Obsidian security

AI Product Manager – SaaS Supply Chain & Agent Access Risk

Palo Alto CA Full Time
Founded in 2017, Obsidian Security was created to close a critical gap: securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds more. 
 
Backed by top investors including Greylock, Norwest Venture Partners, and IVP, we’ve built a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Our team includes leaders who helped define the categories of endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. 
 
Now, we’re transforming how SaaS is secured—in the era of agentic AI. 
 
Today, Obsidian is trusted by global enterprises like Snowflake, T-Mobile, and Pure Storage. We protect more than 200 organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand—including many of the world’s largest Fortune 1000 and Global 2000 companies.
 
With strong global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise on the horizon, we’re scaling quickly toward long-term growth and IPO readiness. Join us as we define the future of SaaS security!

We’re looking for a Product Manager who understands the broader SaaS supply chain risks introduced by integrations, connectors, and third-party tools, and who has hands-on experience with agentic AI systems plus a strong grasp of the unique security risks they pose. In this role, you’ll treat AI agents as a new class of “super-integration” in the SaaS ecosystem and build products that give security teams robust guardrails while still enabling rapid innovation.

You’ll help define and deliver products that secure AI agents and 3rd-party integrations access to SaaS and tools. You will work cross-functionally with engineering, research, and security teams to turn technical innovation into customer-ready solutions.

Responsibilities

  • Product Ownership & Execution
    • Define the product vision and roadmap for AI agent and 3rd-party integrations access to SaaS apps, within Obsidian’s broader SaaS security platform.
    • Collaborate with engineering on designing secure, scalable implementations.
    • Manage the product lifecycle from ideation through launch and iteration.
  • Model AI agent access as SaaS supply chain risk
  • Treat AI agents, copilots, and automation tools as first-class identities in the SaaS supply chain: define how they are discovered, modeled, and risk-scored.
  • Design risk models that combine permissions, OAuth grants, scopes, data access patterns, and blast radius for AI agents and other integrations.
  • Specify detections and policies that surface risky behavior such as prompt injection–driven actions, data exfiltration attempts, over-privileged tools, and malicious or compromised integrations.
  • Build end-to-end workflows for security teams
  • Design workflows for discovery, assessment, approval, and continuous review of AI agents and SaaS integrations.
  • Collaborate with design to present risks, recommendations, and remediations in a way that is clear to security, IT, and app owners.
  • Integrate AI agent and supply chain risk signals into Obsidian’s alerts, investigations, and posture views so customers get a unified story of how AI and SaaS access interact.
  • Customer & Market Research
    • Conduct research with enterprise users and security practitioners to understand adoption barriers and risks.
    • Track industry developments in agentic AI and AI security to inform the roadmap.
  • Cross-Functional Collaboration
    • Work with design, product marketing, and customer success to ensure successful product adoption.
    • Translate highly technical AI/security concepts into clear product narratives for stakeholders.

Qualifications

  • Required
    • 2–5 years of product management experience in software or SaaS.
    • Engineering or technical background (degree or equivalent experience in computer science, machine learning, or cybersecurity).
    • Strong understanding of SaaS integration patterns (SSO/SCIM, OAuth, API keys, webhooks) and how they create third-party and supply chain risk.
    • Conceptual grasp of key AI and SaaS security risks: prompt injection, data leakage, over-privileged agents, compromised connectors, and lateral movement via SaaS.
    • Excellent communication skills and ability to bridge technical and business needs.
    • Demonstrated track record of shipping impactful features end-to-end: discovery → spec → execution → launch → iteration.
  • Preferred
    • Experience in cybersecurity, SaaS security, identity & access management, or third-party risk management.
    • Exposure to security or compliance frameworks (e.g., SOC 2, ISO 27001, NIST) and how they apply to SaaS and AI adoption.
    • Contributions to open-source AI/security projects or research communities.

Employee Benefits

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off 
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization.  If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy.

Base Salary Range
$197,000$231,000 USD