About Nagomi
Security teams are not short on tools. They are short on time, alignment, and the ability to actually close exposure. That's why most breaches could have been prevented with a tool that was already in use.
Nagomi was built to change that.
We are the first Agentic Exposure Ops Platform, designed to prevent the preventable breach by turning fragmented signals into coordinated action. Our agents investigate risk, drive remediation, and verify that issues stay closed, continuously, without adding overhead.
Nagomi is helping organizations move from reactive workflows to continuous execution, replacing manual effort with systems that actually move the work forward.
The Opportunity
As a Senior Security Researcher, you will bridge our core research initiatives at the intersection of proactive exposure management, agentic workflows, and scalable threat modeling. We are looking for an innovator who translates complex security data into product-driven features, taking full ownership from concept to production.
What You'll Do
- Drive Product-Led Research: Translate complex, real-world security challenges into actionable, product-driven research. Take full ownership of research projects end-to-end, from identifying the security gap to collaborating with engineering to ship platform features.
- Drive Proactive Exposure Management: Leverage Automated Security Control Assessments (ASCA) alongside vulnerability evaluation and prioritization to holistically assess organizational risk. Deep dive into enterprise security tools (EDR, SIEM, Firewalls, IAM, etc.) to analyze configurations, map defensive capabilities, and continuously evaluate their effectiveness against real-world threats.
- Build Security Tool Integrations: Drive the technical research and define the data models required to actually build deep, functional integrations into diverse security platforms, ensuring the accurate extraction of telemetry, policies, and configuration data.
- Build AI & Agentic Workflows: Define, design, and implement the logic and knowledge base that feeds Nagomi's AI-powered agents, ensuring they deliver accurate, context-aware security guidance and automated risk assessments.
- Map Attack Paths: Define realistic attack flows, identify toxic combinations of misconfigurations, and surface the security gaps that help customers prioritize the risks that actually matter.
- Engage with Customers: Work directly with customers to help them understand their exposure, translate your research findings into meaningful posture improvements, and gather feedback to drive product innovation.
- Cross-Functional Collaboration: Partner closely with product, engineering, and data teams to embed security insights into everything we build.
- Experience: 5+ years of hands-on experience in cybersecurity research, exposure management, vulnerability analysis, or threat intelligence.
- Product Mindset: Strong ability to tackle projects end-to-end, translating theoretical security research into tangible product features and automated detection logic.
- Broad Security Knowledge: Deep understanding of enterprise security tools (EDR, NDR, SIEM, VM, etc.), network topology, and how security components interact to impact network posture.
- AI/Agentic Expertise: Proven experience building or heavily shaping AI-powered systems and agentic workflows. You must be able to point to concrete examples where you have integrated LLMs or AI processes to solve complex technical problems.
- Attacker's Perspective: Solid foundation in how adversaries think, move laterally, and exploit enterprise environments, paired with expertise in leading vulnerability prioritization standards (MITRE ATT&CK, CISA KEV, EPSS).
- Communication: Strong communication skills with demonstrated experience working directly with customers, stakeholders, and cross-functional engineering teams.
- Experience collaborating with data science, data engineering, or analytics teams to structure security datasets and build scalable intelligence pipelines.
- Published research, CVEs, conference talks, or open-source contributions.
Skills Required
- 5+ years hands-on experience in cybersecurity research, exposure management, vulnerability analysis, or threat intelligence.
- Ability to translate security research into product features and own projects end-to-end (product mindset).
- Deep understanding of enterprise security tools and architectures (EDR, NDR, SIEM, VM, firewalls, IAM) and network topology.
- Proven experience building or shaping AI-powered systems and agentic workflows, with concrete examples integrating LLMs or AI processes.
- Strong attacker's perspective: lateral movement, exploit techniques, and expertise with vulnerability prioritization standards (MITRE ATT&CK, CISA KEV, EPSS).
- Strong communication and customer-facing experience working with stakeholders and cross-functional engineering teams.
- Experience collaborating with data science, data engineering, or analytics teams to structure security datasets and pipelines.
- Published research, CVEs, conference talks, or open-source security contributions.
What We Do
Nagomi automates the process of proving your security is actually working. Our platform unifies data across your assets, defenses, and threats to clearly illustrate your security program is both efficient and effective to key stakeholders. By maximizing existing investments, reducing threat exposure, and improving alignment, Nagomi is the only Proactive Defense Platform to turn cybersecurity from a technical cost center into a strategic business enabler.
Gallery







