Senior/Staff/Principal AI/ML Engineer - Threat Detection Engineering

3 months ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Appgate

Appgate

Appgate is the secure access company empowering secure connections with Zero Trust principles for people, devices, and systems.

Professional Services
251-1K
Founded 2020

Description

  • Design and implement detection algorithms across authentication, authorization, network/location, data access, session management, and behavioral domains.
  • Build threat detection models and systems to identify identity compromise, privilege escalation, impossible travel, data exfiltration, and other threats.
  • Develop and deploy anomaly detection models such as Isolation Forest, One-Class SVM, and autoencoder neural networks.
  • Design explainable risk aggregation and scoring systems that correlate detection signals into dynamic user, device, and session risk scores.
  • Build scalable, low-latency streaming pipelines for real-time processing of ZTNA audit logs and security telemetry.
  • Architect and operate the end-to-end detection pipeline from log ingestion through risk aggregation and enforcement integration.
  • Define and maintain the detection taxonomy and lifecycle for the broader detection library.
  • Measure and improve signal quality by tracking MTTD, false positives, and MITRE ATT&CK coverage.
  • Partner with red teams to validate detections against realistic attack scenarios.
  • Collaborate with security, product, and platform engineering to align detection coverage with customer threat models and roadmap priorities.

Requirements

  • 7+ years of production AI/ML engineering experience.
  • Experience building threat detection, UEBA, ITDR, or identity security platforms, preferably at leading security or cloud companies.
  • Hands-on experience designing detections for identity-based threats such as credential compromise, privilege escalation, insider activity, behavioral anomalies, and data exfiltration.
  • Experience building AI-powered security systems using large language models, deep learning, and agentic AI techniques.
  • Real-time or near-real-time streaming pipeline experience with Kafka, Flink, Spark Streaming, or equivalent.
  • Familiarity with lakehouse formats such as Apache Iceberg or Parquet.
  • Knowledge of MITRE ATT&CK, identity threat kill chains, ZTNA or network access control systems, and audit log analysis.
  • Experience with detection-as-code frameworks such as Sigma or YARA is a bonus.
  • Experience applying LLMs or GNNs to security is a bonus.
  • Publications at USENIX, CCS, NeurIPS, or ICML are a bonus.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior AI Automation Engineer

Coforge 10K-50K IT Services

Coforge is hiring a remote Senior AI Automation Engineer to lead AI-driven automation and enterprise solution work across finance and treasury technology environments.

Generative AI LLM Machine Learning Python
6 hours, 18 minutes ago

Machine Learning Engineer - Azure & Databricks

Coforge 10K-50K IT Services

Coforge is hiring a remote Machine Learning Engineer to deploy and operationalize Azure and Databricks-based AI and machine learning solutions for production use.

Apache Spark Azure CI/CD Databricks Docker FastAPI Flask Kubernetes Machine Learning Microservices MLOps Python REST API
6 hours, 18 minutes ago

Lead Traveling Security Technician

Unlimited Technology 51-250 Professional Services

Unlimited Technology is hiring a Traveling Security Technician for UT Government to install, service, test, and inspect access control and IP camera systems for customers across the U.S.

6 hours, 33 minutes ago

Identity Management Engineer / Architect (R-00197)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking an Identity Management Engineer / Architect to design and operate a secure enterprise identity platform across on-premises, cloud, SaaS, and hybrid environments in support of Zero Trust and regulated government use cases.

Active Directory Cybersecurity DevSecOps OAuth OpenID Connect PowerShell Python SAML Terraform
6 hours, 33 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers