On August 10, 2026, Rapid7 cut about 300 people, or 12% of its workforce, and new CEO Wael Mohamed told the market the company will now focus on "detection and response" and "exposure management." Those are the exact categories where CrowdStrike (up 112% over the past year) and Palo Alto Networks (up 130%) are hiring. If you spent the last five years running InsightVM scans, your next resume is a translation problem, not a rewrite from scratch.
What actually happened at Rapid7 on August 10, 2026
Rapid7 laid off roughly 300 people, forecast 2026 revenue as low as $837 million (down from $860 million), and said the board approved the restructuring plan on August 7. This is the second major cut in three years after an 18% reduction in August 2023, plus a smaller 21-person cut in July 2026.
The financial context matters because it tells you how urgent the pivot is:
- Annualized recurring revenue: $824 million, down 2% year over year
- ARR per customer: ~$70,000, down from $72,000, across more than 11,500 customers
- Restructuring charges: $11 million to $12 million, mostly severance, hitting Q3 and Q4 2026
- Stock performance: down 35% in the year before the announcement, then up 6% in aftermarket trading
- Activist pressure: Jana Partners disclosed a 13% economic interest in October 2024, which triggered the board changes that brought Mohamed in
Mohamed previously ran Forescout, which carried out layoffs around the time of his resignation. Assume more cuts follow when the Q3 and Q4 restructuring charges land. Waiting for a "stabilization" that historically does not come is the wrong move.
12% of the workforce, the second major reset in three years after August 2023's 18% cut.
Why CrowdStrike and Palo Alto are the obvious targets
CrowdStrike and Palo Alto Networks are hiring aggressively into the exact categories Rapid7 is narrowing toward, and their growth rates make the contrast brutal. CrowdStrike FY2026 ARR reached about $4.4 billion, up ~28% year over year. Palo Alto Networks' Next-Gen Security ARR is $4.6 billion, up ~18%, on FY2025 revenue of $8.2 billion.
Here is the head-to-head that displaced Rapid7 ICs should actually look at:
| Metric | Rapid7 | CrowdStrike | Palo Alto Networks |
|---|---|---|---|
| Latest ARR | $824M | ~$4.4B | $4.6B (NGS) |
| YoY ARR growth | −2% | +28% | +18% |
| 1-year stock performance | −35% | +112% | +130% |
| Flagship agent product (2026) | (narrowing) | Charlotte AI Agent | XSIAM Autonomous Response |
| Interview loop length | n/a | 5 to 7 weeks | 4 to 6 weeks |
Palo Alto Networks' Next-Gen Security ARR alone is roughly 5.6x Rapid7's total ARR. That is the size of the destination market. The question is whether your resume looks like it belongs there.
The 1.6% pivot: what the talent-market data actually shows
Only 657 US-based security professionals hold a detection, SOC, or IR title AND list Vulnerability Management as a skill, out of 42,085 US profiles with Vulnerability Management on them - 1.6%. The pivot Mohamed is forcing on 300 Rapid7 employees is a pivot most people in the field have not made, which is exactly why claiming it credibly is high-signal.
The numbers, straight from Refolk's index:
| Segment | US profiles | Note |
|---|---|---|
| "Vulnerability Management" as a skill | 42,085 | The pool being displaced |
| "XDR" or "EDR" as a skill | 5,266 | The destination pool, ~8x smaller |
| Detection/SOC/IR title AND Vulnerability Management | 657 | The people who already pivoted |
| Ratio: already-pivoted / VM pool | ~1.6% | Rare, therefore high-signal on a resume |
| Ratio: XDR/EDR pool / VM pool | ~12.5% | The scarcer, higher-leverage keyword set |
Two things follow. First, if you can honestly claim both VM and detection experience, put them side by side in the top third of the resume. You are in a very small cohort. Second, the top current employers of those 657 already-pivoted profiles are Meta, Datadog, Google, Figma, SAP, Marqeta, and HP, not CrowdStrike or Palo Alto. The pivot lands at end-user security teams as often as at vendors.
The pivot Mohamed is forcing on 300 Rapid7 employees is a pivot only 1.6% of vulnerability-management pros have already made.
The vocabulary swap: InsightVM bullets to AIDR bullets
Your Rapid7 experience already contains the substance CrowdStrike and Palo Alto want. What it lacks is their vocabulary. The single most important keyword right now is AIDR (AI Detection and Response), the category CEO George Kurtz publicly staked out at RSAC 2026 as the successor to EDR. Recruiter ATS boolean strings lag public taxonomy shifts by roughly a quarter, so candidates who put "AIDR" and "agent-behavior baselining" on a resume in August 2026 read as insiders. In six months, everyone will.
Rewrite specific bullets, not the whole resume:
- "Ran InsightVM scans across 12,000 assets" becomes "Operated continuous exposure management across 12,000 assets, aligning findings to detection and response workflows"
- "Triaged CVEs by CVSS score" becomes "Prioritized exposures using exploit-in-the-wild signals feeding SOC detection playbooks"
- "Deployed InsightIDR alerts" becomes "Built endpoint and identity detection content mapped to MITRE ATT&CK, with agent-behavior baselining"
- "Cross-sold three Insight modules per account" becomes "Drove multi-module attach (avg 3 per account) across VM, IDR, and CloudSec, mirroring Falcon's 5-module ARR concentration"
The word "exposure" is the free translation layer. Palo Alto's own competitive framing carves the market into agentic SOC, endpoint protection, exposure management, and attack surface management. VM bullets rewritten as "continuous exposure management" map cleanly onto Cortex Xpanse and Falcon Exposure Management pitches without any invention.
Doing this by hand for every posting is where most candidates lose the week. Paste a CrowdStrike Sales Engineer JD or a Palo Alto XSIAM detection engineer JD into Refolk and it rewrites your own resume against the specific language in that posting, then drafts the cover letter and scores how well you actually fit before you hit apply.
Module attach is what CrowdStrike actually hires for
CrowdStrike hires people who understand module attach, not just detection accuracy, because customers using 5+ Falcon modules now represent the majority of ARR. This is the single most underused framing on Rapid7 resumes.
If you are a Rapid7 SE or CSM who has cross-sold InsightVM plus InsightIDR plus InsightCloudSec, lead with:
- Modules deployed per customer (average and max)
- Attach motion: which module was the wedge, which followed, and why
- Renewal and expansion outcomes tied to multi-module footprints
- Consolidation wins where you replaced two or three point tools with a suite
That framing translates directly to Falcon's Cloud, Identity, Next-Gen SIEM, Exposure Management, and Charlotte AI modules, and to Palo Alto's Cortex XSIAM, Xpanse, XDR, and XSOAR. Detection accuracy stats are nice. Module math is what recruiters and hiring managers score against.
Don't ignore the buyers: Meta, Datadog, Google, Figma
The highest-probability landing spot for a displaced Rapid7 IC is probably not CrowdStrike or Palo Alto; it is an enterprise SOC at a company like Meta, Datadog, Google, or Figma. Refolk's index shows those are the top current employers of the 657 profiles who have already made the VM-to-detection pivot.
The mechanism is boring but real: enterprise security teams staff up quietly, do not run splashy hiring campaigns, and specifically want people who understand why a CVE matters in production, not just how to scan for it. A Rapid7 background is a strong signal there because you have already lived the gap between "the scanner found it" and "the on-call engineer patched it."
For that path, the resume framing shifts again:
- Lead with incidents you helped close, not scans you ran
- Name the cloud stack (AWS, GCP, Kubernetes) and the detection tooling on top
- Quantify MTTR reduction, not vulnerability counts
- Mention collaboration with SRE and platform engineering, since that is the actual job at buyer-side SOCs
Tailoring three variants of the same resume (CrowdStrike or Palo Alto vendor version, buyer-side SOC version, MSSP or consulting version) is the exact work Refolk takes off you: it drafts each version from your own history against a specific posting, so you are not maintaining three parallel documents by hand.
The Boston angle and the timing
Displaced Rapid7 employees are competing in a Boston security labor market that is already absorbing cuts from Snyk (90 jobs the same month) and what CyberSN CEO Deidre Diamond has publicly called "the slow bleed." Move now, before the Q3 and Q4 restructuring charges signal a second round.
Concrete sequencing for the next 30 days:
- Week 1: Rewrite the top of the resume with "exposure management" and "AIDR" language. Post it. Update the LinkedIn headline to include "Detection and Response" or "Exposure Management."
- Week 2: Apply to 8 to 12 postings at CrowdStrike, Palo Alto Networks, and buyer-side SOCs. For experienced hires with directly relevant cybersecurity backgrounds, CrowdStrike recruiter outreach typically arrives within 1 to 2 weeks; without domain-specific keywords, the wait stretches to 3 weeks or gets no reply at all.
- Week 3 to 4: CrowdStrike's technical loop runs 5 to 7 weeks; Palo Alto's runs 4 to 6. Start now to get an offer inside the severance window.
- In parallel: File for MA unemployment the day your separation date is set, not the day it hits.
The severance clock and the interview clock have to overlap. If you wait until the severance runs out, you are interviewing without leverage against candidates who started in August.
Out of 42,085 with Vulnerability Management as a skill in Refolk's index, only 1.6% have made the jump.
FAQ
Should I apply to CrowdStrike or Palo Alto Networks first?
Apply to both in the same week, but expect different timelines. CrowdStrike's technical loop tends to run 5 to 7 weeks with a multi-round virtual onsite and a high bar for domain experience. Palo Alto's runs 4 to 6 weeks. If your background is more sales-engineering or CSM than pure detection engineering, Palo Alto's XSIAM and Cortex Xpanse teams currently have broader entry points because the platform is younger and the module surface is still expanding.
Is "AIDR" really worth putting on a resume, or is it hype?
Put it on now. George Kurtz publicly framed AIDR as the category beyond EDR at RSAC 2026, and recruiter ATS boolean strings lag public taxonomy shifts by roughly a quarter. Candidates who use "AIDR" and "agent-behavior baselining" today parse as insiders; in six months every VM refugee will use them and the signal will collapse. Only claim it if you can defend it in an interview by mapping specific detections you have built or supported to agent-speed telemetry.
What if I only did vulnerability management, not detection?
Reframe as exposure management, which is one of the two focus areas Mohamed named at Rapid7 and a live category at Palo Alto (Cortex Xpanse) and CrowdStrike (Falcon Exposure Management). "Continuous exposure management across N assets, prioritized by exploit-in-the-wild signals" is a truthful VM bullet that maps onto both vendors' current product pitches. You do not need to claim SOC analyst experience you do not have.
How many versions of my resume do I actually need?
Three: a vendor version for CrowdStrike and Palo Alto; a buyer-side SOC version for companies like Meta, Datadog, Google, and Figma; and an MSSP or consulting version. The bullets are the same underlying facts, but the vocabulary, the metrics you lead with, and the module-attach framing all shift. Refolk generates each variant from your work history against the specific posting, which is faster and more honest than keeping three master documents in sync manually.