Staff Security Detection Engineer, Machine Learning
Core
Build and mature machine learning-driven detection and anomaly detection programs for security operations, operating over large-scale security data lakes and streaming pipelines.
Role type
Staff Security Detection Engineer (Machine Learning)
Builds
Production ML models for anomaly detection, detection-as-code pipelines, and high-confidence security alerts
Domain
Cybersecurity / Financial Services
Deliverable
production ML models
Required skills
Machine learning model development (supervised/unsupervised), anomaly detection techniques (clustering, time-series, isolation forests, autoencoders), Python, SQL, data lake technologies (Snowflake, Databricks, Spark, Delta/Iceberg), security telemetry analysis, model lifecycle management, stakeholder collaboration
Preferred skills
Streaming data engineering (Kafka, Flink), AWS ML services (SageMaker), MLOps practices, graph-based ML, deep learning/LLM applications in security
Technologies
Python, SQL, Snowflake, Databricks, Spark, Delta/Iceberg, S3/GCS, PyTorch, TensorFlow, Kafka, Kinesis, Pub/Sub, Flink, Spark Streaming, AWS SageMaker, Glue, Athena, Lambda
Responsibilities
Design and maintain ML models for anomaly detection; operationalize models from notebook to production; engineer and tune features from security telemetry; partner with SOC to triage and close feedback loops; collaborate on threat intelligence and fraud scenarios; establish model governance and monitoring; participate in post-incident reviews; mentor engineers and analysts
Seniority
Staff, hands-on IC with mentorship responsibilities
