AI & DATA ENGINEERING

ML Engineer

Develop production machine learning for security data. The work includes alert prioritisation, classification, anomaly detection and the feedback pipelines that help models improve.

Ho Chi Minh City, Vietnam (Hybrid)Full-Time5+ Years experience

What you’ll work on

  • Build and deploy alert prioritization models that score incoming security alerts by severity, exploitability, and business impact.
  • Develop alert clustering and grouping systems that identify similar patterns across thousands of alerts and surface them as coherent incidents.
  • Train and maintain true positive / false positive classifiers that learn from analyst feedback to automatically distinguish real threats from benign activity.
  • Design anomaly detection models over normalized log data to identify deviations from baseline behavior for users, assets, and network activity.
  • Build feedback loop infrastructure where analyst corrections flow back into model retraining and continuously improve model accuracy.
  • Develop embedding and similarity systems for matching new alerts against known attack patterns and threat intelligence.
  • Create feature engineering pipelines that transform raw security logs, MITRE ATT&CK mappings, and contextual metadata into ML-ready features.
  • Build evaluation and monitoring infrastructure to track model drift and performance over time.
  • Support attack path analysis on the offensive platform by building models that score and rank vulnerability chains.

What you’ll bring

  • 5+ years of applied ML engineering experience building, deploying, and maintaining models in production.
  • Strong proficiency in Python and ML libraries: scikit-learn, XGBoost, PyTorch or TensorFlow.
  • Hands-on experience with classification, clustering, and anomaly detection on structured/tabular data.
  • Experience building feature engineering and data pipelines at scale (Spark, Airflow, or similar).
  • Solid understanding of evaluation methodology (precision/recall tradeoffs, class imbalance handling, A/B testing, and drift monitoring).
  • Experience with embedding models and similarity search (vector databases, nearest-neighbor retrieval).
  • Ability to work with messy, high-volume, real-world data and write production-grade code.
  • Plus: Background in cybersecurity, fraud detection, or abuse/trust & safety.
  • Plus: Experience with SIEM data, log analytics, network telemetry, or MITRE ATT&CK framework.
  • Plus: Knowledge of graph-based ML (Graph Neural Networks, Neo4j GDS).

What’s on offer

  • Build machine-learning features used in day-to-day security work.
  • Work alongside agentic AI engineers and security domain experts.
  • Help decide what we build and how the models are designed.
  • Competitive pay, health insurance and a technical learning budget.
MORE OPEN ROLES

See where you could fit.

View all open roles