About the Team
The AI-SOC product team sits within Rapid7's Detection & Response organization and builds the autonomous investigation platform powering our MDR service. Operating at the intersection of managed security operations and agentic AI, the team develops capabilities that triage alerts at machine speed so analysts can focus on high-value decisions.
About the Role
As a Lead Product Manager, AI-SOC, your primary responsibility will be to own the content layer that determines what the autonomous agent investigates, how it investigates, and what it concludes. Specifically, your focus will be to:
- Define and maintain the full library of investigation playbooks and queries executed across alert types, data sources, and severities, owning the continuous improvement backlog.
- Establish telemetry and schema requirements for onboarding new log sources and alert integrations in direct partnership with engineering and data teams.
- Own the status disposition logic and suppression framework, guiding the evolution from rule-based heuristics to an advanced ML-driven disposition engine.
- Incorporate threat intelligence, including IOC matching, actor context, and TTP enrichment, into autonomous investigation workflows.
- Establish and track core quality metrics, including coverage rate, disposition accuracy, and false positive rates, leveraging feedback loops from MDR analysts.
- Partner with MDR operations to ensure autonomous investigation output consistently meets the quality bar required to replace manual Tier 1-2 triage at scale.
The skills and qualities you'll bring include:
- Bring 7+ years of experience in security operations, alert triage, detection engineering, or security engineering within an MDR, MSSP, or enterprise SOC environment.
- Demonstrate deep working knowledge of Detection & Response across multiple technical domains, including endpoint, network, identity, cloud, or SaaS/email.
- Apply direct experience with major EDR/XDR platforms to write queries, review telemetry, and render defensible disposition decisions.
- Leverage strong proficiency in investigation methodology and the MITRE ATT&CK framework to map alert types to adversary behaviors.
- Demonstrate 2+ years in product management or equivalent SOC leadership where domain expertise was translated into clear engineering requirements.
- Drive efficient decision-making that resolves complex product challenges and enables operational momentum across diverse stakeholder groups.
- Establish clear ownership and accountability for delivery outcomes, quality metrics, and operational commitments.
- Build global cross-functional networks across engineering, data science, and security operations to drive sustainable platform enhancements.
- Act as an active driver of change when transitioning legacy operations toward AI-driven autonomous workflows.
- Bring strong written and verbal communication skills to align cross-functional partners and executive stakeholders around vision and execution.
- Possess US Citizenship with active or prior security clearance experience in federal or government environments.
- Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1 #LI-Remote
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate's salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.
The annual salary range for this role, depending on location, is:
United States: $156,200.00 - 211,400.00 USD Annual
Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity and benefits (where applicable/eligible).
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
Skills Required
- 7+ years in security operations, alert triage, detection engineering, or security engineering within an MDR, MSSP, or enterprise SOC
- Deep working knowledge of Detection & Response across endpoint, network, identity, cloud, or SaaS/email
- Direct experience with major EDR/XDR platforms to write queries, review telemetry, and render defensible disposition decisions
- Strong proficiency in investigation methodology and the MITRE ATT&CK framework
- 2+ years in product management or equivalent SOC leadership translating domain expertise into engineering requirements
- Ability to establish telemetry and schema requirements for onboarding new log sources and alert integrations
- Experience incorporating threat intelligence (IOC matching, actor context, TTP enrichment) into investigation workflows
- Proven ability to define and track core quality metrics (coverage, disposition accuracy, false positive rates) and drive continuous improvement
- US Citizenship with active or prior security clearance experience in federal or government environments
- Strong written and verbal communication skills and ability to align cross-functional and executive stakeholders
Rapid7 Compensation & Benefits Highlights
-
Leave & Time Off Breadth — Unlimited PTO in the U.S., 12 holidays, and five global company days off are prominently offered, with company materials also highlighting competitive paid parental leave. These elements position time away as a notable strength when team norms support usage.
-
Healthcare Strength — Comprehensive medical, dental, and vision coverage is emphasized, alongside mental-health resources and, in some offices, onsite or discounted fitness options. Access to financial advisers and wellness programs further reinforces health and wellbeing support.
-
Equity Value & Accessibility — Equity/RSUs and an ESPP are widely presented as meaningful parts of total rewards, with stock often viewed positively. Performance bonuses and defined commission tiers add to overall compensation for applicable roles.
Rapid7 Insights
What We Do
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.
Why Work With Us
With our products, research, and open source communities, we’re building a secure digital future for everyone. This means constantly learning and evolving in an industry that’s anything but stagnant. You’ll be faced with tough challenges, and given the support to find creative solutions that drive our business, and your career forward.
Gallery
Rapid7 Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Our default working model is hybrid, with employees working three days per week in the office. This approach underpins our commitment to flexibility and adaptability while supporting our dedication to development, teamwork and customer purpose.

.jpg)



















.jpg)
























