Bugcrowd is an innovative company focused on security solutions by leveraging data and AI technologies. They are seeking a Staff Product Manager, AI & Data to define the vision and strategy for their data and intelligence platform, ensuring that the highest-risk issues are prioritized and actionable for customers.
Responsibilities:
- AI & Data Strategy & Vision: Own the vision, strategy, and roadmap for Bugcrowd’s AI & Data pillar. Define how validation, aggregation, prioritization, and recommendations fit together into one trusted data platform
- Validation as a Service: Design and scale an automated triage and deduplication capability. It validates test results across all test types (vulnerability scanning, penetration testing, MBB/VDP) before they enter the data platform. Only clean, trustworthy signal reaches downstream products
- Aggregation & Correlation: Build the data models and pipelines that aggregate and correlate validated findings across test types and sources. The result is a single, unified view of a customer’s risk posture
- Prioritization & Diagnosis: Develop the logic that diagnoses what matters most. Look within a customer across test results, across customers, and against third-party and internal threat feeds. The highest-impact issues should always surface first
- Recommendation Engine: Partner with engineering to turn a diagnosis into action. Surface a suggested code fix. Confirm whether the customer’s logging can even detect the issue. Deliver a ready-to-use detection rule (e.g., Splunk) and a threat hunting query to check for past abuse
- Cross-Functional Intelligence: Work closely with our Agentic Products PM team. Feed new attack vectors and data sources back into agent training. Help our agents learn to 'look for the new thing.'
- Platform Trust & Scalability: Define and own the metrics that prove the platform works: validation accuracy, deduplication rate, time-to-diagnosis. These metrics make the AI & Data pillar the trusted foundation every other product is built on
Requirements:
- 7+ years of Product Management experience. Ideally this spans both security/vulnerability and threat data domains and ML/data platform and pipeline domains. That's a rare blend, but it's the ideal for this role
- Data-Minded Systems Thinker: You're comfortable with data models, pipelines, and deduplication/correlation logic. You can translate messy, multi-source data into a structured, trustworthy output
- Security Domain Fluency: You understand how different test types (vulnerability scanning, penetration testing, bug bounty/VDP) generate findings. You know what it takes to triage, validate, and prioritize them correctly
- Strategic Leader: You've been a contributor at the executive team level with the ability to build trust at every level and rally teams toward a long-term data strategy
- Tactical Execution: You balance the ambition of “one platform, one source of truth” with the pragmatic need to ship trustworthy improvements today
- Detection Engineering Familiarity: Exposure to writing or reviewing SIEM/Splunk-style detection rules and threat hunting queries
- ML/AI for Data Correlation: Experience building or product-managing systems that use ML for entity resolution, deduplication, anomaly detection, or risk scoring
- Security Testing Landscape: Familiarity with vulnerability scanning, penetration testing, and bug bounty/VDP program mechanics
- The “Builder” Edge: You are an active user of AI-native tools (Claude Code, Cursor, etc.) and likely have “robots” of your own running in your personal workflows