Full-Time
Updated on 9/4/2026
Real-time network monitoring and security analytics
No salary listed
Canberra ACT, Australia
Hybrid
Remote role with a balanced mix of remote collaboration and in-person customer meetings; occasional travel is required.
Bachelor's
See people who can refer or advise you
ExtraHop provides cybersecurity and IT operations analytics to large enterprises, helping them monitor and secure their networks in real time. Its products give visibility into network activity, detect anomalies, and enable rapid threat response. The portfolio includes security solutions, cloud performance monitoring, and application analytics, sold mainly via a subscription model that includes professional services and training. Compared with competitors, ExtraHop combines real-time network visibility with analytics across security, cloud performance, and applications, targeting sizable enterprise customers across industries like healthcare, finance, and retail. The company’s goal is to help customers protect sensitive data, maintain smooth IT operations, and continually update its offerings to guard against evolving cyber threats while maintaining a steady, recurring revenue stream.
Company Size
501-1,000
Company Stage
Growth Equity (Venture Capital)
Total Funding
$161.6M
Headquarters
Seattle, Washington
Founded
2007
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Unlimited Paid Time Off
401(k) Company Match
Pet Insurance
Parental Leave
Hybrid Work Options
Educational Reimbursement
FSA and Dependent Care Accounts
Paid Volunteer Time
Annual Discretionary Bonus Plan
ExtraHop has launched the first network detection and response platform capable of analysing enterprise data centre traffic at 400 Gbps. The new sensor ingests and analyses traffic at line rate, addressing security gaps created as data centres upgraded to 400 Gbps whilst most detection tools remained at 100 Gbps. The company says AI adoption has intensified visibility challenges, with GPU clusters and encrypted east-west traffic generating volumes that make traffic sampling inadequate. Mean time to exploit has dropped from 23.2 days in 2025 to roughly 1.6 days in 2026. ExtraHop RevealX structures network data into a continuously updated semantic map accessible through APIs. The platform analyses traffic across over 90 protocols and provides full-fidelity packet capture. The 400 Gbps sensor will be generally available in Q4 2026.
ExtraHop launches 400 Gbps sensor for RevealX platform. Tue, 25th Aug 2026 (Today) ExtraHop has launched a 400 Gbps sensor for its RevealX network detection and response platform, saying it makes RevealX the first NDR platform able to analyse enterprise data centre traffic in full at that speed. The launch addresses a problem for security teams as data centre networks have moved to 400 Gbps while many detection and response tools remain limited to 100 Gbps. As a result, some organisations sample traffic instead of inspecting all of it, creating visibility gaps in high-speed environments. According to ExtraHop, the new sensor analyses traffic at line rate and feeds that data into RevealX, which maps devices, identities, workloads and network conversations in real time. Security operations teams and automated systems can then query that information through APIs and Model Context Protocol interfaces, and access underlying records such as behavioural detections, protocol activity, transaction data across more than 90 protocols, and packet capture. The announcement comes as security vendors and customers grapple with the rise of automated attacks and the growing use of AI systems in corporate infrastructure. ExtraHop pointed to a sharp fall in mean time to exploit, from 23.2 days in 2025 to about 1.6 days in 2026, arguing that tools that see only part of network traffic leave little room for an effective response. Dense east-west traffic inside data centres has also become harder to inspect as organisations add GPU clusters, Kubernetes workloads, model training pipelines, inference systems and traffic between software agents. ExtraHop said these conditions have made network sampling less viable and increased the risk that lateral movement, identity compromise and other intrusions go undetected. Context Layer ExtraHop positioned the sensor as part of a wider shift towards what it called an agentic security operations centre, where automated agents play a larger role in detection and response. In that model, the quality and completeness of available data become central, because partial telemetry can cause automated tools to make incorrect decisions quickly and at scale. The company said the 400 Gbps sensor sits in the Context layer of the three-layer architecture used by the Agentic SOC Alliance: Context, Harness and Model. It argued that real-time structured evidence should sit alongside established systems such as security information and event management platforms and forensic data lakes, which are more often used for historical analysis. Chris Konrad, Vice President of Global Cyber at World Wide Technology, said complete visibility at modern data centre speeds had become more urgent. "AI is compounding the volume of data moving across our infrastructure every day, and our security tooling has not kept pace with our data center," Konrad said. "Complete visibility at this scale is no longer optional post-Mythos. AI-powered attacks move at record speed, and the AI-powered systems need to be able to tell the difference between a quiet network and a network they are only partially seeing." Market Pressure ExtraHop said operating at 400 Gbps could also reduce the number of sensors needed in high-speed networks, cutting operational complexity and lowering overall cost. It added that a single real-time view of network activity could serve both security and IT operations teams, reducing the need to reconcile different data sources across tools. The vendor also said the system supports a live inventory of AI-related assets, including large language model usage, MCP servers, tool endpoints and communication paths between agents. That reflects a broader push among security suppliers to give customers more visibility into how AI components are used inside enterprise environments. Kanaiya Vasani, Chief Product Officer at ExtraHop, said the issue was less about adding AI to existing tools and more about the data beneath them. "The reflex across the industry has been to bolt AI onto the SOC we already have, and the harder problem is the context substrate underneath," Vasani said. "SIEMs, forensic data lakes, and security warehouses are built to look backward. They are valuable as depth and memory, but they cannot be the first and only source of truth for an agent that has to decide something right now. RevealX is the prevention side of that equation: structured, queryable evidence whose latency budget matches the attack. At 400 Gbps, the busiest networks in the world can hand their agents complete evidence instead of a sample, which is the difference between autonomy a CISO can defend to a regulator and autonomy that is confidently wrong at scale."
Prophet Security has partnered with ExtraHop to integrate network detection telemetry into Prophet's Agentic AI SOC Platform. The collaboration allows security teams to autonomously investigate ExtraHop RevealX alerts and incorporate network context into investigations from any alert source, including endpoint, identity, cloud and email systems. The integration launches with two capabilities: autonomous investigation of RevealX network detections and the ability to query network context for investigations from any source. Prophet AI agents can access device information, identity activity, behavioural detections and packet captures from RevealX to reach final determinations. The integration is generally available at no additional charge to existing customers of either company. Prophet Security, backed by Accel, Bain Capital Ventures, Amex Ventures and Citi Ventures, provides an Agentic AI platform for security operations automation.
Cato Networks appoints Tristan Elder as VP of EMEA Channel to accelerate AI security growth. Cato Networks, delivering the leading network security platform for the AI era, today announced the appointment of Tristan Elder as Vice President of EMEA Channel. This move underscores Cato's commitment to scaling its regional partner ecosystem and capitalising on the surging demand for AI security solutions. In this key leadership role, Elder will drive Cato's EMEA channel initiatives, expanding the company's partner programme with a strategic focus on global systems integrators, managed service providers, consulting firms and strategic resellers. Elder joins Cato from ExtraHop Networks, where he led the EMEA channel business. Before ExtraHop, he was part of the early leadership team at CrowdStrike, where he helped build and scale the company's operations across EMEA during its high-growth years. He brings a proven track record of growing enterprise channel businesses across financial services, government and large enterprise accounts. This strategic appointment comes at a pivotal time as enterprise demand for AI security expertise intensifies across EMEA. Organisations are increasingly relying on their channel partners for guidance on AI governance, security risk and the secure deployment of AI technologies. Cato provides partners with the scalable foundation to meet this growing demand, enabling them to support enterprise customers across the full deployment and management lifecycle. This strategic appointment reinforces Cato's strong market trajectory. The company closed 2025 with annual recurring revenue (ARR) exceeding $350 million, a strong 43% year-over-year increase that outperformed the SASE market average. This growth was further fuelled by a $409 million Series G funding round within the past year, which propelled its valuation beyond $4.8 billion and brought total investment to over $1 billion. Additionally, Cato made a strategic acquisition of Aim Security, enhancing its specialised capabilities in securing AI interactions. Elder, Vice President of EMEA Channel From the first day, I am already seeing huge demand for strategy meetings with existing and new Cato partners Karl Soderlund, Global Channel Chief at Cato Networks What stood out about Tristan is not just his experience, but that he has been through this kind of journey before: building a channel business in a high-growth environment, working closely with partners, and helping teams scale. That perspective is exactly what we need as we continue to grow and invest across the region. Ray Sharma is an Industry Analyst and Editor at The Fast Mode. He has over 15 years of experience in mobile broadband technologies and solutions, conducting research and analysis on various technology segments and producing articles and write-ups on the latest developments within the sector. He is also in charge of social media engagement and industry liaisons. The Fast Mode 9658 likes TWEETS 28.4K FOLLOWING 3479 FOLLOWERS 13.2K
ExtraHop(R) named a Leader in Gartner(R) Magic Quadrant(TM) for Network Detection and Response for second consecutive year. May 21, 2026 ExtraHop advances its vision to secure enterprises against a new era of AI threats. SEATTLE - May 21, 2026 - ExtraHop(R), a leader in modern network detection and response (NDR), has been named a Leader in the 2026 Gartner(R) Magic Quadrant(TM) for Network Detection and Response for two consecutive years. Recognized by Gartner as a Leader for its Ability to Execute and Completeness of Vision, ExtraHop also continued to maintain the second highest revenue in NDR in 2025 (Gartner(R), Market Share: Enterprise Network Equipment by Market Segment, Worldwide, 4Q25). ExtraHop is also a Leader in The Forrester Wave(TM): Network Analysis And Visibility Solutions, Q4 2025, 2025 GigaOm Radar for Network Detection and Response (NDR) Solutions, and IDC MarketScape: Worldwide Network Detection and Response 2024 Vendor Assessment. The ExtraHop NDR platform is engineered to deliver unparalleled scale for the world's most demanding enterprise networks. By unifying NDR, network performance monitoring (NPM), intrusion detection (IDS), and network forensics in a single high-performance platform, ExtraHop turns continuous raw network telemetry into a strategic advantage, enabling organizations to: * Build an agentic SOC with confidence: ExtraHop provides the high-fidelity network context essential to power autonomous security agents, enabling the agentic SOC to counter AI-assisted attacks in real time and with high accuracy. * Expose hidden threats: ExtraHop decrypts and decodes traffic at line rate to reveal threats hiding within encrypted TLS and Microsoft RPC workflows - capabilities critical for securing the post-Mythos threat landscape. * De-risk AI transformation: ExtraHop delivers the full-stack observability required to identify security gaps and performance bottlenecks within AI workloads, allowing organizations to scale AI initiatives without compromising enterprise security. "NDR is the foundation of modern defense, providing the critical context needed to power the agentic SOC," said Kanaiya Vasani, Chief Product Officer, ExtraHop. "Defending against post-Mythos threats requires the depth of network intelligence that we believe has led to ExtraHop being positioned as a Leader in the Gartner(R) Magic Quadrant(TM) for NDR. Because we've built our platform to decipher complex, evasive behaviors in real-time and enrich network intelligence with endpoint and identity information, both humans and AI agents have the decisive edge they need to outmaneuver attackers hiding in plain sight." A Smarter Agentic SOC with High-Fidelity Data and Integrations ExtraHop is building the intelligence engine for the agentic SOC, delivering the high-fidelity network context AI models need to accurately triage and neutralize threats. By correlating insights across devices, users, applications, and identities in real-time, ExtraHop provides the evidence AI agents need to see the full scope of an attack This cross-domain context is further strengthened by strategic integrations with leaders like CrowdStrike, Microsoft, and Google, ensuring the most comprehensive intelligence to detect and neutralize threats. ExtraHop rounds out the agentic SOC vision by providing the automated workflows necessary for autonomous defense. Through Smart Triage and Smart Investigations, the platform correlates disparate events into a unified narrative, and a natural-language AI Search Assistant eliminates manual complexity while accelerating response times. Faster Threat Detection, Investigation, and Response with Unified Network Insights and Context In an era of high-velocity, AI-powered attacks and post-Mythos exploits, ExtraHop provides the real-time insights required to stop threats before they escalate. These insights are built on a history of innovation. First to bring native TLS decryption to the NDR market, ExtraHop makes it easier for organizations to uncover threats without compromising data privacy or performance. By decrypting line-rate traffic in real time, the platform ensures that sophisticated, encrypted attacks are stripped of their cover. Complementing this is deep fluency in nearly 100 protocols (including the ability to decrypt SSL and Microsoft protocols) and always-on full packet capture. Together, these capabilities allow SOC teams to expose threats hiding in legitimate workflows and instantly gather the context needed to accelerate investigations and slash mean time to respond (MTTR). The impact is best illustrated by a healthcare customer who said, "This tool is our number 1 tool used in security, especially during a penetration test or incident." (Gartner Peer Insights(TM) Real-Time AI Observability to Secure and Govern the Agentic Enterprise This same network telemetry and deep-layer context provides the real-time visibility into AI workloads organizations need to monitor behavioral shifts, enforce strict governance, and ensure compliance across the agentic enterprise. This deep insight is critical for detecting subtle anomalies within AI interactions, such as prompt injection or unauthorized data access, that signal potential misuse or a sophisticated attack. By monitoring these activities, ExtraHop ensures that as AI scales, organizations maintain the integrity and oversight necessary to secure the future of autonomous operations. Additional resources: Gartner, Magic Quadrant for Network Detection and Response 2026, By Thomas Lintemuth, Charanpal Bhogal, Nahim Fazal, May 18, 2026 Gartner, Market Share: Enterprise Network Equipment by Market Segment, Worldwide, 4Q25, By Gurjyot Uppal, Vivek Tiwari and Christian Canales, February 2026 Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose. Gartner, Magic Quadrant and Peer Insights are trademarks of Gartner, Inc. and/or its affiliates.