Enable job alerts via email!

Cybersecurity Data Scientist – Automation & AI (Remote)

Merck

Austin (TX)

Hybrid

USD 80,000 - 110,000

Full time

9 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as a Cybersecurity Data Scientist, where you'll develop impactful models that enhance enterprise security. This role focuses on creating adaptive automation solutions using telemetry from leading security platforms. Collaborate with engineers to ensure your models drive real-time actions and improve risk posture. If you're ready to make a difference in cybersecurity through innovative data science, this is the perfect opportunity to showcase your skills in a dynamic environment.

Qualifications

  • 1-2 years of experience in applied data science, machine learning, or automation-focused analytics.
  • Proficient in Python and libraries like pandas, scikit-learn, and XGBoost.

Responsibilities

  • Build and maintain ML scoring logic in Databricks using security telemetry.
  • Engineer behavior models and collaborate with security engineers to embed models.

Skills

Python
Machine Learning
Data Science
Business Intelligence (BI)
Data Engineering
Stakeholder Relationship Management

Education

Experience in cybersecurity or enterprise engineering

Tools

Databricks
Microsoft Defender XDR
Microsoft Sentinel
ServiceNow

Job description

Job Description

Position Summary:

We are hiring a Cybersecurity Data Scientist to join the Cybersecurity Automation & AI team. This is a builder role inside a cybersecurity engineering organization—not a research lab, not an analytics reporting team. Your job is to develop real models that drive containment, response, and automation at scale using telemetry from platforms like Microsoft Defender XDR, Sentinel, Wiz, and ServiceNow.

Job Description:

This role is about impact. You will work on systems that directly affect enterprise risk posture, automating decisions around isolation, escalation, and prioritization. The models you build must work reliably inside operational pipelines, integrate with engineering workflows, and be explainable under pressure.

We are building adaptive, system-aware automation—models that reason over behavior and drive real-time action. That means everything you create must be contextual, actionable, and robust enough to operate in live production environments.

If you're used to exploratory notebooks with no consequences or haven't worked with security data before, this role will be hard. You must understand the stakes, the complexity, and how automation changes enterprise behavior. We’re not looking for theoretical modelers—we need someone who can think in systems and ship.

Key Responsibilities:

  • Build and maintain ML scoring logic in Databricks using telemetry from security platforms

  • Engineer behavior models, anomaly detectors, or confidence scoring systems that directly support automation

  • Collaborate with security engineers to embed models into workflows across Defender, Sentinel, ServiceNow, and other platforms

  • Think critically about automation safety, control boundaries, and unintended consequences

  • Validate and tune models based on stakeholder input and real-world telemetry

  • Document model logic, assumptions, edge cases, and operational safety mechanisms

  • Work with platform and automation engineers to integrate outputs cleanly into orchestration layers

Required Qualifications:

  • 1–2 years of experience in applied data science, machine learning, or automation-focused analytics

  • Proficient in Python and libraries like pandas, scikit-learn, and XGBoost

  • Hands-on experience with Databricks or similar environments for pipeline development

  • Strong working knowledge of telemetry, logs, time series, or event-based data

  • Foundational cybersecurity knowledge—if you don’t understand why systems are secured, why identity matters, or how detection works, you will struggle in this role

  • Ability to engineer models that support live security automation—not just insight or dashboards

  • A degree is not required; proven experience, portfolio work, or adjacent technical background in cybersecurity or enterprise engineering is valued more

Preferred Qualifications:

  • Familiarity with Defender XDR, Microsoft Sentinel, Wiz, ServiceNow, or related platforms

  • Experience building risk scoring, behavior classification, or signal enrichment models

  • Understanding of automation frameworks and how model outputs trigger action

  • Ability to document clearly, reason across technical domains, and work across multiple security teams

Current Employees apply HERE

Current Contingent Workers apply HERE

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics.As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

U.S. Hybrid Work Model

Effective September 5, 2023, employees in office-based positions in the U.S. will be working a Hybrid work consisting of three total days on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence.This Hybrid work model does not apply to, and daily in-person attendance is required for, field-based positions; facility-based, manufacturing-based, or research-based positions where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance also does not apply to roles that have been designated as “remote”.

San Francisco Residents Only:We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only:We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance

Search Firm Representatives Please Read Carefully
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Employee Status:

Regular

Relocation:

VISA Sponsorship:

Travel Requirements:

Flexible Work Arrangements:

Remote

Shift:

Valid Driving License:

Hazardous Material(s):


Required Skills:

Business Intelligence (BI), Database Design, Data Engineering, Data Modeling, Data Science, Data Visualization, Machine Learning, Software Development, Stakeholder Relationship Management, Waterfall Model

Preferred Skills:

Job Posting End Date:

05/13/2025

*A job posting is effective until 11:59:59PM on the day BEFOREthe listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.


Requisition ID:R347251

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Cybersecurity Data Scientist – Automation & AI (Remote)

MSD Malaysia

Austin

Remote

USD 80,000 - 130,000

8 days ago

Cybersecurity Data Scientist – Automation & AI (Remote)

Merck

Austin

Hybrid

USD 90,000 - 130,000

4 days ago
Be an early applicant

GEN AI Sr Data Scientist/Data Scientist

The Hartford

Hartford

Remote

USD 90,000 - 167,000

7 days ago
Be an early applicant

Senior Data Scientist - Enterprise DS & AI Org

Rootshell Inc

Remote

USD 80,000 - 120,000

2 days ago
Be an early applicant

Senior Data Scientist

83data

Raleigh

Remote

USD 55,000 - 145,000

4 days ago
Be an early applicant

Sr. Machine Learning Engineer

Mr. Cooper

Lewisville

Remote

USD 80,000 - 120,000

Yesterday
Be an early applicant

Sr. Machine Learning Engineer

Mr. Cooper Group Inc.

Lewisville

Remote

USD 90,000 - 150,000

Yesterday
Be an early applicant

Machine Learning Engineer

StackAdapt

Remote

USD 100,000 - 720,000

10 days ago

Energy Research Scientist

DataAnnotation

Texas

Remote

USD 80,000 - 100,000

Yesterday
Be an early applicant