Principal Product Manager, Exposure Management

Posted 6 Hours Ago
Be an Early Applicant
5 Locations
Hybrid
160K-250K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Define your future at CrowdStrike.
The Role
Own the strategy and roadmap for integrating third-party security controls into CrowdStrike’s Exposure Management platform. Lead connector ecosystems, exploitability scoring, and asset-level risk modeling using vulnerability data, cloud context, control signals, and adversary tactics. Partner with engineering, data science, threat intelligence, customers, and sales teams; define platform metrics; represent the product externally; and mentor product managers. The role requires deep offensive security, vulnerability management, cloud security, API integration, and cross-functional product strategy expertise.
Summary Generated by Built In

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.


About the Role:

Principal Product Manager, Exposure Management

CrowdStrike's Exposure Management portfolio is redefining how organizations understand and reduce real-world risk. We are seeking a seasoned Principal Product Manager to lead a critical, differentiating capability within this portfolio: understanding how an organization's existing security controls reduce the exploitability of a given exposure.


In this role, you will define and own the strategy for integrating third-party compensating controls into CrowdStrike's exposure and risk data model to drive best-in-class exploitability analysis. You will build the connector ecosystem, partnerships, and data model that let CrowdStrike answer not just "is this vulnerable?" but "can this actually be exploited, given everything else protecting this asset?"


You will partner closely with engineering, data science, threat intelligence, and peer product managers across Exposure Management and the broader Proactive Security organization. Candidates with an offensive security background — penetration testing, red teaming, adversary simulation, or exploit development — are particularly well suited to this role, given the deep understanding required of how compensating controls hold up (or fail) against real attacker techniques.


What You'll Do:

  • Define and own the long-term strategy and roadmap for compensating-controls integration and exploitability analysis within the Exposure Management portfolio
  • Lead the 3rd-party connector framework that ingests signal from EDR/EPP, firewalls, network security, IAM/PAM, patch management, and other security controls to build a comprehensive, asset-level view of compensating controls
  • Partner with data science and threat intelligence teams to build exploitability scoring that combines vulnerability data, asset and business context, compensating controls, and adversary TTPs (e.g., MITRE ATT&CK)
  • Engage directly with enterprise customers, sales engineers, and support to validate connector priorities and pressure-test exploitability logic against real-world environments and adversary behavior
  • Define and track platform health metrics — connector coverage, control-signal freshness and accuracy, exploitability model precision/recall, and customer adoption
  • Represent the product externally through analyst briefings, customer advisory boards, and industry conferences on exposure management and offensive security
  • Mentor and provide strategic guidance to other product managers across the Exposure Management team

What You'll Need:

  • 8+ years of product management experience (or equivalent experience in offensive security, red teaming, penetration testing, vulnerability management, or exposure management)
  • Deep, hands-on understanding of offensive security concepts, exploitation techniques, attack paths, and adversary tradecraft
  • Strong domain expertise in vulnerability management (Note: trailing comma in original — please confirm if additional text is needed here)
  • Experience integrating with or building products atop third-party security tools (EDR, firewall, IAM, SIEM, patch management) via APIs
  • Strong domain experience with cloud technologies (AWS, Azure, GCP) and cloud security concepts
  • BS degree in an applicable field; Master's preferred
  • Track record of leading platform or product strategy in ambiguous, cross-functional environments, building consensus and buy-in from technical and business stakeholders
  • Demonstrated ability to navigate complex organizational structures and influence without direct authority across multiple product and engineering teams
  • Excellent verbal and written communication skills, with the ability to translate complex offensive-security and platform concepts for executive, technical, and go-to-market audiences
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
  • Ability to work 1–3 days per week from one of our office locations

Bonus Points:

  • Direct practitioner experience as a penetration tester, red teamer, or offensive security researcher
  • Experience with attack path analysis, breach and attack simulation (BAS) tools, or graph-based attack surface modeling
  • Familiarity with CAASM concepts and cyber asset data models, and the challenges of consolidating asset data from heterogeneous sources

#LI-AP1


Benefits of Working at CrowdStrike:

  • Market leader in compensation and equity awards

  • Comprehensive physical and mental wellness programs 

  • Competitive vacation and holidays for recharge  

  • Paid parental and adoption leaves

  • Professional development opportunities for all employees regardless of level or role

  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections

  • Vibrant office culture with world class amenities

  • Great Place to Work Certified™ across the globe

CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program.

CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements.

If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at [email protected] for further assistance.

Find out more about your rights as an applicant.

CrowdStrike participates in the E-Verify program.

Notice of E-Verify Participation

Right to Work

CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $160,000 - $250,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.

For detailed information about the U.S. benefits package, please click here. 

Skills Required

  • 8+ years of product management experience, or equivalent experience in offensive security, red teaming, penetration testing, vulnerability management, or exposure management
  • Deep hands-on understanding of offensive security concepts, exploitation techniques, attack paths, and adversary tradecraft
  • Strong domain expertise in vulnerability management
  • Experience integrating with or building products atop third-party security tools through APIs
  • Experience with EDR, firewall, IAM, SIEM, and patch management tools
  • Strong experience with AWS, Azure, GCP, and cloud security concepts
  • Bachelor’s degree in an applicable field
  • Master’s degree
  • Track record leading platform or product strategy in ambiguous, cross-functional environments
  • Ability to build consensus and buy-in among technical and business stakeholders
  • Ability to influence across multiple product and engineering teams without direct authority
  • Excellent verbal and written communication skills
  • Ability to translate complex offensive-security and platform concepts for executive, technical, and go-to-market audiences
  • Experience using AI technologies to enhance decision-making, streamline workflows, improve efficiency, and drive business outcomes
  • Ability to work 1–3 days per week from a CrowdStrike office location
  • Practitioner experience as a penetration tester, red teamer, or offensive security researcher
  • Experience with attack path analysis, breach and attack simulation tools, or graph-based attack surface modeling
  • Familiarity with CAASM concepts and cyber asset data models

What the Team is Saying

Andrew C.
Lauren P.
Brian P.
Alexa Z.
Theo K.
Sara I.
Lam N.
Lauren B.
Adeeb C.
Kristan C.
Alena C.
Thaddeus M.
Alyssa J.
KT T.

CrowdStrike Compensation & Benefits Highlights

  • Healthcare Strength — Feedback suggests health coverage is comprehensive with multiple plan options (HSA and PPO) and is generally regarded as good. Dental and vision are also included and described positively.
  • Leave & Time Off Breadth — Feedback suggests time off is flexible or unlimited, with generous PTO and paid holidays highlighted. Actual usage is noted as depending on team or manager.
  • Equity Value & Accessibility — Equity awards and an ESPP with a discount and lookback are described as meaningful components of pay. These elements are often cited as strengthening total compensation.

CrowdStrike Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
11,000 Employees
Year Founded: 2011

What We Do

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Why Work With Us

We have a culture that celebrates achievement, encourages flexibility and innovation and thrives on teamwork. We all work towards a single mission: to stop breaches. This common goal drives a sense of community and connection among our people across the globe.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

CrowdStrike Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
HQAustin, TX
Osaka
Aarhus, DK
Arlington, VA
Barcelona, ES
Bengaluru, IN
Brussels, BE
Bucharest, RO
Cheltenham, GB
Copenhagen, DK
Dubai, Dubai
Irvine, CA
Kirkland, WA
Minneapolis, MN
Mumbai, IN
New Delhi, IN
Pune, IN
Reading, GB
Riyadh, SA
Saint Louis, MO
Singapore
Sunnyvale, CA
Sydney, Sydney
Tel Aviv-Yafo, IL
Tokyo, Japan
Learn more

Similar Jobs

CrowdStrike Logo CrowdStrike

Engineer III, AI SDLC Engineer (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

CrowdStrike Logo CrowdStrike

Director, Engineering - Cloud Detection Platform (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
195K-290K Annually

CrowdStrike Logo CrowdStrike

Consultant

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
95K-140K Annually

CrowdStrike Logo CrowdStrike

Engagement Lead, Incident Response Partner Services (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
115K-160K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account