Sr. Product Manager - Identity Protection (NYC, Hybrid)
CrowdStrike
- Location
- USA - New York, NY
- Work model
- Hybrid
- Level
- Senior
- H-1B history
- 35 approvals (FY2023)
- Posted
- 8h ago
Skills
About this role
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you.
About the Role
Identity is the target. Adversaries don't need to break through a firewall when they can log in as someone who already has access, and identity-based attacks are now the most common way breaches happen. The less exposed an identity is, the harder and more expensive an attack becomes. This role owns the part of CrowdStrike's Identity Protection product that reduces that exposure and shrinks the blast radius when an identity is compromised: understanding an identity's full digital footprint and the assets and other identities it connects to, finding where risk concentrates, prioritizing what matters most, and turning that into action. It's an area with significant scope for a Sr. Product Manager to define the approach rather than execute an existing one. This is a hybrid position requiring at least 2 days a week in the office at our NYC office location.
What You'll Do
Own how Identity Protection finds and prioritizes identity risk : define the strategy for detecting risk across every identity type (human, service account, AI agent) and turning raw findings into a ranked, actionable view of what matters most. Own the strategy for closing the loop from finding to fix : decide where automation is appropriate, where a human needs to stay in the loop, and how the product proves a fix actually worked. Define how identities relate to each other and to the resources they touch : your work depends on a clear model of how accounts, groups, devices, workloads, and AI agents connect, and how those connections reveal risk that isolated findings miss. Drive identity risk as shared context across the security stack : every detection, alert, and access decision is better when it's informed by what you know about the identity behind it. You'll work with engineering teams to make that context available wherever decisions are being made. Use AI agents as a core part of how you work : research, analysis, spec iteration, and customer synthesis should run through agentic tooling as a default, not an occasional experiment.
What You'll Need
Identity and IAM Depth Hands-on background in IAM, identity governance, privileged access, or a closely adjacent technical domain. "Adjacent" means you've worked with the plumbing, not just named the category. Real understanding of how identity relationships work: account inheritance, entitlement propagation, transitive privilege paths, cross-tenant trust. You can explain why a human's effective permissions differ from their assigned permissions and why that gap matters. Familiarity with non-human identity: service accounts, workload identity, machine credentials, SPIFFE/SPIRE or equivalent standards. You know why