B

Blackpoint Cyber

Proactive MDR cybersecurity for MSPs

Client Success Architect - Client Success Manager

Full-TimeUpdated on 9/30/2026
$99.1k - $123.9k/yr+ Equity participation
Junior
Bachelor's
Remote in USA
Remote

About the job

Requirements
  • A minimum of 2 years of work experience in a customer-facing and technical role.
  • Ability to demonstrate a high degree of technical proficiency with product suites and platforms.
  • Knowledge of Zendesk and HubSpot or similar software.
  • History of working successfully to drive customer value and engagement.
  • Willingness to be customer-facing and ability to navigate customer needs and challenges.
  • Experience working with clients in the security landscape.
  • Bachelor's degree or equivalent experience.
  • Proven ability to work independently and remotely.
Responsibilities
  • Enhance partner health by driving adoption of the Blackpoint Suite of products and services and penetration of endpoints.
  • Provide in-depth technical engagement and training to partners, educating them and helping them use the product suite in relation to their business.
  • Collaborate with Go-To-Market and Product team members to facilitate strategic engagements with partners and their clients, including direct engagement, preparation processes, and flowchart documentation to enhance partner experiences.
  • Provide onboarding and offboarding support through direct engagement with partners and their clients; assist in building strategic documentation and process flows to ensure faster and smoother onboarding experiences.
  • Continue education related to Blackpoint products, services, and integrated systems to stay current and provide the best support to partners.
  • Assist in crafting and preparing monthly partner reviews to assess value delivery and customer health, ensuring ongoing satisfaction and long-term partnership success.
  • Track activity analytically using KPIs on ChurnZero and measure progress month over month.
  • Follow documented processes and procedures for all events to continuously enhance the partner and client experience.

About the company

Blackpoint Cyber provides proactive cybersecurity protection through its proprietary MDR platform designed for MSPs and their clients. Its system continuously monitors networks and endpoints, visualizes activity, detects attacker tradecraft, and automatically responds to stop threats in their early stages. It stands out by combining real-time network visualization with tradecraft detection and by offering add-ons like Cloud Response and Managed Application Control tailored for MSPs. The goal is to deliver scalable, proactive defense against cyber threats through the MSP ecosystem.

Company Size

201-500

Company Stage

Series C

Total Funding

$203M

Headquarters

Denver, Colorado

Founded

2014

Get referred to Blackpoint Cyber

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • July 8, 2026 AI SOC Agent contained credential attacks in under two minutes.
  • September 10, 2026 ITDR adds historical scans, six Microsoft detections, and forensic reports.
  • June 2026 Erin Whitmore and July 2025 CyberFOX partnerships deepen intelligence and distribution.

What critics are saying

  • Microsoft 365 and Google Workspace can bundle identity security, crushing Blackpoint pricing power.
  • No visible funding since June 2023 limits acquisitions and sales expansion through 2026.
  • MSP channel concentration creates existential risk if top partners defect to larger platforms.

What makes Blackpoint Cyber unique

  • Former NSA operators built CompassOne around human-led, AI-accelerated 24/7 SOC response.
  • CompassOne unifies identity, endpoint, cloud, network, and SIEM for MSPs.
  • Blackpoint serves 1,800+ MSPs with threat telemetry across tens of millions daily events.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Discretionary Time Off

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 0%

2 year growth

↑ 1%
TechDay
Sep 23rd, 2026
Blackpoint adds identity threat tools to CompassOne.

Blackpoint adds identity threat tools to CompassOne. Wed, 23rd Sep 2026 (Today) Blackpoint Cyber has added identity threat detection and response features to its CompassOne platform, expanding its tools for Microsoft 365, Google Workspace and Cisco Duo environments. The update includes a historical scan for Microsoft 365, nine new detections, automated response controls and new incident reporting tools. The additions are intended to identify identity-based attacks earlier, contain threats with less disruption and improve post-incident records. Identity-based attacks are a growing concern for security teams as attackers increasingly rely on stolen credentials, compromised mailboxes and social engineering rather than malware alone. Email compromise and misuse of legitimate sign-in systems can make these intrusions harder to spot because they often resemble normal user activity. Among the new detections are six for Microsoft environments: Suspicious Sending Pattern, Anomalous Token, Attacker in the Middle, Possible PRT Access, Verified Threat Actor IP and Suspicious Browser Sign-In. Blackpoint has also added two detections for Microsoft Teams that look for helpdesk impersonation chats and tenant-name spoofing attempts. Another detection targets device code phishing, flagging sign-ins that use Microsoft's device code authentication flow when the pattern is consistent with phishing, even if the login otherwise appears legitimate. Response tools Blackpoint has also expanded its automated response options. Geo and VPN Policy Automation can block logins from unapproved countries or commercial VPNs as they occur, while allowing policy updates to be applied in bulk across managed tenants. For Google Workspace customers, a new Auto Logout option ends a compromised session and resets the account password while keeping the user's mailbox and calendar active. The aim is to avoid the access loss and disruption that can follow a full account shutdown. New visibility tools also track account and policy changes. User Disabled Notifications send real-time alerts when CompassOne disables an account across Microsoft 365, Google Workspace or Cisco Duo, including the affected user, the actor behind the action and the reason. ITDR Policy Change Visibility shows who last changed a geo or VPN policy and when. The information appears directly on the Cloud Response policies page, giving administrators an audit trail for configuration changes. Historical scan A notable part of the update is the Historical Scan Report for Microsoft 365 onboarding. The tool provides a retrospective view of up to 180 days of activity to help organisations assess whether an attacker may already have access to the environment. The report includes AI-driven analysis, MITRE ATT&CK mappings and remediation guidance ranked by priority. Blackpoint has also introduced a Forensic Report that generates a customer-ready PDF once a Microsoft 365 incident has been contained, including an attacker timeline, a blast-radius summary and exfiltration tracking. William Kapes, Director of Technical Operations at Integritek, described the operational burden some security tools can place on internal teams. "A compromised mailbox is not an inconvenience; it's a confidentiality problem with our clients' own clients attached to it. Much of what we saw when evaluating the competition was alerts dressed up as detection, which just moves the work back to us. Blackpoint's SOC investigates and acts, and every addition has been aimed at taking work off my team rather than handing them another dashboard to check," said Kapes. Blackpoint linked the expansion to a broader shift in the threat landscape, where identities have become a common entry point into corporate systems. Security providers have increasingly focused on account behaviour, sign-in anomalies and cloud service misuse as attacks move away from traditional endpoint compromise. Sasmita Panda, Vice President of Engineering at Blackpoint Cyber, said the company sees identity as a central area of risk. "Threats are becoming agentic, and identities are the new threat vector where attackers are entering the business," said Panda. "We aren't here to merely defend, we are here to protect, and that requires more than adding another detection rule-it requires the ability to continuously recognize new attack patterns, make sense of identity activity in context, and act immediately. Our expanded ITDR capabilities and newly launched ITDR AI SOC Agent are a powerful combination of machine-speed detection and containment with the expertise of our human AI-accelerated SOC. That allows us to respond to identity threats in an average of under 2 minutes and as fast as 21 seconds without losing the judgment, accountability and precision that effective incident response demands." Blackpoint focuses on small and mid-sized businesses and managed service provider partners, a segment that often has fewer in-house security resources than larger enterprises. In that context, automation, managed investigation and clearer reporting can carry particular weight for service providers overseeing multiple customer environments at once. The latest additions also reflect a broader push across the cybersecurity sector to produce more structured evidence after incidents, as customers and insurers seek clearer records of what happened, what data may have been exposed and what steps were taken in response. The Historical Scan Report covers up to 180 days of Microsoft 365 activity during tenant onboarding.

MSSP Alert
Sep 18th, 2026
Arctic Wolf launches new MDR offering for managed service providers.

Arctic Wolf launches new MDR offering for managed service providers. September 18, 2026 Arctic Wolf announced the launch of Aurora MDR Connect, a managed detection and response offering designed for managed service providers (MSPs). This new service aims to provide a streamlined version of Arctic Wolf's cybersecurity platform to partners, enabling them to deliver enterprise-grade security to a wider range of customers more quickly, as reported by Channeldive. Aurora MDR Connect builds upon Arctic Wolf's existing managed detection and response (MDR) services, specifically targeting MSPs that serve midmarket companies and those with fewer than 100 employees. The offering simplifies deployment by eliminating the need for network sensors, relying solely on endpoint agents to collect security data. This allows for faster implementation and reduced operational complexity, catering to businesses embracing remote and hybrid work models. Arctic Wolf's strategy involves treating MSPs as their direct customers, empowering them to integrate Arctic Wolf's technology with their own services. Analysts note that this move positions Arctic Wolf to compete with other MDR providers like Huntress and Blackpoint, though the company must carefully manage its partner tiers to avoid cannibalization. The company emphasizes its channel-first approach, with its MSP program being its fastest-growing business unit.

ARN
Aug 12th, 2026
MSP growth depends on execution, not more tools: Blackpoint's Andrew Pedroso.

MSP growth depends on execution, not more tools: Blackpoint's Andrew Pedroso. 12 Aug 2026 7 mins Calls for a return to community in the MSP channel. Managed service providers (MSP) should stop chasing every new tool and AI trend and focus on consolidating their stack, improving execution and sales discipline. This will help them to become trusted business advisers. Not because they can sell the most products, but because they combine technology with trust, empathy, and a genuine commitment to customer success, said Blackpoint Cyber Asia Pacific (APAC) regional director Andrew Pedroso. The ability to prove return on investment (ROI) to customers and boards was equally as important as developing trusted adviser relationships and supporting customer growth. At the same time, MSPs need to strengthen identity- and cloud-based security and deliver a genuinely local Australia and New Zealand (A/NZ) customer experience, Pedroso said during the panel discussion Security as a growth engine - Why partners need to maximise their security practice at EDGE 2026. "The attackers aren't breaking in, they're actually logging in. Being vigilant with that is a starting point," he said. "The other part is around consolidation - that tool sprawl is exhausting." For Pedroso, the challenge with tool sprawl is that MSPs accumulate multiple products that often overlap in functionality. This is why they need to carefully evaluate how they prioritise tool consolidation. They also need to focus on the investment in technology that will deliver growth, improve margins, and support effective execution. What Pedroso outlined on the panel aligned with what he told ARN in an interview ahead of EDGE 2026. "The first thing I noticed coming back into the channel and MSP-first space is that there are a lot of incumbents," he said. "There are a lot of existing and legacy relationships, and naturally, when the market shifts with AI, there's a genuine need to explore what's out there and what improvements other vendors or competitors have made across products and services." Pedroso is now eight months in his role at Blackpoint but has spent more than a decade in the industry, with experience at AI platform provider Enable and research firm Forrester. Since coming back, owners, CEOs, general managers, and directors frequently ask him what has changed in the industry. "My response is always the same - whenever there's a leading-edge technology shift, it's not about whether the current provider can do the job," Pedroso said. "It's about whether you're future proofing yourself as an MSP. "Someone else is adopting that technology; someone else is offering a new or premium service to market. You don't want to be left behind." That concern extends beyond adopting new technologies to reassessing long-standing vendor relationships. "Going back to those legacy relationships, I've seen vendors with 10, 12, or 15 years of renewals behind them," observed Pedroso. "They've been incumbents for over a decade." As such, Pedroso said the first question from an MSP owner or general manager should often be, 'Is this still meeting the needs of our customers?' followed by an evaluation on tool consolidation, the benefits of a single platform, the best provider for that MSP, and the potential of a newer solution that combines what multiple vendors currently provide. "I think people are experiencing tech fatigue, tool sprawl, and complexity," Pedroso said. "They're asking whether they have multiple solutions doing the same thing and whether they can simplify everything into one place. "Organisations are reassessing the core technology stack that delivers outcomes for customers and determining whether it can be consolidated. "That's not just a cyber security issue. It's technology-agnostic and applies across industries, segments, and categories." Securing growth. Understanding that will help MSPs to future-proof their tech stack in an AI world so they don't fall behind competitors who adopt new capabilities and premium services faster. "My one liner always is whenever there's a bleeding edge or leading-edge change of technology, it's not about whether your current provider can do the job," observed Pedroso. "Are you future proofing yourself as a as an MSP to ensure your tech stack matches what your customers want [and] what your competitors are doing?" However, future proofing is about more than adopting new technologies like AI. According to Pedroso, many MSPs have invested in tools and AI but have not done the people and process work required to execute effectively and translate those investments into growth. "You can choose all the best tech in the world, but if you don't tangibly know how that fits as part of an operating model, you're missing the process; you're missing the execution... you're actually not going to grow with it," he said. That means owners and teams need to be educated and upskilled first, and only once they're clear on how they want the business to run and grow - the operating model, sales motions, and service delivery - should they start choosing tools or AI solutions. Otherwise, he said, even the "best tech in the world" won't translate into real execution or growth. "The gap that I'm noticing here is that execution part. Everyone's so caught up in assessing their vendors, assessing their partnerships, but who's actually executing to try and grow their business?" Pedroso said the genuine problem he is trying to solve is how to help MSPs grow. He noted that one of the most common topics he is asked about is sales organisations. Many business leaders seeking advice on how to take a company from zero to $15 million or $20 million in revenue and how to get their sales teams working towards sustainable growth. "Transactional sales aren't there anymore. It stopped," Pedroso noted. "Everyone's so fixated on AI fixing the process [and] fixing the people. "Whereas it's actually the opposite...it should be the people first. "Whether it's a delivery team, sales team, marketing, whatever it is in your business - could be just you and another person [or] you as an individual - what do you need to get educated on? What do you need to be upskilled on? That's a fundamental human learning educational experience that you need to undergo as part of modernisation." For Pedroso, if MSPs don't tangibly understand how a technology fits within their operating model, they are "missing the process" and "missing the execution" that growth won't be achieved. Once the technology provider understands how they want to grow, how they want to operate, and how they want to modernise their way of working, offering, and positioning, the direction becomes clearer. They can then determine whether they want to be a premium service provider, an advisory-plus-technology business, or pursue another modernisation strategy. Although this shouldn't be done in isolation, noted Pedroso. "We don't give enough of that upskilling, reskilling, and support that an enterprise customer has at their disposal if not 1000s of resourcing to complete that," he said. "How do we package that as an MSP community to say, 'Here are some associations,' or 'Here are some bodies that can come together to uplift your own MSP capability.'" "The community piece is something I believe that we've just lost. We need to go back to how do we level up as a group?" That philosophy aligns closely with Blackpoint's MSP-first strategy. Pedroso personally emphasises education, knowledge sharing, local support, and long-term partnerships designed to help providers strengthen their capabilities and grow together. "Being MSP first, built for MSPs for MSPs, and obviously with that single pane of glass solution, the way we operate is heavy in the discovery," he said. This echoes his thoughts on the EDGE 2026 panel which was, "If you're not localising your efforts and making it a true A/NZ experience, good luck, because there are another three or four vendors doing that better than you now." Don't miss a thing From its editors straight to your inbox. Get started by entering your email address below. Community Editor

Yahoo Finance
Jul 8th, 2026
Blackpoint Cyber launches AI SOC agent to stop credential attacks in 21 seconds

Blackpoint Cyber has launched its AI SOC Agent for Identity Threat Detection and Response, an autonomous system that detects and contains credential-based attacks targeting Microsoft 365 and Google Workspace accounts. The system can respond to threats in as little as 21 seconds, with an average containment time of under two minutes. The AI agent was trained using years of SOC analyst decisions, forensic evidence from hundreds of breaches, and telemetry from nearly a million accounts. It operates under human oversight from Blackpoint's security operations centre. Microsoft reported a 32% increase in identity-based attacks during the first half of 2025, highlighting growing security challenges. The new capability is included with all Blackpoint ITDR service tiers at no additional cost. Blackpoint Cyber was founded by former NSA cybersecurity experts and provides managed detection and response services through its 24/7 SOC.

Citybiz
Jun 16th, 2026
Blackpoint Cyber appoints Erin Whitmore as Head of the Adversary Pursuit Group.

Blackpoint Cyber appoints Erin Whitmore as Head of the Adversary Pursuit Group. June 16, 2026 Erin Whitmore will lead Blackpoint's threat research, turning frontline detection data from thousands of environments into intelligence partners can act on. Erin Whitmore Blackpoint Cyber today announced the appointment of Erin Whitmore as Head of the Adversary Pursuit Group (APG), deepening its commitment to intelligence-led cybersecurity through continued investment in threat research, adversary intelligence, and cyber risk expertise. Whitmore brings more than 16 years of experience at the intersection of national security, intelligence, and cybersecurity. Prior to joining Blackpoint, she served as a CIA Operations Officer and held intelligence roles supporting the Defense Intelligence Agency, National Geospatial-Intelligence Agency, and the Office of the Director of National Intelligence. She later held executive leadership positions at Aon and CYPFER, where she advised organizations on cyber resilience and strategic risk. As Head of APG, Whitmore will lead Blackpoint's threat research and intelligence initiatives while serving as the company's voice on the evolving threat landscape. Working closely with Blackpoint's Response Operations Center (B-ROC), she will transform frontline operational insights into actionable intelligence, industry research, and executive guidance for partners and the broader cybersecurity community. Under Whitmore's leadership, APG will focus on transforming the real-time visibility generated through Blackpoint's MDR platform and Security Operations Center into forward-looking intelligence that helps organizations anticipate and disrupt emerging threats. Her vision is to bridge the gap between what Blackpoint observes across thousands of environments and what defenders need to know, delivering not only indicators and alerts, but the context, analysis, and strategic guidance required to make confident security decisions. Drawing on her intelligence community experience, Whitmore aims to further establish APG as a trusted authority on adversary behavior, cyber risk, and the evolving tactics shaping the future of cybersecurity. "The adversaries targeting organizations today are sophisticated, well-resourced, and constantly adapting, and the intelligence used to stop them has to be just as dynamic," said Whitmore. "What drew me to Blackpoint is that the APG and B-ROC are built around real-world, human-led operations, not theoretical frameworks. That's a rare foundation, and I'm excited to help push it further." "Erin brings a unique combination of intelligence expertise, operational leadership, and industry credibility," said Gagan Singh, CEO of Blackpoint Cyber. "She has spent her career helping organizations understand complex threats and navigate uncertainty. As Head of APG, she will ensure our partners have the intelligence and clarity they need to stay ahead of every threat." Whitmore is a recognized voice in cybersecurity and national security, frequently speaking at industry conferences, executive forums, and leadership events. Her work spans cyber resilience, nation-state threats, ransomware, artificial intelligence, cyber risk governance, and the growing convergence of cybersecurity and geopolitics. Under Whitmore's leadership, APG will play an increasingly central role in expanding Blackpoint's research, intelligence, and educational initiatives while helping the broader cybersecurity community anticipate emerging risks and make more informed decisions. About Blackpoint Cyber Blackpoint Cyber was founded by former NSA cybersecurity experts with one purpose: to win the unfair fight. Blackpoint delivers Managed Detection and Response (MDR) through a 24/7 SOC that combines detection at AI speed with elite human expertise, giving organizations real defense against sophisticated threat actors. Its CompassOne platform unifies identity, endpoint, and cloud into a single context-rich environment, enabling decisive response before attacks escalate. We measure security by threats stopped, not alerts generated.