Staff Security Detection Engineer, Machine Learning

SoFi SoFi · Fintech · San Francisco, CA · Information Security

Staff Security Detection Engineer at SoFi, focused on building and maturing an ML-driven detection and anomaly detection program. The role involves end-to-end ownership of the detection and model lifecycle, including feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines. Collaboration with Security Operations Center (SOC), Security Operations Engineering, and Fraud programs is key to transforming high-volume telemetry into high-confidence, low-noise detections at scale.

What you'd actually do

  1. Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets.
  2. Operationalize models and detections from notebook to production, including enrichment, correlation, and response playbook hooks (detection-as-code, CI/CD, model versioning, and rollback).
  3. Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality.
  4. Partner with the SOC to triage, tune, and close detection feedback loops; use analyst dispositions as labels to retrain and improve models, reduce noise, and document runbooks.
  5. Collaborate with Threat Intelligence, Security Architecture, and Fraud stakeholders to translate threat hypotheses and scenarios into repeatable, model-backed analytics with clear success metrics.

Skills

Required

  • Python
  • SQL
  • scikit-learn
  • PyTorch or TensorFlow
  • Snowflake
  • Databricks
  • Spark
  • Delta/Iceberg
  • S3/GCS
  • anomaly detection techniques
  • MITRE ATT&CK
  • security telemetry sources

Nice to have

  • Kafka
  • Kinesis
  • Pub/Sub
  • Flink
  • Spark Streaming
  • AWS SageMaker
  • AWS S3
  • AWS Glue
  • AWS Athena
  • AWS Lambda
  • MLOps
  • feature stores
  • model registries
  • experiment tracking
  • canary and shadow releases
  • Graph-based ML
  • deep learning
  • LLM-based approaches to security
  • LLMs to design, analyze, and test detections
  • AWS/GCP machine learning or data engineering certifications
  • Databricks certifications

What the JD emphasized

  • 7+ years hands-on experience building and operating machine learning models for detection or anomaly detection in production

Other signals

  • building and operating machine learning models for detection or anomaly detection in production
  • design, build, and maintain machine learning models for anomaly detection
  • Operationalize models and detections from notebook to production