Obsidian Security has named Khanh Tran as its new Chief Product Officer (CPO). Tran, previously the CPO at JumpCloud and VP of Product Management at CrowdStrike, brings more than 20 years of experience in cybersecurity product leadership. Beyond his corporate achievements, he has advised and invested in numerous startups, consistently driving growth and innovation.

Joining Tran at Obsidian are former CrowdStrike product leaders Rekha Das and Alex Graul. Das will oversee the company’s initiatives in platform, partner ecosystems, and agentic AI—preparing for the unique security challenges posed by this emerging identity category. Graul will lead user experience design and UI engineering, simplifying SaaS security for all stakeholders within the shared responsibility model.

As organizations increasingly rely on SaaS platforms, they face complex challenges in managing federated, unfederated, and unsanctioned applications. Under the shared responsibility model, the burden of data protection falls largely on customers. The rise of agentic AI—a new identity category requiring advanced authentication and access controls—further complicates the landscape. While businesses seek to maximize SaaS value, many lack the governance tools needed to secure sensitive data. Despite broad adoption of Zero Trust frameworks, SaaS-specific vulnerabilities often remain unaddressed. Gaps in configuration, monitoring, shadow IT, and account governance are now key focus areas for both threat actors and regulators.

“We have the opportunity to build an iconic, enduring company. The business agility from SaaS presents a new security frontier,” said Obsidian CEO Hasan Imam. “From my first conversations with Khanh, his forward-thinking approach and customer-first mindset aligned perfectly with our mission to strengthen digital resilience across all SaaS identities—human, non-human, and agentic.”

Obsidian Security’s proprietary Knowledge Graph is foundational to its capabilities, mapping SaaS identities and integrations to normalize unstructured logs and deliver high-fidelity threat detection. The company's Identity Threat Detection and Response (ITDR) solution continuously monitors for anomalous activity across SaaS environments, drawing on insight from hundreds of real-world incident responses. This enables near real-time detection of sophisticated threats, including insider risks.

Additionally, Obsidian’s context-aware SaaS Security Posture Management (SSPM) solution safeguards both known and shadow applications while ensuring organizations meet evolving compliance mandates. Obsidian stands out as the only fully integrated platform purpose-built to address the full SaaS security lifecycle—spanning prevention, discovery, posture management, integration risk, detection, and response.

“The cybersecurity landscape is anything but predictable,” said Tran. “With its identity-first approach and unparalleled breach insights, Obsidian is ahead of the curve in SaaS security. I’m excited to help advance our vision—protecting customers today and continuously evolving our solutions to meet tomorrow’s threats.”