Senior/Staff/Principal AI/ML Engineer - Threat Detection Engineering

2 months, 1 week ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Appgate

Appgate

Appgate is the secure access company empowering secure connections with Zero Trust principles for people, devices, and systems.

Professional Services
251-1K
Founded 2020

Description

  • Design and implement detection algorithms across authentication, authorization, network/location, data access, session management, and behavioral domains.
  • Build threat detection models and systems to identify identity compromise, privilege escalation, impossible travel, data exfiltration, and other threats.
  • Develop and deploy anomaly detection models such as Isolation Forest, One-Class SVM, and autoencoder neural networks.
  • Design explainable risk aggregation and scoring systems that correlate detection signals into dynamic user, device, and session risk scores.
  • Build scalable, low-latency streaming pipelines for real-time processing of ZTNA audit logs and security telemetry.
  • Architect and operate the end-to-end detection pipeline from log ingestion through risk aggregation and enforcement integration.
  • Define and maintain the detection taxonomy and lifecycle for the broader detection library.
  • Measure and improve signal quality by tracking MTTD, false positives, and MITRE ATT&CK coverage.
  • Partner with red teams to validate detections against realistic attack scenarios.
  • Collaborate with security, product, and platform engineering to align detection coverage with customer threat models and roadmap priorities.

Requirements

  • 7+ years of production AI/ML engineering experience.
  • Experience building threat detection, UEBA, ITDR, or identity security platforms, preferably at leading security or cloud companies.
  • Hands-on experience designing detections for identity-based threats such as credential compromise, privilege escalation, insider activity, behavioral anomalies, and data exfiltration.
  • Experience building AI-powered security systems using large language models, deep learning, and agentic AI techniques.
  • Real-time or near-real-time streaming pipeline experience with Kafka, Flink, Spark Streaming, or equivalent.
  • Familiarity with lakehouse formats such as Apache Iceberg or Parquet.
  • Knowledge of MITRE ATT&CK, identity threat kill chains, ZTNA or network access control systems, and audit log analysis.
  • Experience with detection-as-code frameworks such as Sigma or YARA is a bonus.
  • Experience applying LLMs or GNNs to security is a bonus.
  • Publications at USENIX, CCS, NeurIPS, or ICML are a bonus.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security / DevSecOps Engineer (Blockchain-Fintech)

Alloy Internet Software & Services

Index Industries is seeking a DevSecOps engineer to secure its stealth-stage blockchain and cloud infrastructure as it prepares to launch its first technology in 2026.

AWS Blockchain CI/CD DevSecOps Docker GCP Go Kubernetes Python Secrets Management
18 hours ago

Senior Software Engineer - Security Libraries

Datadog 5K-10K IT Services

Datadog is hiring a senior polyglot engineer to build and operate security library integrations for its run-time security products, with a primary focus on .NET or Java.

C# C++ Envoy Go HAProxy Java Maven .NET Nginx Node.js PHP Python Ruby WAF
18 hours ago

Head of Security Research

Dropzone AI 51-200 computer & network security

Dropzone AI is hiring a Head of Security Research to lead its cybersecurity research and detection team as the company builds agentic AI systems that reimagine threat intelligence, hunting, detection engineering, and alert investigation.

Cybersecurity SOC
18 hours, 15 minutes ago

Cyber Data Engineer

D2 Technical Services 11-50 IT services and consulting

D2 Technical Services is hiring a systems engineer to support national security cybersecurity operations by managing infrastructure, data pipelines, and SIEM environments.

AWS Bash Cybersecurity DHCP DNS Elasticsearch GCP Linux PowerShell Python SIEM Splunk
18 hours, 15 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers