Full Time

Staff Security ML Researcher

Illumio Sunnyvale, CA
Match score ---
Confidence ---

Role snapshot

Compensation $221,000 - $265,000
Location Sunnyvale, CA

Technologies

Certifications

Ready to apply?

Review the details above and continue to the employer's site to start your application.

Job description

Onwards Together!

Illumio is the leader in ransomware and breach containment, redefining how organizations contain cyberattacks and enable operational resilience. Powered by the Illumio AI Security Graph, our breach containment platform identifies and contains threats across hybrid multi-cloud environments – stopping the spread of attacks before they become disasters.

Recognized as a Leader in the Forrester Wave™ for Microsegmentation, Illumio enables Zero Trust, strengthening cyber resilience for the infrastructure, systems, and organizations that keep the world running.

Location: 4 on-site days a week in Sunnyvale, CA Headquarters.

Our Team's Vision:

The Office of the CTO and Security team sets the strategic technical direction of the company while keeping both Illumio and our customers secure. Those who join us represent the leader in Zero Trust Segmentation and maintain Illumio’s competitive advantage by exploring new technologies while collaborating with Engineering and Product Management.

We are looking for people who leverage differences and push the pace of innovation in a time when the world faces its greatest cybersecurity threats in history.   

About the Role

We're seeking a Staff Security ML Researcher to develop machine learning-driven approaches for threat detection, risk assessment, and security analytics. In this role, you'll apply advanced statistical methods, machine learning, and graph-based analysis to identify threats, model attacker behavior, and quantify cyber risk across complex enterprise environments.

Working at the intersection of cybersecurity, machine learning, and product innovation, you'll partner with threat researchers, engineers, and product teams to transform large-scale security data into intelligent models, actionable insights, and customer-facing capabilities that help organizations better understand and reduce cyber risk.


Your Impact:

Machine Learning & Security Intelligence

  • Design, develop, and deploy machine learning models that identify anomalous behavior, detect threats, and predict security risk across complex enterprise environments.

  • Apply statistical techniques and predictive modeling to evaluate breach likelihood, attack exposure, and segmentation effectiveness.

  • Build behavioral profiling, anomaly detection, clustering, classification, and forecasting models using large-scale security telemetry.

  • Evaluate model performance, reduce false positives, and continuously improve detection quality through experimentation and data-driven analysis.

Threat Research & Risk Modeling

  • Analyze large-scale security datasets to identify attacker behaviors, emerging threats, and patterns aligned to frameworks such as MITRE ATT&CK.

  • Develop threat scoring and risk assessment models that help customers prioritize remediation and security investments.

  • Leverage graph-based analysis techniques to model attack paths, quantify lateral movement risk, and recommend mitigation strategies.

  • Work closely with threat researchers to transform security intelligence into measurable detection and prediction capabilities.

Data Science & Analytics Engineering

  • Design and maintain scalable data pipelines used for model training, validation, and analytics.

  • Investigate new features, signals, and telemetry sources to improve detection accuracy and risk predictions.

  • Partner with engineers to productionize models and analytics systems while ensuring scalability, reliability, and observability.

  • Conduct experiments and hypothesis-driven analysis to validate new detection approaches and security insights.

Product Collaboration & Innovation

  • Collaborate with product managers, designers, and engineers to embed ML-driven security insights into customer-facing experiences.

  • Influence product strategy through data-backed recommendations and threat intelligence findings.

  • Help define security analytics frameworks, data requirements, and detection methodologies for future product capabilities.

  • Serve as a subject matter expert on the use of machine learning in cybersecurity applications.

Research & Thought Leadership

  • Explore emerging techniques in machine learning, graph analytics, and AI-driven threat detection.

  • Investigate applications of graph neural networks, probabilistic modeling, and advanced analytics for cyber defense.

  • Contribute to patents, technical publications, conference presentations, and thought leadership initiatives.

  • Stay current on advancements in cybersecurity, machine learning, and adversary tradecraft to continuously evolve Illumio's detection capabilities.

Your Toolkit:

Required Qualifications

  • 5+ years of experience in security analytics, threat research, detection engineering or data science, machine learning

  • Strong Python programming skills, including experience with data science and machine learning frameworks such as Pandas, NumPy, Scikit-learn, TensorFlow, or PyTorch.

  • Experience designing, training, validating, and deploying machine learning or statistical models in production environments.

  • Proven ability to work with large-scale telemetry datasets from security, networking, cloud, or infrastructure environments.

  • Strong understanding of model evaluation, feature engineering, experimentation, and handling imbalanced datasets.

  • Experience applying analytics or machine learning techniques to cybersecurity problems such as anomaly detection, behavioral analysis, threat hunting, or risk assessment.

  • Familiarity with security frameworks such as MITRE ATT&CK and common security telemetry sources.

  • Strong SQL and data querying skills.

  • Excellent communication skills with experience translating technical findings into actionable business and product recommendations.

Preferred Qualifications

  • 7-10+ years of experience spanning cybersecurity, machine learning, data science, or threat research.

  • Experience building graph-based security analytics using Neo4j, graph databases, or graph algorithms.

  • Knowledge of graph machine learning techniques, including graph neural networks or link prediction methods.

  • Experience productionizing ML models in cloud environments using AWS, Kubernetes, or similar platforms.

  • Experience developing risk-scoring systems, recommendation engines, or predictive analytics solutions.

  • MS or PhD in Computer Science, Data Science, Machine Learning, Cybersecurity, Statistics, or a related field.

Bonus Points:

  • Background at a cybersecurity company focused on cloud security, network security, endpoint security, or threat intelligence.

  • Experience integrating external threat intelligence feeds and enrichment data into ML workflows.

  • Publications, patents, open-source contributions, or conference presentations related to security or applied machine learning.

  • Industry certifications such as CISSP, GIAC, or advanced machine learning credentials.

 

#LI-PO1 #LI-ONSITE

Our Commitment

Illumio believes that an environment of unique backgrounds, experiences, viewpoints, and individual contributions creates a culture of belonging, drives our future, and makes us stronger together in support of our customers and their success.

All official job offers from our company are extended directly by our recruitment team and will be sent through an official E-Signature document for your review and signature. Please be aware that we do not ask for any personal information in the process of extending offers of employment, such as financial details or social security numbers. Upon acceptance of any offer, we will request such information as part of the onboarding process prior to or on your first day of employment, and only after completing a background check through an authorized third-party vendor. If you receive any communication asking for personal details outside of these processes, please contact us immediately to verify the authenticity of the request. Your security is important to us, and we are committed to a safe and transparent hiring experience.

For roles in San Francisco and Los Angeles: Pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Illumio will consider for employment qualified applicants with arrest and conviction records.