SentinelOne: The Listed Israeli Position in Autonomous Endpoint Security
SentinelOne (NYSE: S) — Israeli-founded autonomous endpoint security. $6B market cap, $1.16B ARR, 2,800 employees. Weingarten, Cohen, Shamir founded 2013. Acquired Prompt Security ($250M), Observo AI ($230M), PingSafe. Tel Aviv R&D anchor.
SentinelOne (NYSE: S) is the Israeli-founded autonomous endpoint security platform — the listed U.S. public-market position on next-generation endpoint protection and AI-driven security operations. Founded in 2013 in Israel by Tomer Weingarten, Almog Cohen, and Ehud "Udi" Shamir. Listed on NYSE in June 2021. Market capitalization approximately $6 billion as of mid-2026, on $1.16 billion ARR (+23% YoY) and roughly 2,800 employees across Mountain View, Tel Aviv, Boston, Prague, and Tokyo. Category position: autonomous endpoint security and the emerging agentic SOC — competing directly with CrowdStrike, Microsoft Defender, and Palo Alto Networks Cortex. The listed public-market vehicle for Israeli cybersecurity R&D at the AI-and-endpoint intersection.
Company snapshot
Ticker: NYSE: S
Founded: 2013 in Israel by Tomer Weingarten, Almog Cohen, and Ehud "Udi" Shamir
HQ: Mountain View, California — Tel Aviv is the primary R&D center
IPO: June 2021, NYSE: S
Market cap: ~$6B (mid-2026)
ARR: $1.163B (Q1 FY2027, +23% YoY)
Revenue: $277M quarterly (+21% YoY)
Employees: ~2,800
CEO: Tomer Weingarten (co-founder)
CFO: Sonalee Parekh
President, Product & Technology: Ana Pinczuk (former President & GM at HPE; former SentinelOne board director)
Platform: Singularity XDR · Purple AI · Wayfinder MDR
Founder lineage and Israeli roots
The founding team traces to Israeli signals-intelligence and the broader Unit 8200 alumni network that has produced an outsized share of the global cybersecurity industry. Tomer Weingarten, the CEO, previously co-founded Toluna analytics and held product roles across the Israeli enterprise software cluster. Almog Cohen, the technical co-founder, had operating background at Check Point and the intelligence-community adjacent Israeli cyber layer. Ehud "Udi" Shamir, chief security officer, spent his early career in Israeli offensive-security research and vulnerability discovery.
Weingarten remains CEO more than a decade after founding — one of a small group of Israeli-founded cybersecurity public-company CEOs who have run the operating business continuously through the IPO transition and into the mature category-competition phase. The Tel Aviv R&D center is the platform's engineering base and the source of the technical leadership across the Singularity product line. SentinelOne is the U.S.-listed public-market vehicle through which global institutional investors express exposure to the Israeli autonomous-endpoint category.
Platform: Singularity, Purple AI, and the agentic SOC
The Singularity Platform extends across endpoint protection, XDR, cloud workload protection, identity threat detection, and — as of the 2025-2026 product cycle — an agentic SOC layer built on Purple AI. The platform architecture is built around an autonomous-agent model that runs local decision-making on the endpoint itself, rather than requiring cloud round-trips for every threat evaluation. That design decision, embedded from the 2013 founding, has become the platform's central technical differentiation as the endpoint-security category has consolidated around autonomous, AI-driven prevention.
Purple AI Agentic Investigations, launched in 2025, delivers zero-click autonomous threat investigation with full evidence chain generation before an analyst opens the console. The product represents the current frontier of the autonomous-SOC category — where AI agents conduct the initial investigation autonomously, present the analyst with a finished evidence package, and reduce the mean-time-to-response metric that defines enterprise security operations economics.
Wayfinder, launched at OneCon 2025, is SentinelOne's managed detection and response service, built on Singularity plus Google Threat Intelligence. The service extends the platform into the MDR category — where SentinelOne runs the security operations on behalf of the customer — and competes directly against CrowdStrike Falcon Complete and Microsoft Defender Experts.
Approximately 50% of ARR now comes from AI, Data, and Cloud products — up from a near-zero baseline three years ago. The category thesis has become the business. The endpoint-protection layer that SentinelOne was founded to build has extended into a full autonomous-security platform whose highest-growth segments are the AI-native adjacencies.
Acquisitions
SentinelOne has run a disciplined M&A program under the S Ventures and corporate development team, using acquisition to accelerate the platform expansion into cloud, AI security, and data infrastructure.
PingSafe — cloud security, acquired January 2024 for over $100 million. Extended Singularity into cloud workload protection at a moment when the CNAPP (cloud-native application protection platform) category was defining itself and where SentinelOne needed a native cloud product to compete against Wiz, Palo Alto Networks Prisma Cloud, and CrowdStrike Falcon Cloud Security.
Krebs Stamos Group — advisory consultancy founded by former CISA Director Chris Krebs and former Facebook CSO Alex Stamos. Acquired November 2023, rebranded as PinnacleOne Strategic Advisory Group. The acquisition gave SentinelOne a senior policy and strategic-advisory bench positioned around U.S. federal cyber policy. Krebs resigned April 2025 following a Trump-administration executive order.
Prompt Security — Tel Aviv-based GenAI cyber startup — acquired August 2025 for approximately $250 million. See the Olam profile of Prompt Security. Extended Singularity into runtime AI security and prompt-injection defense — one of the fastest-emerging categories in enterprise cyber and one where Israeli founding density is high.
Observo AI — AI-native real-time data pipeline platform — acquired September 2025 for approximately $230 million in cash and stock. Advanced the AI SIEM strategy and autonomous-SOC roadmap by giving SentinelOne native ownership of the data infrastructure layer that Purple AI and the broader autonomous-SOC platform depend on.
S Ventures — the strategic investment arm
S Ventures, SentinelOne's corporate venture arm, has made 25 investments in market-defining AI and infrastructure companies including Anthropic, Cohere, Scale AI, and PsiQuantum. The portfolio doubles as a strategic-partner network and a signaling asset for SentinelOne's positioning at the AI-and-security intersection. Corporate venture as a strategy — building relationships with the AI-infrastructure companies whose models the SentinelOne platform will increasingly integrate with — is one of the newer M&A-adjacent tools that has emerged in the last two enterprise-cyber cycles.
Position in the Israeli cyber cohort
SentinelOne sits inside the small group of Israeli-rooted cybersecurity companies listed on U.S. public markets, alongside Check Point Software, CyberArk (acquired by Palo Alto Networks in February 2026 for $25B — see Nir Zuk profile), Cellebrite, Verint Systems, and Cognyte. Privately held Israeli-rooted peers include Wiz (acquired by Google Cloud in March 2026 for $32B — see Assaf Rappaport profile), Snyk, and Cato Networks. Structurally distinct from the offensive-cyber cohort represented by NSO Group, Paragon, and the Pegasus platform — SentinelOne operates on the defensive enterprise side.
The consolidation cycle across the Israeli cyber cohort in 2025-2026 — CyberArk into Palo Alto Networks, Wiz into Google Cloud — has left SentinelOne as one of the largest remaining independent Israeli-founded public cyber companies. That structural position matters for investors who want listed Israeli cyber exposure without the concentration risk of Check Point.
Competitive positioning
SentinelOne's core market is autonomous endpoint protection and extended detection and response (XDR). Primary competitors: CrowdStrike (Falcon), Microsoft (Defender for Endpoint), Palo Alto Networks (Cortex XDR), and legacy Symantec and McAfee. Named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms.
The July 2024 CrowdStrike Falcon outage produced a customer-migration window that SentinelOne captured meaningfully — reflected in the accelerated net-new ARR figures across 2025 and 2026. The outage exposed the concentration risk in single-vendor endpoint deployments and created an opening for the two remaining pure-play competitors (SentinelOne and Palo Alto Networks Cortex) to win share from customers who had been consolidated onto CrowdStrike single-vendor architectures.
The Microsoft Defender competitive dynamic is different in structure. Microsoft distributes Defender inside E5 enterprise licenses at a substantial pricing discount to standalone endpoint operators — SentinelOne, CrowdStrike, Palo Alto — and wins share primarily on procurement bundling rather than pure product performance. The autonomous-agent architecture SentinelOne was founded on has been the platform's principal defense against that bundling pressure, since it produces measurably better detection outcomes on the enterprise-endpoint benchmarks that CISO buyers reference.
Primary Sources
- SentinelOne — SEC filings (10-K, 10-Q, S-1 IPO prospectus)
- Gartner Magic Quadrant for Endpoint Protection Platforms 2026
- SentinelOne OneCon 2025 product announcements
- NYSE — SentinelOne (S) listing materials
FAQ
What is SentinelOne?
SentinelOne (NYSE: S) is the Israeli-founded autonomous endpoint security and XDR platform. Founded 2013 by Tomer Weingarten, Almog Cohen, and Ehud Shamir. Listed on NYSE in June 2021.
Where is SentinelOne headquartered?
Mountain View, California, with primary R&D in Tel Aviv. Additional offices in Boston, Prague, and Tokyo.
What is SentinelOne's revenue and market cap?
Approximately $6 billion market cap on ~$1.16B in annual recurring revenue (Q1 FY2027, +23% YoY). Quarterly revenue $277M (+21% YoY). ~2,800 employees.
Who runs SentinelOne?
Co-founder Tomer Weingarten is CEO. CFO is Sonalee Parekh. President of Product & Technology is Ana Pinczuk. The Tel Aviv center leads platform engineering.
What has SentinelOne acquired?
Recent acquisitions include Prompt Security ($250M, August 2025), Observo AI ($230M, September 2025), PingSafe ($100M+, January 2024), and Krebs Stamos Group (November 2023).
Who does SentinelOne compete with?
CrowdStrike, Microsoft Defender, Palo Alto Networks Cortex, and legacy Symantec and McAfee. Named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms.
בעברית
SentinelOne (בורסת ניו יורק: S) — פלטפורמת אבטחת קצה אוטונומית וסוכני SOC, נוסדה ב־2013 בישראל על ידי טומר וויינגרטן, אלמוג כהן ואהוד "אודי" שמיר. הונפקה ביוני 2021 ב־NYSE. שווי שוק של כ־6 מיליארד דולר, ARR של 1.163 מיליארד דולר (רבעון 1 של שנת הכספים 2027, +23% שנתי), הכנסה רבעונית של 277 מיליון דולר (+21%), כ־2,800 עובדים במאונטיין ויו, תל אביב, בוסטון, פראג וטוקיו. מנכ"ל: טומר וויינגרטן. מרכז המו"פ המרכזי בתל אביב. פלטפורמת Singularity, שכבת ה־AI האוטונומית Purple AI, ושירות ה־MDR החדש Wayfinder שנבנה בשיתוף Google Threat Intelligence. רכישות מהתקופה האחרונה: Prompt Security (250 מיליון דולר, אוגוסט 2025), Observo AI (230 מיליון דולר, ספטמבר 2025), PingSafe (מעל 100 מיליון דולר, ינואר 2024). מתחרות עיקריות: CrowdStrike, Microsoft Defender, Palo Alto Networks Cortex. ליידר במגיק קוודרנט של גרטנר לשנת 2026.

