Senior Machine Learning Engineer, Shield

Box Box · Enterprise · Redwood City, CA · Enterprise

Senior Machine Learning Engineer at Box, focused on building and deploying ML models for enterprise security features, including threat detection (ransomware, suspicious sessions, user behavior analytics) and anomaly detection. The role involves scaling ML pipelines, feature engineering, and production ML systems within a GCP environment, collaborating with cross-functional teams.

What you'd actually do

  1. Build Threat Detection Models: Design, train, and deploy ML models for ransomware detection, suspicious session identification, and user behavior analytics, anomaly detection
  2. Scale Data Pipelines: Own end-to-end ML pipelines that process high-volume security event streams using Apache Spark, GCP Dataflow, GCP Dataproc, BigQuery and Vertex AI
  3. Feature Engineering: Create and maintain feature stores that power real-time and batch anomaly detection systems
  4. Production ML Systems: Deploy, monitor, and iterate on ML models in production, serving enterprise customers at scale
  5. Cross-functional Collaboration: Partner with Platform, Application Engineering, and Product teams to translate security requirements into ML solutions

Skills

Required

  • 5+ years of experience in applied machine learning
  • Lead design and implementation efforts in building, deploying and supporting scalable ML systems
  • Experience with GCP (Vertex AI, BigQuery, Dataflow) or equivalent (AWS SageMaker, Azure ML)
  • Strong communication skills with ability to explain complex ML concepts to non-technical stakeholders
  • Ownership mindset with focus on delivering high-quality work both technically & collaboratively
  • Bachelors or above degree in Computer Science or equivalent practical experience.
  • Strong programming skills in Python
  • Deployed and maintained ML models serving real traffic
  • Deep understanding of feature engineering, model evaluation, and MLOps
  • Clear, inclusive communicator who values collaboration, mentorship, and continuous improvement.

Nice to have

  • Experience in security/threat or fraud detection and with sequential data and behavioral modeling (e.g., anomaly detection, time-series forecasting, LSTM, Transformers, or similar).
  • Experience with streaming/real-time ML systems
  • Experience with FedRAMP/compliance-constrained environments
  • Familiarity with Java stack for service integrations
  • Publications or contributions in ML security

What the JD emphasized

  • Deployed and maintained ML models serving real traffic
  • Deep understanding of feature engineering, model evaluation, and MLOps

Other signals

  • ML models for ransomware detection
  • suspicious session identification
  • user behavior analytics
  • anomaly detection
  • ML pipelines that process high-volume security event streams
  • feature stores that power real-time and batch anomaly detection systems
  • Deploy, monitor, and iterate on ML models in production