We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Vellox Product Manager, Cyber Environment Detections

Booz Allen Hamilton
tuition assistance
United States, Virginia, McLean
Aug 24, 2026
Job Number: R0247722

Senior Vellox Product Manager, Cyber Environment Detections

The Opportunity:

The Product team is defining a new product-led growth business within Booz Allen where you will have the opportunity to design, build, and deliver products to mission and commercial customers at scale.You will experience the energy of a start-up, with the resources, mentorship, and stability of an established tech company - being able to look across industry & capability areas to craft new outcomes leveraging the deep catalog of existing technology and customer solutions. This team is looking to consistently push the boundaries of what is possible, shaping a future where product investments combined with Booz Allen existing services businesses can supercharge customers.

If you are wanting to build and deliver a product which can outsmart human adversaries while managing massive scales of data - the intersection of where software engineering is meeting digital forensics; Booz Allen is seeking a Product Manager to define and build this next generation products. As a Product Manager focused on the next generation of detection and remediation engineering, you will need to blend your knowledge of how threats manifest themselves with your passion for eliminating the SIEM & SOAR "noise" and alert fatigue burying analysts today. This role will be able to leverage the decades of experience which Booz Allen has in delivering differentiated and successful deep security outcomes for customers, but to contribute to shaping its future.

One challenge will be to fuse deep domain knowledge around threat modeling & adversarial techniques to develop automated and agentic patterns which unfold the "story" of an attack or vulnerability and then craft a detection rule to prevent it in the future. This PM will work across the end-to-end product lifecycle, from identifying high-impact AI use cases, such as like new patterns to detect living-of-the-land (LOTL) attacks, and defining the technical roadmap, to collaborating with engineering and data science teams to build trustworthy, auditable features, and finally, partnering with go-to-market teams to ensure the product successfully meets the complex security and audit requirements of our most regulated customers. These capabilities will underpin solutions and products across our product portfolio, including Cybersecurity, Defense, Autonomy, AI, Data, and more.

Why environment knowledge matters:To deliver trustworthy detections and reduce false positives at scale, this role will build capabilities that make customer environments firstclass inputs to Ranger systematically capturing asset inventories, topology, control stacks, and telemetry sources. By codifying these signals into environment models and baselines, we'll tune rule generation to each client's reality, including cloud, on prem, and hybrid, improve analyst outcomes, and accelerate time to value across regulated and mission contexts.

WhatYou'll Do:

  • Own the endtoend vision, strategy, and roadmap for an AIdriven detection engineering platform that surpasses humancentric models.

  • Create a repeatable discovery process to model environments, including assets, topology, identity, and logs, and generate contextaware, ranked detection rules with KPIs like readiness time, FP reduction, and coverage uplift.

  • Apply deep knowledge of frameworks like MITRE ATT&CK to design detections aligned to real adversary behaviors across movement, exfiltration, and persistence.

  • Identify highvalue opportunities for AI automation, enabling autonomous detection creation, triage, and response actions that help users resolve threats, not just notice them.

  • Design analystfocused interfaces that elevate critical threats while suppressing nonactionable SIEM/SOARstyle noise.

  • Build DaC workflows using Gitbased version control, CI/CD testing, and automated deployment across massive, normalized event pipelines.

  • Integrate strategic data sources, including endpoint trees and behavioral telemetry, to enrich environment models and scale tuning from small regions to global deployments.

  • Conduct ongoing competitive and market research to identify gaps, auditor expectations, and defensible product advantages in the evolving detection landscape.

  • Translate complex threatbehavior stories into prioritized product requirements, user stories, and acceptance criteria that drive engineering and design execution.

  • Partner across engineering, AI/DS, UX, legal and compliance, and GTM teams to align technical architecture, data governance, ingestion, labeling, and modeltraining strategy with customer needs.

You Have:

  • 5+ years of experience in technology product management

  • Experience analyzing and solving problems

  • Ability to manage the entire product lifecycle, from ideation to launch and beyond

  • Ability to thrive in fast-moving startup environments and effectively lead change

  • Ability to travel up to 20% of the time

  • Bachelor's degree inComputer Science,Engineering,InformationSystems,DataScience,AppliedMathematics, or Business

Nice If You Have:

  • Experience with SaaS platforms and products involving multi-tenancy, subscriptions, billing, and compliance requirements

  • Experience with detection engineering, including authoring and tuning detections across SIEM and EDR platforms, and detection-as-code or CI/CD workflows

  • Experience modeling customer environments, including cloud, on prem, and hybrid, including asset discovery, controlstack mapping, including EDR, SIEM, or IDP, and telemetry onboarding for detection use cases

  • Experience with threat hunting using telemetry, analytics, and threat intelligence to identify adversary activity

  • Experience with incident response, including alert triage, investigation, containment, and remediation

  • Experience with leading a product team toward a shared goal, inspire confidence, and drive consensus across the organization.

  • Experience with and capacity to break down complex, ambiguous problems into smaller, manageable pieces and develop innovative solutions.

  • Experience with design tools, such as Figma, that enhance the product conceptualization process.

  • Knowledge of the MITRE ATT&CK framework for detection mapping and adversary analysis

  • Knowledge of cybersecurity operations, detection, cyberthreat intelligence, AI, distributed systems, and cloud-based infrastructure

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Applied = 0

(web-77cf7d65c7-rfjkk)