What you’ll work on
- Build and deploy alert prioritization models that score incoming security alerts by severity, exploitability, and business impact.
- Develop alert clustering and grouping systems that identify similar patterns across thousands of alerts and surface them as coherent incidents.
- Train and maintain true positive / false positive classifiers that learn from analyst feedback to automatically distinguish real threats from benign activity.
- Design anomaly detection models over normalized log data to identify deviations from baseline behavior for users, assets, and network activity.
- Build feedback loop infrastructure where analyst corrections flow back into model retraining and continuously improve model accuracy.
- Develop embedding and similarity systems for matching new alerts against known attack patterns and threat intelligence.
- Create feature engineering pipelines that transform raw security logs, MITRE ATT&CK mappings, and contextual metadata into ML-ready features.
- Build evaluation and monitoring infrastructure to track model drift and performance over time.
- Support attack path analysis on the offensive platform by building models that score and rank vulnerability chains.
