18 days ago
Paris, FranceSenior
Responsibilities
- Design, develop, deploy, evaluate, and tune machine learning models for security detection, anomaly identification, and incident response.
- Integrate ML outputs into SOC workflows to improve triage speed, detection precision, interpretability, and analyst actionability.
- Build and maintain pipelines that collect, process, transform, and securely store security-relevant data such as logs, network traffic, endpoint events, and authentication records.
- Develop LLM-powered tools for alert triage, evidence gathering, incident summarization, and report generation with operationally appropriate guardrails.
- Research and prototype unsupervised anomaly detection, graph-based threat correlation, adversarial ML, clustering, and other automated threat-detection techniques.
- Deploy models securely into production and implement monitoring, alerting, retraining, documentation, and performance tracking.
Requirements
- Proven experience in machine learning engineering or data science, ideally in a cybersecurity or operations context.
- Proficiency in Python and strong knowledge of machine learning frameworks.
- Experience manipulating and analyzing data with Pandas, NumPy, or similar tools.
- Familiarity with security data sources including SIEM logs, EDR telemetry, network flow, and authentication logs.
- Understanding of the full machine learning lifecycle, including data preparation, training, evaluation, deployment, and monitoring.
- Experience with data pipelines and storage technologies such as Airflow, Kafka, Redis, Elasticsearch, or ClickHouse.
- Prior experience in threat detection, SOC operations, or security automation is preferred.
- Knowledge of adversarial ML, graph analytics, or behavioral modeling in security contexts is preferred.
- Experience integrating ML models into SIEM pipelines or automated detection frameworks is preferred.
- Exposure to LLMs and AI engineering, including prompt engineering, RAG, and agent design, plus awareness of prompt injection and data leakage risks, is preferred.
- Ability to work independently and collaborate with machine learning and security specialists.
Benefits
- Hardware and software needed to do the job effectively.
- Learning and development investment with substantial ownership from the start.
- Health coverage, retirement options, generous leave, and wellness support.
- Stock options and company ownership opportunities.
- Primarily in-person collaboration at Proton offices, including Geneva, Zürich, Barcelona, and London.
- Free lunch and snacks in offices.
- Public transport, bike allowance, or parking support.
- Flexible working hours and schedule.
- Paris compensation is listed as €46,000–€74,000 gross annually; compensation for other locations is discussed during interviews.
