Senior AI/ML Engineer, Security Log Intelligence

RedMimicry GmbH

Berlin

Vor Ort

EUR 90.000 - 150.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

RedMimicry GmbH in Berlin seeks a Senior AI/ML Engineer to lead applied AI/ML work behind its breach and attack emulation platform. You will extract structure from noisy security telemetry and relate it to attacker activity, shaping LLMs, embeddings, and retrieval with practical latency and reliability.

You will design parsing methods for SIEM/EDR/NDR data, evaluate representations, calibrate models, and ground results in traceable evidence.

Qualifikationen

  • MSc/PhD or equivalent practical research in CS/ML/data science.
  • Ability to read, reproduce, and critically evaluate current research.
  • Strong Python and ML engineering foundations.

Aufgaben

  • Develop Security-Log Parsing Methods for heterogeneous telemetry.
  • Design Embeddings and Retrieval for security events.
  • Handle Ambiguity with confidence scoring and calibration.
  • Ground results in traceable evidence from original telemetry.
  • Build rigorous evaluations with datasets, baselines, and ablations.
  • Optimize inference for cloud and on-prem deployments.
  • Productise research into maintainable services with backend teams.
  • Document experiments, architecture decisions, and technical reports.
  • Contribute to an academic research paper as co-author.

Kenntnisse

Python
PyTorch
LLM systems
Embeddings
Retrieval systems
Fine-tuning/PEFT
Model serving
Calibration
Security telemetry
English
German (plus)

Ausbildung

MSc/PhD or equivalent

Tools

Docker/Kubernetes
APIs
Distributed services

Jobbeschreibung

We are building a new capability that turns fragmented, noisy security logs into explainable, AI-powered threat analysis, delivered inside the RedMimicry platform.

As Senior AI/ML Engineer at RedMimicry, you will lead the applied AI/ML work behind new analysis capabilities for our breach and attack emulation platform. The core challenge is extracting useful structure from heterogeneous, partially unstructured security telemetry and relating it to known attacker activity.

The problem is broader than prompt engineering. You will determine where LLMs, embeddings, retrieval, learned ranking, and deterministic heuristics are justified. The standard is measurable improvement against reproducible baselines, not architectural fashion. Everything you build must operate under realistic latency, reliability, and deployment constraints.

What You’ll Do
  • Develop Security-Log Parsing Methods: Design and implement methods for extracting typed events from heterogeneous SIEM, EDR, NDR, operating-system, and network telemetry.
  • Design Embeddings and Retrieval: Select, evaluate, and tune representations and retrieval methods for security events.
  • Handle Ambiguity Explicitly: Implement confidence scoring, calibration, and controlled treatment of ambiguous evidence.
  • Ground Results in Evidence: Ensure that results are supported by traceable evidence from the original telemetry.
  • Build Rigorous Evaluations: Define datasets, baselines, ablations, and metrics, and analyse failure modes systematically.
  • Optimise Inference: Make the pipeline practical for cloud operation and on-premises deployment.
  • Productise the Research: Work with backend, integration, and offensive-security engineers to turn experimental methods into maintainable services.
  • Document the Work: Produce clear experiment records, architecture decisions, and technical reports.
  • Contribute to Academic Research: Contribute, at minimum as a co-author, to an academic research paper published in the context of the project.
Skills

You do not need to meet every requirement to apply. We care more about demonstrated depth, sound experimental judgement, and the ability to ship reliable systems than about a specific academic title.

  • Machine Learning and LLM Systems
    • Strong Python programming skills
    • Practical experience with PyTorch or a comparable framework
    • Experience with open-weight language models, structured outputs, embeddings, or retrieval systems
    • Experience with fine-tuning, PEFT, quantisation, model serving, or inference optimisation
    • Understanding of hallucination, calibration, distribution shift, and model failure analysis
  • Information Retrieval and Evaluation
    • Semantic retrieval, ranking, classification, or information extraction
    • Approximate nearest-neighbour search and vector indices
    • Evaluation using metrics such as Recall@K, MRR, F1, exact match, calibration, and ablation studies
    • Dataset construction, partitioning, and reproducible benchmarking
  • Software Engineering
    • Ability to turn experimental code into maintainable production components
    • Testing, profiling, observability, and performance analysis
    • Experience working with APIs, distributed services, and containerised environments
  • Cybersecurity Knowledge
    • Security logs, SIEM, EDR, NDR, detection engineering, incident response, or threat hunting are strong advantages
    • Understanding of endpoint, process, identity, and network telemetry is a plus
  • Research Background
    • MSc, PhD, or equivalent practical research experience in computer science, machine learning, data science, mathematics, or a related field
    • Ability to read, reproduce, and critically evaluate current research
  • Languages
    • English (required)
    • German (a plus)
Other Requirements
  • Existing legal right to work in Germany and primary residence in Germany
  • Clean criminal record certificate
  • Willingness to travel to the Berlin office approximately once per month
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Platform and Integration Engineer, Security Telemetry
Platform and Integration Engineer, Security Telemetry

RedMimicry GmbH • Berlin

Vor Ort
EUR 90.000 - 130.000
Junior AI/ML Engineer, Data and Evaluation
Junior AI/ML Engineer, Data and Evaluation

RedMimicry GmbH • Berlin

Hybrid
EUR 70.000 - 100.000
Senior AI/ML Engineer, Security Log Intelligence
Senior AI/ML Engineer, Security Log Intelligence

United States Digital Space LLC • Berlin

Hybrid
EUR 90.000 - 130.000
Work from anywhere in Germany
Berlin office access
30 days paid time off
+4
Full Stack Engineer, Security Analytics
Full Stack Engineer, Security Analytics

Meyandy LLC • Berlin

Hybrid
EUR 70.000 - 100.000
Work from anywhere in Germany
Berlin office access
30 days PTO
+4
Platform and Integration Engineer, Security Telemetry (32h)
Platform and Integration Engineer, Security Telemetry (32h)

Meyandy LLC • Berlin

Hybrid
EUR 45.000 - 75.000
Berlin office access
Work from anywhere in Germany
Full Stack Engineer, Security Analytics
Full Stack Engineer, Security Analytics

United States Digital Space LLC • Berlin

Hybrid
EUR 70.000 - 110.000
Work from anywhere in Germany
Berlin office access
Deutschlandticket
+3
Platform and Integration Engineer, Security Telemetry (32h)
Platform and Integration Engineer, Security Telemetry (32h)

United States Digital Space LLC • Berlin

Hybrid
EUR 83.000 - 124.000
30 days paid time off
Deutschlandticket
Annual learning budget
+1
Security Engineer (m/f/d)
Security Engineer (m/f/d)

Security Research Labs • Berlin

Hybrid
EUR 55.000 - 90.000
Gym discounts
Public transport pass
German lessons
+5
Senior AI/ML Engineer, Security Log Intelligence
Senior AI/ML Engineer, Security Log Intelligence

Meyandy LLC • Berlin

Hybrid
EUR 70.000 - 110.000
Machine Learning Lead
Machine Learning Lead

Cyber Valley GmbH • Tübingen

Vor Ort
EUR 110.000 - 160.000
Remote within Germany
Small, fast-moving team