About the Role:Principal Product Manager, Exposure ManagementCrowdStrike's Exposure Management portfolio is redefining how organizations understand and reduce real-world risk. We are seeking a seasoned Principal Product Manager to lead a critical, differentiating capability within this portfolio: understanding how an organization's existing security controls reduce the exploitability of a given exposure.
In this role, you will define and own the strategy for integrating third-party compensating controls into CrowdStrike's exposure and risk data model to drive best-in-class exploitability analysis. You will build the connector ecosystem, partnerships, and data model that let CrowdStrike answer not just "is this vulnerable?" but "can this actually be exploited, given everything else protecting this asset?"
You will partner closely with engineering, data science, threat intelligence, and peer product managers across Exposure Management and the broader Proactive Security organization. Candidates with an offensive security background - penetration testing, red teaming, adversary simulation, or exploit development - are particularly well suited to this role, given the deep understanding required of how compensating controls hold up (or fail) against real attacker techniques.
What You'll Do:- Define and own the long-term strategy and roadmap for compensating-controls integration and exploitability analysis within the Exposure Management portfolio
- Lead the 3rd-party connector framework that ingests signal from EDR/EPP, firewalls, network security, IAM/PAM, patch management, and other security controls to build a comprehensive, asset-level view of compensating controls
- Partner with data science and threat intelligence teams to build exploitability scoring that combines vulnerability data, asset and business context, compensating controls, and adversary TTPs (e.g., MITRE ATT&CK)
- Engage directly with enterprise customers, sales engineers, and support to validate connector priorities and pressure-test exploitability logic against real-world environments and adversary behavior
- Define and track platform health metrics - connector coverage, control-signal freshness and accuracy, exploitability model precision/recall, and customer adoption
- Represent the product externally through analyst briefings, customer advisory boards, and industry conferences on exposure management and offensive security
- Mentor and provide strategic guidance to other product managers across the Exposure Management team
What You'll Need:- 8+ years of product management experience (or equivalent experience in offensive security, red teaming, penetration testing, vulnerability management, or exposure management)
- Deep, hands-on understanding of offensive security concepts, exploitation techniques, attack paths, and adversary tradecraft
- Strong domain expertise in vulnerability management (Note: trailing comma in original - please confirm if additional text is needed here)
- Experience integrating with or building products atop third-party security tools (EDR, firewall, IAM, SIEM, patch management) via APIs
- Strong domain experience with cloud technologies (AWS, Azure, GCP) and cloud security concepts
- BS degree in an applicable field; Master's preferred
- Track record of leading platform or product strategy in ambiguous, cross-functional environments, building consensus and buy-in from technical and business stakeholders
- Demonstrated ability to navigate complex organizational structures and influence without direct authority across multiple product and engineering teams
- Excellent verbal and written communication skills, with the ability to translate complex offensive-security and platform concepts for executive, technical, and go-to-market audiences
- Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
- Ability to work 1-3 days per week from one of our office locations
Bonus Points:- Direct practitioner experience as a penetration tester, red teamer, or offensive security researcher
- Experience with attack path analysis, breach and attack simulation (BAS) tools, or graph-based attack surface modeling
- Familiarity with CAASM concepts and cyber asset data models, and the challenges of consolidating asset data from heterogeneous sources
#LI-AP1
Benefits of Working at CrowdStrike:- Market leader in compensation and equity awards
- Comprehensive physical and mental wellness programs
- Competitive vacation and holidays for recharge
- Paid parental and adoption leaves
- Professional development opportunities for all employees regardless of level or role
- Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
- Vibrant office culture with world class amenities
- Great Place to Work Certified™ across the globe
CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $160,000 - $250,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.
For detailed information about the U.S. benefits package, please click here.