Staff Security ML Researcher

Illumio

Sunnyvale (CA)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Illumio is seeking a Staff Security ML Researcher to develop ML-driven threat detection and risk analytics. You will apply advanced statistical methods and graph-based analysis to quantify cyber risk across large enterprise environments.

You'll collaborate with threat researchers, engineers, and product teams to transform security data into actionable insights and customer-facing capabilities, driving zero trust and breach containment across hybrid multi-cloud environments.

Qualifications

  • 5+ years in security analytics, threat research, detection engineering, or data science/ML.
  • Strong Python with data science frameworks (Pandas, NumPy, Scikit-learn, TensorFlow or PyTorch).
  • Experience building ML models in production and evaluating them.
  • Ability to work with large-scale telemetry from security, networking, cloud, or infrastructure.
  • Knowledge of model evaluation, feature engineering, and experimentation.
  • Experience applying ML to cybersecurity: anomaly detection, risk, or threat hunting.
  • Familiarity with MITRE ATT&CK and common security telemetry sources.
  • Strong SQL/data querying and excellent communication skills.

Responsibilities

  • Design, train, validate, and deploy ML models for threat detection and risk assessment.
  • Analyze attacker behavior and model cyber risk across enterprise environments.
  • Build scalable data pipelines for model training and analytics.
  • Collaborate with threat researchers, engineers, and product teams to deliver security insights.
  • Advance graph-based security analytics and risk scoring with practical impact.

Skills

Security analytics
Threat research
Detection engineering
Data science
Machine learning
Python programming
Model deployment
Telemetry data handling
Model evaluation
Cybersecurity domain knowledge
MITRE ATT&CK familiarity
SQL & data querying
Communication skills

Education

MS or PhD in CS/DS/ML/Cybersecurity/Statistics

Tools

Neo4j
Graph databases
Graph algorithms
AWS
Kubernetes
TensorFlow / PyTorch

Job description

Onwards Together!

Illumio is the leader in ransomware and breach containment, redefining how organizations contain cyberattacks and enable operational resilience.Powered by the Illumio AI Security Graph, our breach containment platform identifies and contains threats across hybrid multi-cloud environments – stopping the spread of attacks before they become disasters.
Recognized as a Leader in the Forrester Wave™ for Microsegmentation, Illumio enables Zero Trust, strengthening cyber resilience for the infrastructure, systems, and organizations that keep the world running.

Location: 4 on-site days a week in Sunnyvale, CA Headquarters.
Our Team's Vision:

The Office of the CTO and Security team sets the strategic technical direction of the company while keeping both Illumio and our customers secure. Those who join us represent the leader in Zero Trust Segmentation and maintain Illumio’s competitive advantage by exploring new technologies while collaborating with Engineering and Product Management.

We are looking for people who leverage differences and push the pace of innovation in a time when the world faces its greatest cybersecurity threats in history.

About the Role

We're seeking a Staff Security ML Researcher to develop machine learning-driven approaches for threat detection, risk assessment, and security analytics. In this role, you'll apply advanced statistical methods, machine learning, and graph-based analysis to identify threats, model attacker behavior, and quantify cyber risk across complex enterprise environments.

Working at the intersection of cybersecurity, machine learning, and product innovation, you'll partner with threat researchers, engineers, and product teams to transform large-scale security data into intelligent models, actionable insights, and customer-facing capabilities that help organizations better understand and reduce cyber risk.

Your Impact:

Machine Learning & Security Intelligence

  • Design, develop, and deploy machine learning models that identify anomalous behavior, detect threats, and predict security risk across complex enterprise environments.

  • Apply statistical techniques and predictive modeling to evaluate breach likelihood, attack exposure, and segmentation effectiveness.

  • Build behavioral profiling, anomaly detection, clustering, classification, and forecasting models using large-scale security telemetry.

  • Evaluate model performance, reduce false positives, and continuously improve detection quality through experimentation and data-driven analysis.

Threat Research & Risk Modeling

  • Analyze large-scale security datasets to identify attacker behaviors, emerging threats, and patterns aligned to frameworks such as MITRE ATT&CK.

  • Develop threat scoring and risk assessment models that help customers prioritize remediation and security investments.

  • Leverage graph-based analysis techniques to model attack paths, quantify lateral movement risk, and recommend mitigation strategies.

  • Work closely with threat researchers to transform security intelligence into measurable detection and prediction capabilities.

Data Science & Analytics Engineering

  • Design and maintain scalable data pipelines used for model training, validation, and analytics.

  • Investigate new features, signals, and telemetry sources to improve detection accuracy and risk predictions.

  • Partner with engineers to productionize models and analytics systems while ensuring scalability, reliability, and observability.

  • Conduct experiments and hypothesis-driven analysis to validate new detection approaches and security insights.

Product Collaboration & Innovation

  • Collaborate with product managers, designers, and engineers to embed ML-driven security insights into customer-facing experiences.

  • Influence product strategy through data-backed recommendations and threat intelligence findings.

  • Help define security analytics frameworks, data requirements, and detection methodologies for future product capabilities.

  • Serve as a subject matter expert on the use of machine learning in cybersecurity applications.

Research & Thought Leadership

  • Explore emerging techniques in machine learning, graph analytics, and AI-driven threat detection.

  • Investigate applications of graph neural networks, probabilistic modeling, and advanced analytics for cyber defense.

  • Contribute to patents, technical publications, conference presentations, and thought leadership initiatives.

  • Stay current on advancements in cybersecurity, machine learning, and adversary tradecraft to continuously evolve Illumio's detection capabilities.

Your Toolkit:

Required Qualifications

  • 5+ years of experience in security analytics, threat research, detection engineering or data science, machine learning

  • Strong Python programming skills, including experience with data science and machine learning frameworks such as Pandas, NumPy, Scikit-learn, TensorFlow, or PyTorch.

  • Experience designing, training, validating, and deploying machine learning or statistical models in production environments.

  • Proven ability to work with large-scale telemetry datasets from security, networking, cloud, or infrastructure environments.

  • Strong understanding of model evaluation, feature engineering, experimentation, and handling imbalanced datasets.

  • Experience applying analytics or machine learning techniques to cybersecurity problems such as anomaly detection, behavioral analysis, threat hunting, or risk assessment.

  • Familiarity with security frameworks such as MITRE ATT&CK and common security telemetry sources.

  • Strong SQL and data querying skills.

  • Excellent communication skills with experience translating technical findings into actionable business and product recommendations.

Preferred Qualifications

  • 7-10+ years of experience spanning cybersecurity, machine learning, data science, or threat research.

  • Experience building graph-based security analytics using Neo4j, graph databases, or graph algorithms.

  • Knowledge of graph machine learning techniques, including graph neural networks or link prediction methods.

  • Experience productionizing ML models in cloud environments using AWS, Kubernetes, or similar platforms.

  • Experience developing risk-scoring systems, recommendation engines, or predictive analytics solutions.

  • MS or PhD in Computer Science, Data Science, Machine Learning, Cybersecurity, Statistics, or a related field.

Bonus Points:
  • Background at a cybersecurity company focused on cloud security, network security, endpoint security, or threat intelligence.

  • Experience integrating external threat intelligence feeds and enrichment data into ML workflows.

  • Publications, patents, open-source contributions, or conference presentations related to security or applied machine learning.

  • Industry certifications such as CISSP, GIAC, or advanced machine learning credentials.

#LI-PO1 #LI-ONSITE

Our Commitment

Illumio believes that an environment of unique backgrounds, experiences, viewpoints, and individual contributions creates a culture of belonging, drives our future, and makes us stronger together in support of our customers and their success.

For roles in San Francisco and Los Angeles: Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Illumio will consider for employment qualified applicants with arrest and conviction records.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security ML Researcher
Staff Security ML Researcher

Illumio • San Jose (CA)

On-site
USD 180,000 - 240,000
Sr. Machine Learning Engineer
Sr. Machine Learning Engineer

Illumio • Sunnyvale (CA)

On-site
USD 120,000 - 160,000
Member of Technical Staff II, Cloud Security
Member of Technical Staff II, Cloud Security

Illumio • Sunnyvale (CA)

On-site
USD 120,000 - 180,000
Director of Engineering - Insights
Director of Engineering - Insights

Illumio • Sunnyvale (CA)

On-site
USD 150,000 - 200,000
Director, Product Management
Director, Product Management

Illumio • San Jose (CA)

On-site
USD 180,000 - 240,000
Member of Technical Staff II- Cloud Security
Member of Technical Staff II- Cloud Security

Illumio • San Jose (CA)

On-site
USD 150,000 - 190,000
Sr. Engineering Manager - Architecture
Sr. Engineering Manager - Architecture

Illumio • San Jose (CA)

On-site
USD 240,000 - 420,000
Member of Technical Staff II, Cloud Security
Member of Technical Staff II, Cloud Security

Illumio • San Jose (CA)

On-site
USD 150,000 - 210,000
Sr. Software Engineer - Cloud Security
Sr. Software Engineer - Cloud Security

Illumio • San Jose (CA)

On-site
USD 150,000 - 190,000
Director, Product Management
Director, Product Management

Illumio • Sunnyvale (CA)

On-site
USD 180,000 - 240,000