Skip to content
IllumioIllumio

Staff Security ML Researcher

Develops machine learning and graph-based security analytics for threat detection, attacker behavior modeling, and cyber-risk assessment. The role requires substantial experience in cybersecurity or machine learning, production model deployment, large-scale telemetry analysis, and strong Python and SQL skills.

About the job

Responsibilities

  • Design, develop, and deploy machine learning models for anomaly detection, threat detection, behavioral profiling, and security-risk prediction.
  • Apply statistical techniques and predictive modeling to evaluate breach likelihood, attack exposure, and segmentation effectiveness.
  • Analyze large-scale security datasets to identify attacker behavior, emerging threats, and MITRE ATT&CK-aligned patterns.
  • Develop threat-scoring and risk-assessment models to prioritize remediation and security investments.
  • Use graph-based analysis to model attack paths, quantify lateral-movement risk, and recommend mitigations.
  • Design and maintain scalable data pipelines for model training, validation, and analytics.
  • Partner with engineers to productionize models and analytics systems with scalability, reliability, and observability.
  • Conduct experiments and hypothesis-driven analysis to improve detection quality and reduce false positives.
  • Collaborate with product managers, designers, engineers, and threat researchers to embed ML-driven security insights into customer-facing products.
  • Research graph analytics, graph neural networks, probabilistic modeling, and AI-driven threat detection.
  • Contribute to patents, technical publications, conference presentations, and thought leadership.

Requirements

  • 5+ years of experience in security analytics, threat research, detection engineering, data science, or machine learning.
  • Strong Python programming skills and experience with data science and machine learning frameworks.
  • Experience designing, training, validating, and deploying ML or statistical models in production.
  • Experience working with large-scale security, networking, cloud, or infrastructure telemetry.
  • Strong understanding of model evaluation, feature engineering, experimentation, and imbalanced datasets.
  • Experience applying ML or analytics to cybersecurity problems such as anomaly detection, behavioral analysis, threat hunting, or risk assessment.
  • Familiarity with MITRE ATT&CK and common security telemetry sources.
  • Strong SQL and data-querying skills.
  • Excellent communication skills, including translating technical findings into product and business recommendations.

Nice to Have

  • 7–10+ years of experience spanning cybersecurity, machine learning, data science, or threat research.
  • Experience with graph-based security analytics, Neo4j, graph databases, or graph algorithms.
  • Knowledge of graph machine learning, graph neural networks, or link prediction.
  • Experience productionizing ML models in cloud environments using AWS, Kubernetes, or similar platforms.
  • Experience developing risk-scoring systems, recommendation engines, or predictive analytics solutions.
  • MS or PhD in Computer Science, Data Science, Machine Learning, Cybersecurity, Statistics, or a related field.
  • Cybersecurity-company experience in cloud security, network security, endpoint security, or threat intelligence.
  • Experience integrating threat-intelligence feeds and enrichment data into ML workflows.
  • Publications, patents, open-source contributions, or conference presentations related to security or applied ML.
  • CISSP, GIAC, or advanced machine-learning credentials.

Skills

Python, pandas, NumPy, scikit-learn, TensorFlow, PyTorch, Machine Learning, Statistical Modeling, Anomaly Detection, Mitre Att&Ck, Graph Analytics, Neo4J, SQL, AWS, Kubernetes

Shield AI

Shield AI

Washington, DC
Staff Engineer, Autonomy Capabilities – Maritime
$221k+/yrOn-site7+ YOEML Engineering

Leads development and integration of advanced maritime autonomy for USVs, UUVs, and cooperating UAVs, including motion planning, localization, safety, and multi-agent coordination. Requires staff-level technical leadership, substantial robotics experience, C++ and Python proficiency, and eligibility for a SECRET clearance.

Idme

Idme

Mountain View, CA

Staff Software Engineer - AI Agent Evaluations
$218k+/yrOn-site8+ YOEML Engineering

Leads the engineering discipline for evaluating, testing, and monitoring production AI agents, while building scalable eval infrastructure and developer tooling. Requires 8+ years of production software experience, strong backend skills, and expertise with LLM evaluation and agentic systems.

Harvey

Harvey

San Francisco, CA

Staff Software Engineer, Model Infrastructure
$231k+/yrHybrid7+ YOEML Engineering

Leads the design and operation of reliable, scalable model infrastructure powering AI inference across multiple providers. Requires 7+ years of distributed-systems engineering experience, strong programming skills, and expertise in production reliability and cloud infrastructure.

Shield AI

Shield AI

San Mateo, CA

Staff Software Engineer, Autonomy Capabilities
$234k+/yrOn-site7+ YOEML Engineering

Leads the design, implementation, integration, and field validation of tactical autonomy and multi-agent coordination capabilities for unmanned platforms. Requires 7+ years of relevant experience, production C++, technical leadership, and eligibility for a U.S. Secret clearance.

Snowflake

Snowflake

Bellevue, WA

Staff Software Engineer - Snowflake Feature Store
$236k+/yrOn-site10+ YOEML Engineering

Leads the roadmap and technical vision for Snowflake Feature Store, building reliable, high-performance machine learning platform capabilities and supporting technical execution across partner teams. Requires 10+ years of experience with data-serving infrastructure or ML platforms, plus Java and Python expertise.