platform provides users with unbiased information that helps them make informed business decisions, while also enabling vendors to influence the business decisions of potential clients. Vendors get to win ideal new customers, customize their quadrants, decide key parameters, and position themselves strategically in a niche space, to be consumed by giants and start-ups alike. Experts get to grow their brands and increase their thought leadership. The platform targets the building of a social network that links industry experts with companies worldwide. About MarketsandMarkets(TM) MarketsandMarkets(TM), recognized as one of America's Best Management Consulting Firms by Forbes as per their recent report, is a blue ocean alternative in growth consulting and program management, leveraging a man-machine offering to drive supernormal growth for progressive organizations in the B2B space. With a broad lens on emerging technologies, the company is proficient in co-creating exceptional growth for clients worldwide. Today, 80% of Fortune 2000 companies rely on MarketsandMarkets, and 90 of the top 100 companies in each sector trust it to accelerate their revenue growth. With a global clientele of over 13,000 organizations, MarketsandMarkets helps businesses thrive in a rapidly evolving and disruptive ecosystem. The B2B economy is witnessing the emergence of USD 25 trillion in new revenue streams that are replacing existing ones within this decade. MarketsandMarkets collaborates with clients on growth programs, enabling them to monetize this USD 25 trillion opportunity through their service lines, including TAM Expansion, Go-to-Market (GTM) Strategy to Execution, Market Share Gain, Account Enablement, and Thought Leadership Marketing. Built on the 'GIVE Growth' principle, MarketsandMarkets collaborates with several Forbes Global 2000 B2B companies to keep them future-ready. The company's insights and strategies are powered by industry experts, cutting-edge AI, and their proprietary Market Intelligence Cloud, KnowledgeStore(TM), which integrates research and provides ecosystem-wide visibility into revenue shifts. SOURCE MarketsandMarkets
Stellar Cyber and M-Theory Group will demonstrate a co-managed, AI-powered security operations centre at Black Hat USA 2026 in Las Vegas. The companies are showcasing how artificial intelligence and human analysts work together in a managed detection and response model. Recent Stellar Cyber data analysed over 130,000 alerts across 124 days, showing AI-powered triage returned 19 minutes of every analyst hour. This equates to approximately 1.5 Level 1 analysts annually. The analysis revealed 99.7% agreement between AI verdicts and human analysts. The demonstration will feature Stellar Cyber's Multi-Layer AI platform combined with M-Theory's managed detection and response expertise. The model targets organisations needing stronger detection and response capabilities without building a full 24/7 security operations centre. Attendees can view the demonstration at booth 5542 during the conference.
Stellar Cyber adds Brite, Inspira and M-Theory as delivery partners. July 27, 2026 Stellar Cyber has named Brite, Inspira, and M-Theory as the first approved partners in its Infinity Delivery Partner Program, giving the three companies a larger role in deploying and operating its security operations platform. The partners will provide services including deployment planning, architecture reviews, data onboarding, integrations, detection tuning, automation, and ongoing operational support. The program is aimed at customers and service providers who need more help after the initial platform purchase. Security operations deployments often require continued work around data normalization, dashboards, rules, APIs, testing, and workflow design. Under the new model, qualified partners can lead those engagements while Stellar Cyber provides training, technical guidance, and escalation support. For Brite, Inspira, and M-Theory, the program opens a broader services opportunity around the Stellar Cyber platform. Rather than limiting their involvement to resale and basic implementation, the companies can build longer-term consulting and managed services relationships. That could increase service revenue and customer retention while giving partners more influence over how the platform is used inside each account. Stellar Cyber will require delivery partners to maintain trained technical teams, named delivery leads, documented implementation processes, and ongoing certifications. The first three appointments show the company placing more responsibility for customer deployment and adoption in the hands of its channel, creating a clearer delivery model for partners supporting complex enterprise and MSSP environments.
Stellar Cyber expands its AI-native SOC platform with releases 6.5, 6.6. June 25, 2026 AI cybersecurity safeguards systems with encryption, access control, and AI secure data flow. Futuristic cyber security featuring AI digital shield, zero trust and AI threat detection system. Corpus AI has become a cornerstone in security operations centers (SOCs), with security teams and MSSPs using the technology for everything from reducing alert fatigue to accelerating the mean-time-to-response to enhancing threat detection. For organizations with SOCs, the rapidly evolving technology acts as a force multiplier, letting them to scale without having to add too much headcount, while also increasingly leveling the playing field against adversaries that are quickly using AI in their attacks. That said, it isn't always easy figuring out how best to use the technology. "Many practitioners are still struggling to turn early experimentation into consistent operational value," wrote Christopher Crowley, a senior instructor with the SANS Institute and SOC consultant. "This is because SOCs are adopting AI without an intentional approach to operational integration. Some teams treat it as a shortcut for broken processes. Others attempt to apply machine learning to problems that are not well defined." In the SANS 2025 SOC Survey, the cybersecurity training institute found that many organizations are experimenting with AI, but that 40% of SOCs use AI or machine learning tools without making them a defined part of the operations, and 42% rely on these tools out of the box, with no customization. This creates what Crowley called a "familiar pattern. AI is present inside the SOC but not operationalized." A lot in two releases. Still, vendors are building out the AI capabilities in their SOC platforms, giving organizations more ways to use the technology to their advantage. Stellar Cyber, in the last two releases of its AI-native SecOps platform, expanded the capabilities of its Auto Triage tool, extended detection coverage across identity, cloud, network, and application-driven threats, improved the platform's operations, and introduced Parser Studio to create a self-service workspace for creating, testing, and activating custom parsers. In Stellar Cyber 6.5 (released in May) and 6.6 (introduced this month), the vendor also offered early access support for the Stellar Cyber MCP Server, giving certain AI customers a governed way to connect to the platform via the Model Context Protocol (MCP) Server, and improved network and sensor coverage. "Taken together, 6.5 and 6.6 move Stellar Cyber closer to the goal of the human-augmented autonomous SOC by improving the full operating loop: data onboarding, threat detection quality, triage, investigation, case management, automation, and response," Christophe Briguet, Stellar Cyber's senior director of product management for AI and security analytics, told MSSP Alert. "That matters because SOC teams do not have one isolated problem. They need cleaner data, better context around threat alerts, faster decisions, and trusted automation, all working together." Everything in a single platform. Such a broad approach is something that separates what Stellar Cyber offers from competitors' platforms, Briguet said. "Many automated SOC offerings focus on a single layer, such as AI assistants, SOAR playbooks, or alert triage," he said. "Stellar Cyber differentiates itself by combining AI, automation, detection engineering, case management, response orchestration, and open integrations into a single platform, while retaining human oversight and control." Writing about 6.5, Mayuresh Ektare, senior vice president of product management for Stellar Cyber, noted that with Parser Studio, security teams can see built-in and custom parsers, clone supported modular parsers, test parser behavior before deployment, and activate parsers for production ingestion, which, for MSSPs, can shorten client onboarding cycles and reduce their dependency on vendor-delivered parser work. Parser development is now a security outcome issue, not simply a back-office detail, Ektare wrote. A security outcome issue. "Every environment has unique telemetry," he wrote. "MSSPs see this every day. One customer uses a particular firewall. Another uses a regional VPN provider. Another has specialized infrastructure, legacy systems, DLP tools, file transfer platforms, remote access technologies, API security products, or custom applications." He added that "if onboarding that telemetry requires long vendor cycles or custom engineering every time, the security program slows down before it begins delivering value." The Stellar Cyber MCP Server lets users bring AI into existing SOC workflows with case context, tenant awareness, and access controls rather than relying on disconnected assistants outside the analyst workflow. The vendor extended the Auto Triage feature by adding verdict visibility to the Alert Table and Threat Hunting views so analysts can more quickly see triage outcomes, filter them by verdict, and more easily act on the results. Benefits for MSSPs. Such enhancements will benefit MSSPs, which Briguet said are under pressure to deliver better outcomes, speed up onboarding, improve reporting, and broaden their coverage without adding analysts. "The improvements we made to 6.5 and 6.6 help them achieve all of this by enhancing parser creation, data onboarding, detection fidelity, AI-assisted triage, case visibility, and repeatable workflows, enabling MSSPs to scale services while protecting margins," he said. Stellar Cyber 6.5 is available now, while some updates in Stellar Cyber 6.6, like the Stellar Cyber MCP Server and Parser Studio, are available through the vendor's Early Access Program. An in-depth guide to cloud security. Get essential knowledge and practical strategies to fortify your cloud security. Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He's an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.
Stellar Cyber enhances threat detection & data onboarding with new updates. Post Views: 3 Stellar Cyber has introduced advancements in threat detection capabilities and data integration processes through updates to its Stellar Cyber 6.5 and 6.6 platforms. Advancements in threat detection and data integration. These releases build upon the company's AI-driven, human-assisted security operations center (SOC) framework by incorporating controlled AI workflows, enhanced Auto Triage functionalities, improved detection accuracy, and expanded integration options. The updates aim to streamline operations for managed security service providers (MSSPs) and enterprise security teams by reducing friction in data onboarding and enabling more efficient incident response. Key features of the updates. The platform emphasizes the need for a unified system that accelerates threat identification, provides contextual investigation tools, and ensures seamless data integration without requiring additional alerts or fragmented tools. This approach aligns with the company's focus on integrating AI-assisted analysis with human oversight to create actionable security operations (SecOps) workflows. AI-Native SOC Workflows. Key features of the updates include AI-native SOC workflows with controlled access to AI functionalities. Version 6.5 introduced early access to the Stellar Cyber MCP Server, allowing approved AI clients to connect to the platform via the Model Context Protocol. This integration enables AI to operate within existing SOC workflows, leveraging case-specific context, tenant awareness, and access controls rather than relying on standalone AI assistants. Enhanced Auto Triage and detection accuracy. Auto Triage visibility and actionable outcomes have been expanded in version 6.6. The release adds verdict tracking to the Alert Table and Threat Hunting views, including filterable columns for triage results. A response action panel on the Auto Triage alert page allows analysts to act on findings without navigating away from the interface. Detection accuracy has been improved across identity, cloud, and network domains. Operational enhancements. Operational enhancements in the releases include a Dashboard Hub for centralized monitoring, temporary alert filters for dynamic analysis, improved rule import/export functionality for Automated Threat Hunting (ATH), and enhanced timestamps for playbook execution. Platform health monitoring is now accessible through the System Action Center, while license enforcement and usage notification APIs provide better resource management. Self-Service data onboarding and flexibility. Self-service data onboarding capabilities have been expanded through Parser Studio, introduced in 6.5. This tool allows teams to create, test, and deploy custom parsers independently. Version 6.6 adds broader parser and connector coverage, selective parser port activation, and support for response actions from Liongard, Ironscales, and Check Point Smart-1 Cloud. Network and sensor coverage improvements. Network and sensor coverage has been deepened with updates such as Azure VTAP documentation, SMB session ID tracking, NFS file assembly for malware analysis, expanded Linux sensor support, and DPI protocol bundle updates. Version 6.6 also includes Suricata 8.0.1 integration and enhanced sensor security hardening for local service communications. Conclusion. Stellar Cyber's updates to its 6.5 and 6.6 platforms demonstrate a commitment to enhancing threat detection, streamlining operations, and improving integration capabilities for security teams and MSSPs. According to Stellar Cyber, the platform's focus on AI-assisted analysis with human oversight ensures actionable SecOps workflows, reducing friction in data onboarding and enabling efficient incident response.