Full-Time
Open-source cybersecurity platform for threat management
No salary listed
Remote in USA
Remote
Fully remote within the United States, with regular on-site travel for instructor-led training delivery.
See people who can refer or advise you
Filigran builds an extended threat management (XTM) cybersecurity platform based on open-source principles, combining threat intelligence, breach-and-attack simulation, and risk management. Its core products include OpenCTI for consolidating and visualizing threat knowledge, OpenAEV for testing security controls against real-world attack scenarios, and OpenGRC for threat-informed risk management. The company operates a dual model with free open-source community editions and enterprise editions that add advanced features, managed hosting, and professional services such as support and training. Its goal is to help organizations anticipate and reduce cyber risk with a scalable, proactive security platform and agentic AI to automate threat analysis.
Company Size
201-500
Company Stage
Series C
Total Funding
$115.8M
Headquarters
Asnières-sur-Seine, France
Founded
2022
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Remote Work Options
Flexible Work Hours
401(k) Retirement Plan
401(k) Company Match
Stock Options
Equity
Filigran CTO on building an award-winning, ai-native Threat Management platform. Filigran was recently recognized with the Most Innovative Security Solution award for its eXtended Threat Management (XTM) Platform, an open, AI-native ecosystem that unifies threat intelligence, adversarial exposure validation, and risk governance. Tech Ascension Awards sat down with Julien Richard, CTO and Co-Founder of Filigran, to talk about the company's mission and how the XTM Platform is helping security teams move from reactive alert-chasing to continuous, threat-informed defense. For readers who may not be familiar with Filigran, can you introduce the company and what it does? A: Filigran is a European company, founded in 2022 by its CEO, Samuel Hassine, and me. Tech Ascension Awards started the company because Tech Ascension Awards saw the same gap everywhere: security teams had more tools and more data than ever, but no real way to turn that into fast, confident action. Its mission is to empower defense teams to be proactive through open-source solutions that uncover threats and drive action. Tech Ascension Awards began with OpenCTI, a platform to centralize and structure threat intelligence, and have since expanded into OpenAEV for continuous exposure validation, with OpenGRC (risk governance and quantification) coming next. Together, these form its XTM Platform. At its center is XTM One, an agentic AI layer that connects intelligence, validation, and response into one workflow. Everything Tech Ascension Awards build starts as open source. Tech Ascension Awards is backed by a global community of more than 6,500 practitioners who build alongside Tech Ascension Awards. What's the biggest challenge you see security teams facing today? A: It isn't a lack of data. Organizations have more visibility into their environments than ever. The real challenge is separating signal from noise. A large security team can receive thousands of alerts a day, but only a small fraction of them represent a genuine, exploitable threat. Its State of Threat Management report found that security teams spend an average of 42% of their time investigating risks that later prove low priority or non-exploitable. In a 40-hour week, that's about 17 hours per analyst. That's not just an efficiency problem. It's a retention problem, and it hits some of the most skilled people in the industry. How does the XTM Platform help organizations address that problem? A: Tech Ascension Awards help organizations move from reactive to proactive security, following what the industry calls CTEM: Continuous Threat Exposure Management. Instead of a point-in-time assessment, it's a continuous cycle: understand the threat landscape, prioritize the exposures that actually matter to you, validate whether your defenses hold up against realistic attacks, and act on what you find. Then repeat. That's exactly what its platform is built to deliver. Being secure today doesn't mean you're secure tomorrow. Threats evolve, and systems change, so defenses need to be tested continuously, not once a year during an audit. What role does AI play in Filigran's approach? A: AI helps teams keep pace with the volume and speed of modern threats, but the goal isn't to replace the analyst. It's to remove the low-value work that keeps analysts from focusing on what matters. Through XTM One, teams can ask direct questions of their own data, automate repetitive investigation steps, and get straight to the context they need, while humans stay in control of the decisions that count. The point of AI here isn't automation for its own sake. It's giving skilled people back the time to do the work only they can do. Why is open source such a core part of Filigran's model? A: Cybersecurity is built on trust, and trust requires transparency. When your security stack is open source, you can see exactly how it works, adapt it to your environment, and keep control of your own data. That matters enormously for organizations handling sensitive information, and increasingly for anyone thinking about digital sovereignty and long-term control of their systems. It also means Tech Ascension Awards build alongside its community of practitioners and contributors instead of behind closed doors. That community is a big part of why its products keep improving as fast as the threat landscape does. What's next for Filigran, and what excites you most right now? A: Tech Ascension Awards is focused on closing the gap between knowing about a risk and acting on it in time. That means connecting threat intelligence, exposure validation, and, risk governance and quantification. The goal is for security and business leaders to finally work from the same picture instead of several disconnected ones. What excites me most is that this isn't just a technology shift. It's a mindset shift, from managing alerts to managing outcomes. The organizations that make that shift are the ones that will actually get ahead of attackers, instead of constantly chasing them.
Intelligence Approval Workflows: ensure data quality and streamline processes. Organizations collect intelligence from many different sources, but not all data arrives in a consistent format or through automated feeds. Manual submissions, file imports, and form-based contributions often require review before becoming part of a trusted intelligence repository. Previously, draft content in OpenCTI could typically move between two simple states: Open or Validated. While effective for basic use cases, organizations often need greater visibility into the review status of a draft and who's responsible for the next action. This is precisely the gap that Filigran is addressing with its new draft intelligence workflows. Tl;dr. * Configurable multi-step approval workflows: OpenCTI now lets organizations build custom review chains for draft intelligence with fine-grained RBAC, keeping quality control and governance transparent and easy to set up. * Workflows can be applied to any draft intelligence: Unstructured, human-sourced intelligence (analyst notes, tips, customer reports) via manual creation, file import, form intake, or the browser extension. * Granular RBAC at status and transition level: Control who can view, edit, manage, or advance a draft, including dynamic roles and cross-organization sharing, for full accountability at every stage. * Built for scale and governance: ISACs, MSSPs, large enterprises, government bodies, and teams handling external intelligence all benefit from consistent, auditable review before data is published. Organizations can now configure multi-step approval workflows with fine grained role-based user access (RBAC) to ensure quality control and data governance, while keeping the process transparent and easy to implement. Whether it's an ISAC collecting member-submitted observations, an MSSP fielding incident reports from customers, or internal teams contributing their own intelligence, draft workflows ensure ingestion processes are consistent and scalable. Watch the video for an introduction to draft approval workflows in OpenCTI: Manual vs automated intelligence. Automated and manual threat intelligence serve very different purposes, and organizations need both. Whereas automated feeds are built for scale, continuously ingesting structured, pre-vetted data like indicators and reports from trusted sources, manual intelligence is built for context, capturing what only a person can observe. For instance an analyst's investigation notes, a partner's tip-off, or a customer's description of an incident, arriving unstructured and unvetted. That difference is exactly why manual submissions can't simply flow into the same pipeline as automated feeds: they require a review step that automated sources have often already earned. Submitting manual intelligence in OpenCTI. In OpenCTI manual submissions are saved in 'Draft' mode, so they can first be reviewed before entering the knowledge base. There are a few ways manual intelligence can be submitted in OpenCTI: * Manual draft creation: Analysts can create a draft directly in OpenCTI and populate it from scratch, building out entities and relationships within the isolated workspace before review. * File import: When importing a file, users can select draft validation mode so the system automatically generates a draft and routes the extracted results into it for review, instead of writing directly to the main knowledge base. * Form intake: Contributors can submit structured input via form toggles on entity list pages (Reports, Incidents, Threat Actors, Indicators, and more), the 'Import using a Form' option in the standard import dialog, or a shared form link distributed to external or non-expert contributors (e.g., ISAC members, MSSP customers) who need to submit incidents or observations without direct platform access. * XTM browser extension: With the Filigran browser plugin, analysts can capture intelligence while browsing, flagging web pages, articles, or indicators encountered in the field, and send them straight into a draft for review, streamlining collection at the source without leaving the browser. Flexible workflows to meet any organization's needs. Every organization has its own intelligence processes. Some may require only a few straightforward review steps, while others need detailed approval chains involving analysts, managers, and specialized teams. The new Draft Workflows can easily be adapted to your organization's needs. Administrators can create custom statuses, connect them through transitions, and define how drafts move from one stage to the next. Workflows can be kept simple, or expanded to support complex operational processes. With intelligence approval workflows, organizations can: * Define custom review and approval stages * Control which users or roles can move a draft forward * Restrict editing rights at specific stages * Maintain visibility into the status of intelligence submissions * Ensure only properly reviewed intelligence enters the platform Applying role-based access control to workflows. For organizations that require additional governance, workflows can incorporate role-based controls that determine who can perform specific actions or approvals. This provides a structured way to manage collaboration while preserving accountability throughout the review process. RBAC within a workflow can be controlled at two different levels: * 1/ Status: This setting controls who can view, edit or manage the draft content. Access control can be applied when the user enters or exits the draft. * 2/ Transition: This setting controls which user(s) can transition to the next step: * Who can trigger the transition (who can move the draft to the next status, regardless of editing rights on the draft). * Who can view, edit or manage the draft content. * Provide other organizations access to the draft content in the context of cross organization work. Built-in validation checks help ensure workflows remain coherent before publication, providing administrators with guidance during configuration. Playbooks can also be configured to run automatically when the new intelligence has completed the approval process. Key use cases. Organizations that manage high volumes of intelligence submissions or operate in highly regulated environments can particularly benefit from intelligence approval workflows, including: * Information Sharing and Analysis Centers (ISACs): Information-sharing communities that need controlled submission and approval processes. With members submitting intelligence from varied sources and skill levels, a formal review step ensures only vetted, actionable data reaches the wider community. * Managed security service providers (MSSPs): Coordinating intelligence between teams and customers. Approval workflows give MSSPs a consistent way to validate findings before they're passed to clients, protecting both accuracy and client trust. * Large enterprises: With multiple teams and review layers. Draft workflows let intelligence move through the right chain of stakeholders, from analysts to leadership, without bottlenecking day-to-day operations. * Government and public-sector organizations: These environments often require auditable, multi-stage sign-off before intelligence can inform decisions, especially when countering foreign information manipulation and interference (FIMI) campaigns. * Teams collecting intelligence from external sources: External submissions can vary widely in reliability, so a review layer helps confirm credibility and context before intelligence is acted upon or shared further. Community versus Enterprise Edition. Basic workflow management is included in the Community Edition, including the ability to define multiple steps in the approval workflow and perform the review process without having to leave the platform. The following advanced features are included in the Enterprise Edition: * Enforce RBAC at each step: Define who can view, edit, or manage a draft at every stage. Authorized members can be specific users, groups, or organizations, or dynamic roles like "the draft creator" or "the draft's author organization," ensuring only the right people can act on it at each point. * Control who can advance each step: Independent of edit rights, you can specify exactly which user, group, or organization can push a draft to its next step. For example, you can specify that only managers can move the draft forward. * Enable cross-organization collaboration: When platform segregation applies, drafts can be shared with other organizations before specific edit rights are assigned. You can pre-define which organizations automatically receive the draft at a given step, or leave it open so the user chooses who to share with when that step is reached. Conclusion. At its core, Draft Approval Workflows help organizations improve the quality of their intelligence. By introducing structured review gates before intelligence is published, teams can validate submissions, verify context, and ensure data meets internal standards before it enters the platform. The result: higher-quality intelligence, stronger governance, and a more consistent process for collecting, reviewing, and approving data before it enters your platform. Would you like to see Draft Approval Workflows in action? Book a demo with one of its threat intelligence experts, or start a free 30-day trial of OpenCTI Enterprise Edition.
AI-Powered attacks become top concern for security professionals, new Filigran survey reveals. A survey of cybersecurity professionals at Infosecurity Europe finds organisations struggling to prioritise risks, validate threats and prepare for AI-driven attacks LONDON, UK - 17th June 2026 - AI-powered attacks have emerged as the biggest cybersecurity concern among security professionals, according to new research conducted by Filigran during Infosecurity Europe 2026. The survey of 168 cybersecurity professionals across various industry sectors found that 41% identified AI-powered attacks at scale as their biggest security concern, nearly double the number citing supply chain risk (21%) or unknown threats (21%). AI-driven threats and what security professionals are doing about them is also the top concern for nearly one in three boards (32%). The findings suggest that organisations are entering a new phase of threat-informed defence, where security teams are focused on being armed with the intelligence and context to figure out which threats pose genuine business risk in order to make informed and accurate decisions quickly... "Organisations have access to more security data than ever before, but turning that information into action remains difficult," said Julien Richard, CTO at Filigran. "The challenge is determining which exposures actually matter, which can be exploited in their environment, and whether their existing controls will stop them. That's where many organisations are still struggling." Security teams continue to lose time to operational inefficiencies. When asked what wastes the most time in their security team, the most common response was chasing false positives and low-priority alerts (26%). A further 25% cited validating whether risks are real, while 17% said manually stitching together data from multiple security tools and 13% pointed to delays waiting for other teams to act on findings. The results suggest that security teams are spending a significant proportion of their time validating findings, correlating information and coordinating remediation efforts. As organisations face growing volumes of threat intelligence, vulnerabilities and security alerts, the challenge lies not in collecting more data, but in reducing complexity and accelerating decision-making across the security workflow. Boardrooms increasingly focused on AI-driven risk. When questioned on what boards ask about most, respondents selected AI-driven threats and organisational preparedness as the top issue, cited by 32% of security professionals. This placed AI ahead of more established boardroom cyber priorities, including regulatory compliance such as NIS2 and DORA (19%), supply chain and third-party risk (16%), and cloud and infrastructure exposure (15%). The findings indicate that boards are increasingly looking for reassurance that their organisations understand how AI could change the threat landscape, whether existing controls are fit for purpose, and how prepared security teams are to respond. For security leaders, this creates a growing need to translate AI risk into clear business terms, moving beyond technical discussion to explain exposure, readiness and resilience. Organisations struggle to turn threat intelligence into action. The survey found that while threat intelligence plays an increasingly important role in security operations, many organisations still struggle to translate intelligence into clear actionable priorities. Only 19% of respondents said they completely trust threat intelligence to tell them what to fix first. More than half (52%) said it helps inform decisions but still requires significant human judgement, while 21% said the volume of information often creates more noise than clarity. This challenge is reflected in automation priorities. When asked what they would automate tomorrow, the most common response was turning threat intelligence into actionable priorities, selected by 27% of respondents. Security pros remain cautious about autonomous AI. While AI-powered attacks topped the list of concerns, respondents showed significant caution when it came to using AI for security decision-making. Only 8% said they would trust AI to make security decisions without human approval. By comparison: * 44% said a human should always remain in the loop * 38% would trust AI only for low-risk, routine decisions * 11% said they are still experimenting with AI-driven decision-making This suggests that, for now, the most credible role for AI in cybersecurity is as an analyst accelerator rather than an independent decision-maker: helping teams move faster while keeping accountability and final judgement with human experts. CTEM adoption remains in its early stages. The survey also examined adoption of Continuous Threat Exposure Management (CTEM), a growing framework for prioritising and validating cyber risk. Only 28% of respondents described their organisation as having a continuous, proactive exposure management programme in place. The remainder reported either operating reactive security programmes, running disconnected initiatives, or being unfamiliar with CTEM altogether. "The findings from this research tell a consistent story: security professionals know they need to be more proactive, but the tools and processes around them create constraints and siloes," said Neena Sharma, Head of Customer and Product Marketing at Filigran. "The volume of findings is high but with no clear way to determine what matters, what's exploitable, and whether their defenses are working as expected to do so. That's the promise of Continuous Threat Exposure Management. It's not a single product; it's a discipline that allows security teams to unify threat signals, take faster, better-informed remediation decisions and show that the actions they're taking are actually reducing risk." About the research. The research was conducted by Filigran at Infosecurity Europe 2026. A total of 168 cybersecurity professionals participated in the survey, representing organisations of varying sizes across technology, financial services, government, healthcare, energy, manufacturing, communications, legal and other sectors. About Filigran Filigran, a cybersecurity company, offers an open-source, AI-powered, threat-informed approach to Continuous Threat Exposure Management (CTEM). Its eXtended Threat Management (XTM) platform delivers threat intelligence, exposure validation, and cyber risk reduction. Learn more: Website - Blog - LinkedIn - X
Filigran, a European open-source threat management company, has launched XTM One, an AI-native platform that automates Continuous Threat Exposure Management workflows. The company announced a $120 million Series C round led by Ribbit Capital, valuing it at $1.45 billion. XTM One introduces an AI orchestration layer connecting Filigran's OpenCTI and OpenAEV products, automating workflows from threat intelligence to validated defensive action. The platform deploys AI agents to handle intelligence ingestion, threat summarisation, attack scenario generation and remediation guidance. Early benchmarks show organisations achieving up to 70% faster threat detection cycles and 80% less preparation time for security testing. The platform supports on-premises deployment and allows organisations to use their own large language models. XTM One is available now across three pricing tiers.
Filigran launches XTM One to automate threat exposure management with AI agents. French cybersecurity company Filigran SAS today launched XTM One, an artificial intelligence orchestration layer that automates continuous threat exposure management workflows across its platform. XTM One connects the company's OpenCTI extended threat intelligence platform and its OpenAEV exposure validation tool into a single continuous workflow. Security teams today move manually between systems, ingesting threat intelligence in one tool, building attack scenarios in another and tracking remediation in separate dashboards. XTM One automates those handoffs by coordinating AI agents across the lifecycle, taking raw intelligence through to validated defensive action. The XTM platform already includes AI-powered automation within OpenCTI and OpenAEV. Filigran said XTM One differs by adding a dedicated layer where agents coordinate across products rather than assisting within a single one. "The volume of CVEs, threat actors and attack campaigns has reached a scale no human team can process manually," said co-founder Julien Richard. "XTM One is not AI as a feature. It is AI as the operating system for threat management. Security teams deserve automation that works the way they work." The platform ships with prepackaged AI agents that handle some of the most time-intensive security tasks. These include intelligence ingestion and enrichment, threat summarization and reporting, attack scenario generation and validation and remediation guidance. The agents interact to form a continuous loop, letting teams identify priority threats, test their exploitability and validate defenses from one interface. Filigran said that early platform benchmarks show organizations using XTM achieving up to 70% faster threat detection and response cycles and up to 80% less preparation time for offensive security testing. Customers can build and deploy their own agents, workflows and integrations on top of XTM One. The platform's Bring Your Own LLM support means they can run Filigran's models or plug in their own and it can be deployed on-premises. Filigran is pitching that last point at regulated industries and government agencies that cannot send sensitive data off their own systems. "The biggest barrier to threat intelligence adoption has always been complexity," Jean-Philippe Salles, vice president of product management at Filigran, said in the announcement. The natural-language interface lets junior analysts become productive faster while removing repetitive work for experienced practitioners, he added. XTM One will be available in three tiers. Existing Enterprise Edition customers of OpenCTI or OpenAEV receive a built-in set of prepackaged agents, a usage quota and BYOLLM support at no additional cost, while organizations needing custom agent creation, workflow orchestration and premium model packages can license XTM One separately. A free, open-source Model Context Protocol server is also available for integrating Filigran products into other AI architectures regardless of tier. The product will be generally available this month. Founded in 2022, Filigran raised $58 million in a Series C round in October backed by Eurazeo SE, Insight Partners LP, Accel Partners LP and Deutsche Telekom AG's T.Capital. Image: siliconangle/ideogram. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.