Staff Security Detection Engineer, Machine Learning
Job description
About the role
SoFi is seeking a Staff Security Detection Engineer to define and execute the machine learning strategy for detection and anomaly detection across the security organization. In this role, you will own the detection and model lifecycle end to end, from initial hypothesis through feature engineering, model training, tuning, validation, and production operations over large-scale security data lakes and streaming pipelines. You will partner closely with our Security Operations Center (SOC), Security Operations Engineering, and Fraud programs to transform high-volume telemetry into high-confidence, low-noise detections that scale. The ideal candidate will bring a strong bias for action, a commitment to scientific rigor in model evaluation, and a passion for mentoring others to elevate the entire security engineering organization. Join us to invest in yourself, your career, and the future of financial services security.
Key facts
What you'll do
Design, build, and maintain machine learning models for anomaly detection, including unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, and risk scoring, with measurable precision and recall targets.
Operationalize models and detections from notebook to production, implementing detection-as-code, CI/CD pipelines, model versioning, and rollback mechanisms to ensure reliability and reproducibility.
Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality and reduce false positives.
Partner with the Security Operations Center (SOC) to triage alerts, tune detection parameters, and close detection feedback loops, using analyst dispositions as labels to retrain and improve models.
Collaborate with Threat Intelligence, Security Architecture, and Fraud stakeholders to translate threat hypotheses and scenarios into repeatable, model-backed analytics with clear success metrics and defined outcomes.
Establish model governance practices, including offline and online evaluation, drift and data-quality monitoring, periodic retraining and re-baselining, explainability and traceability, and privacy-by-design controls.
Participate in root-cause and post-incident reviews to identify new signals, features, and coverage gaps; translate findings into backlog items and deliver the resulting models and detections on an agile schedule.
Contribute to reference architectures, standards, and documentation for the ML detection platform, data lake, and pipelines across the security organization to ensure consistency and scalability.
Mentor engineers and analysts on applied ML, anomaly detection techniques, detection tuning, data quality, and pipeline reliability to foster a culture of continuous improvement.
Requirements
Demonstrate 7+ years of hands-on experience building and operating machine learning models for detection or anomaly detection in production environments, spanning both supervised and unsupervised approaches.
Possess hands-on experience with data lake and big-data technologies such as Snowflake, Databricks, Spark, Delta or Iceberg, and object stores like S3 or GCS for storing, transforming, and querying large-scale security telemetry.
Show strong programming and query skills in Python and SQL, with hands-on usage of the ML and data stack including pandas, scikit-learn, and frameworks such as PyTorch or TensorFlow for feature engineering, model training, and automation.
Exhibit a solid understanding of security telemetry sources, including identity and access management (SSO, IGA, PAM), endpoint and EDR, network and proxy, cloud platforms such as AWS, GCP, and Azure, and SaaS audit logs, and how to shape these sources into effective model features.
Maintain a working knowledge of anomaly detection techniques such as statistical baselining, clustering, isolation forests, autoencoders, and time-series methods, as well as the end-to-end model lifecycle from experimentation to deployment.
Demonstrate familiarity with security frameworks and adversary tradecraft, including MITRE ATT&CK, the kill chain, and how these map to detectable behaviors and model features.
Bring experience collaborating with SOC and DFIR teams, incident response, threat hunting, and digital forensics to ensure that models are aligned with real-world investigative workflows.
Illustrate experience with security visualization and query languages such as KQL or similar to explore data and validate detection logic during investigation and tuning.
Practical notes
The role is based in the United States and requires authorization to work in the country. Candidates must be able to commute to one of the following office locations: Washington (Seattle, WA) or California (San Francisco, CA). This role is not eligible for remote work arrangements. Travel is not required for this position. The work location and schedule are subject to change to meet business needs. All employment is subject to SoFi's background check and drug screening policies. SoFi is an Equal Opportunity Employer.