
Data Scientist
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in Virginia.
• Develop and assess machine-learning analytics tailored for cyber defense applications utilizing network, sensor, alert, asset, and various operational telemetry.
• Create unsupervised and statistical models for tasks such as clustering, anomaly/outlier detection, behavioral baselining, novelty detection, and pattern discovery.
• Implement graph analytics/embeddings, nearest-neighbor techniques, time-series analysis, clustering, dimensionality reduction, and anomaly scoring on extensive cyber datasets.
• Design models and features that take into consideration concept drift, noisy data, incomplete ground truth, and elevated false-positive rates in operational cyber settings.
• Assist in asset discovery and entity resolution, including probabilistic asset graphs that link IPs, hostnames, MAC addresses, services, certificates, device attributes, and other observations across various data sources.
• Generate contextual features from security alerts and network telemetry to pinpoint significant alert clusters and outliers.
• Collaborate with cyber analysts and detection engineers to convert operational inquiries and adversary behaviors into quantifiable features, experiments, and analytics.
• Assess model performance through quantitative metrics and operational validation; benchmark accuracy, false-positive behavior, computational efficiency, and relevance to analysts.
• Produce production-quality Python code and partner with engineers to integrate models into sensor-side CPU environments and GPU-enabled enterprise analytics platforms.
• Decide when to utilize LLMs, conventional ML/statistics, or deterministic rules and queries.
• Construct evaluation harnesses with test datasets, expected behaviors, regression tests, failure cases, and quantitative assessments.
• BS or MS in Data Science, Computer Science, Statistics, Applied Mathematics, Engineering, Cybersecurity, or a related quantitative field.
• Proficient in Python.
• Practical experience with pandas, NumPy, scikit-learn, SciPy, and similar libraries.
• Strong grasp of unsupervised machine learning, encompassing clustering, anomaly/outlier detection, similarity/distance methods, feature engineering, and statistical baselining.
• Experience with graph analytics or graph ML, entity resolution/record linkage, probabilistic modeling, time-series analysis, change-point/concept-drift detection, nearest-neighbor techniques, or dimensionality reduction.
• Background in working with extensive, noisy, heterogeneous datasets where labels or authoritative ground truth are scarce.
• Familiarity with scalable data processing and effective model implementation.
• Comfortable considering CPU/memory constraints and GPU acceleration for larger tasks.
• Working knowledge of networking and cybersecurity concepts, including IP addressing, DNS, TLS, network flows, ports/services, routing, network devices, and security alerts.
• Experience with cyber/network telemetry such as Zeek, PCAP-derived data, SIEM data, IDS/IPS alerts, device configuration data, or vulnerability/asset data is highly desirable.
• Familiarity with graph/network-analysis libraries, SQL/data stores, Elasticsearch/Splunk, or similar analytic platforms is a plus.
• Experience in developing analytics for cybersecurity, threat hunting, detection engineering, or defensive cyber operations is strongly preferred.
• Unique benefits and personalized touches aimed at fostering a positive work-life experience.
• Inc. Magazine ‘Best Workplaces’ awardee employer.
Tendios
GuidePoint Security
Seneca Holdings
Get handpicked remote jobs straight to your inbox weekly.