← Back to jobs

Lead Product Manager, AI-SOC

Company
Rapid7
Location
Remote
Work type
Full Time
Posted
2026-08-07

Job description

About the Role
As a Lead Product Manager, AI-SOC, your primary responsibility will be to own the content layer that determines what the autonomous agent investigates, how it investigates, and what it concludes. Specifically, your focus will be to:
Define and maintain the full library of investigation playbooks and queries executed across alert types, data sources, and severities, owning the continuous improvement backlog.
Establish telemetry and schema requirements for onboarding new log sources and alert integrations in direct partnership with engineering and data teams.
Own the status disposition logic and suppression framework, guiding the evolution from rule-based heuristics to an advanced ML-driven disposition engine.
Incorporate threat intelligence, including IOC matching, actor context, and TTP enrichment, into autonomous investigation workflows.
Establish and track core quality metrics, including coverage rate, disposition accuracy, and false positive rates, leveraging feedback loops from MDR analysts.
Partner with MDR operations to ensure autonomous investigation output consistently meets the quality bar required to replace manual Tier 1-2 triage at scale.

The skills and qualities you'll bring include:
Bring 7+ years of experience in security operations, alert triage, detection engineering, or security engineering within an MDR, MSSP, or enterprise SOC environment.
Demonstrate deep working knowledge of Detection & Response across multiple technical domains, including endpoint, network, identity, cloud, or SaaS/email.
Apply direct experience with major EDR/XDR platforms to write queries, review telemetry, and render defensible disposition decisions.
Leverage strong proficiency in investigation methodology and the MITRE ATT&CK framework to map alert types to adversary behaviors.
Demonstrate 2+ years in product management or equivalent SOC leadership where domain expertise was translated into clear engineering requirements.
Drive efficient decision-making that resolves complex product challenges and enables operational momentum across diverse stakeholder groups.
Establish clear ownership and accountability for delivery outcomes, quality metrics, and operational commitments.
Build global cross-functional networks across engineering, data science, and security operations to drive sustainable platform enhancements.
Act as an active driver of change when transitioning legacy operations toward AI-driven autonomous workflows.
Bring strong written and verbal communication skills to align cross-functional partners and executive stakeholders around vision and execution.
Possess US Citizenship with active or prior security clearance experience in federal or government environments.
Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

Skills Required
7+ years in security operations, alert triage, detection engineering, or security engineering within an MDR, MSSP, or enterprise SOC
Deep working knowledge of Detection & Response across endpoint, network, identity, cloud, or SaaS/email
Direct experience with major EDR/XDR platforms to write queries, review telemetry, and render defensible disposition decisions
Strong proficiency in investigation methodology and the MITRE ATT&CK framework
2+ years in product management or equivalent SOC leadership translating domain expertise into engineering requirements
Ability to establish telemetry and schema requirements for onboarding new log sources and alert integrations
Experience incorporating threat intelligence (IOC matching, actor context, TTP enrichment) into investigation workflows
Proven ability to define and track core quality metrics (coverage, disposition accuracy, false positive rates) and drive continuous improvement
US Citizenship with active or prior security clearance experience in federal or government environments
Strong written and verbal communication skills and ability to align cross-functional and executive stakeholders

Original source