Principal Security ML Research Engineer

Elastic Elastic · Enterprise · Canada +1 · Security - Protections

Principal Security ML Research Engineer at Elastic, focusing on developing advanced AI/ML solutions for threat detection and response. The role involves designing ML architectures, prototyping AI agent workflows, developing anomaly detection models, creating evaluation frameworks, implementing guardrails, and integrating LLM APIs into production. Emphasis on research, community involvement, and mentoring.

What you'd actually do

  1. Design innovative ML architectures that enhance threat detection and response capabilities. Prototype advanced AI agent workflows to streamline incident investigation processes. Collaborate with cross-functional teams to define project specifications and ensure models are optimized for real-world performance and accuracy.
  2. Develop machine learning models aimed at detecting behavioral anomalies in security telemetry. Create techniques for profiling threat actors to better understand and predict their behaviors. Collaborate with stakeholders to refine security use cases, ensuring the applicability of ML models.
  3. Build evaluation frameworks to assess ML model performance metrics while developing benchmarking pipelines to test for accuracy and latency. Implement guardrails that minimize false-positive rates in detection systems. Measure the endurance of models against adversarial attacks and prompt injections, and conduct regular audits of model robustness to report findings to stakeholders.
  4. Mentor senior engineers in machine learning best practices and security methodologies to elevate the team's expertise. Collaborate closely with Product Management to ensure that security research aligns with product roadmaps. Foster well-developed relationships with engineering teams to guarantee the seamless implementation of machine learning solutions.
  5. Produce technical blogs that showcase your innovative findings in security machine learning. Author white papers that tackle emerging threats and detection strategies. Present insights at industry conferences to share advancements in security ML, and engage with the security research community to promote collaboration and information sharing.

Skills

Required

  • Master's degree in Computer Science, Cybersecurity, or a related field, or 5+ years designing and implementing security machine learning models
  • Experience with vector search technology for data retrieval
  • Retrieval-Augmented Generation techniques
  • working knowledge of deep learning, clustering, and graph algorithms
  • experience training models using scikit-learn, xgboost, PyTorch/Tensorflow
  • Knowledge of behavioral anomaly detection in security telemetry
  • expertise in profiling threat actor behaviors using machine learning
  • Ability to develop evaluation frameworks for ML model performance metrics
  • experience with benchmarking pipelines for testing accuracy and latency
  • Experience developing industry-leading scalable machine learning models that significantly improved threat detection while ensuring minimal false-positive rates
  • Published research in reputable security and machine learning journals or presented findings at major security conferences and workshops
  • Proficiency in modern AI/ML frameworks
  • hands-on experience integrating LLM APIs into production applications

Nice to have

  • Prototype advanced AI agent workflows
  • Implement guardrails that minimize false-positive rates
  • Measure the endurance of models against adversarial attacks and prompt injections
  • conduct regular audits of model robustness
  • Mentor senior engineers in machine learning best practices and security methodologies
  • Collaborate closely with Product Management
  • Foster well-developed relationships with engineering teams
  • Produce technical blogs
  • Author white papers
  • Present insights at industry conferences
  • engage with the security research community

What the JD emphasized

  • designing and implementing security machine learning models
  • vector search technology for data retrieval
  • Retrieval-Augmented Generation techniques
  • behavioral anomaly detection in security telemetry
  • profiling threat actor behaviors using machine learning
  • develop evaluation frameworks for ML model performance metrics
  • benchmarking pipelines for testing accuracy and latency
  • developing industry-leading scalable machine learning models
  • minimal false-positive rates
  • Published research in reputable security and machine learning journals or presented findings at major security conferences and workshops
  • integrating LLM APIs into production applications

Other signals

  • developing advanced AI and machine learning solutions
  • prototype advanced AI agent workflows
  • develop evaluation frameworks to assess ML model performance metrics
  • implement guardrails that minimize false-positive rates
  • integrating LLM APIs into production applications