Staff Security Detection Engineer, Machine Learning
$144k - $247.5kSoFi
Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
The role:
We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning–driven detection and anomaly detection program. You will own the detection and model lifecycle end to end; feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines. You’ll partner closely with our Security Operations Center (SOC), Security Operations Engineering, and Fraud programs to turn high-volume telemetry into high-confidence, low-noise detections at scale.
What you’ll do:
- Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets.
- Operationalize models and detections from notebook to production, including enrichment, correlation, and response playbook hooks (detection-as-code, CI/CD, model versioning, and rollback).
- Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality.
- Partner with the SOC to triage, tune, and close detection feedback loops; use analyst dispositions as labels to retrain and improve models, reduce noise, and document runbooks.
- Collaborate with Threat Intelligence, Security Architecture, and Fraud stakeholders to translate threat hypotheses and scenarios into repeatable, model-backed analytics with clear success metrics.
- Establish model governance: offline and online evaluation, drift and data-quality monitoring, periodic retraining and re-baselining, explainability/traceability, and privacy-by-design controls.
- Participate in root-cause and post-incident reviews to identify new signals, features, and coverage gaps; backlog and deliver the resulting models and detections.
- Contribute to reference architectures, standards, and documentation for the ML detection platform, data lake, and pipelines across the security organization.
- Mentor engineers and analysts on applied ML, anomaly detection, detection tuning, data quality, and pipeline reliability.
What you’ll need:
- 7+ years hands-on experience building and operating machine learning models for detection or anomaly detection in production (e.g., security, fraud, or abuse), across both supervised and unsupervised approaches.
- Hands-on experience with data lake and big-data technologies (e.g., Snowflake, Databricks, Spark, Delta/Iceberg, S3/GCS) for storing, transforming, and querying large-scale security telemetry.
- Strong programming and query skills in Python and SQL, with hands-on use of the ML and data stack (e.g., pandas, scikit-learn, PyTorch or TensorFlow) for feature engineering, model training, and automation.
- Solid understanding of security telemetry sources; identity and access (SSO, IGA, PAM), endpoint/EDR, network/proxy, cloud (AWS/GCP/Azure), and SaaS audit logs, and how to shape them into model features.
- Working knowledge of anomaly detection techniques (statistical baselining, clustering, isolation forests, autoencoders, time-series methods) and the end-to-end model lifecycle.
- Familiarity with security frameworks and adversary tradecraft (MITRE ATT&CK, kill chain) and how they map to detectable behaviors and model features.
- Experience collaborating with SOC/DFIR and fraud/risk teams; excellent written communication for models, detections, runbooks, and stakeholder updates.
- Ability to balance detection coverage, model precision, and operational load; metrics-driven mindset (precision/recall, false-positive rate, MTTD, alert fatigue).
- Bachelor’s degree in computer science, data science, statistics, a related field, or equivalent practical experience.
Nice to have:
- Experience with streaming and real-time data engineering (e.g., Kafka, Kinesis, Pub/Sub, Flink, Spark Streaming) for near-real-time model scoring.
- Experience building and deploying ML models on AWS (e.g., SageMaker, S3, Glue, Athena, Lambda) for training, feature pipelines, and inference.
- MLOps practices – feature stores, model registries, experiment tracking, canary and shadow releases for reliable model deployment and retraining.
- Graph-based ML and analytics for entity relationships, risk propagation, and community detection.
- Experience applying deep learning or LLM-based approaches to security, log, or sequence data.
- Experience leveraging LLMs to design, analyze, and test detections.
- Relevant certifications (e.g., AWS/GCP machine learning or data engineering, Databricks, or equivalent).
Compensation and Benefits
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location.
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email View email address on aiapply.co.
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Internal Employees
If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.
- .... Join us to invest in yourself, your career, and the financial world.The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning-driven detection and anomaly detection program. You will own the detection and model lifecycle end...SuggestedRemote work
$146.3k - $257.7k
...future of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's... ...gym, massage/chiropractor, personal training, etc.Learning and development stipendCompany-wide off-sites and team...SuggestedFull timeWork at officeLocal area$293k - $385k
...benefits all of humanity.The Security organization protects... ...is seeking a Security Engineer, Host Assurance to... ...systems such as machine identity, certificate... ...claims and continuously detect and manage drift over... ...disability coverageAnnual learning and development stipend...SuggestedWork at officeLocal areaRelocation packageFlexible hours$237.6k - $297k
We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the... ..., dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally...SuggestedFull time$122.5k - $165k
...-scale financial innovation. Learn more at circle.com.What you’ll... ...responsible for:The Circle Security Team works to protect Circle;... ...visibility through logging and detection.Respond to incidents and... ...detection, response, or security engineering.Experience working security incidents...SuggestedWork experience placementFlexible hoursShift workNight shift$293k - $385k
...intelligence benefits all of humanity.The Security team protects OpenAI’s technology,... ...security culture.About the RoleAs a Security Engineer on Detection & Response, you’ll help protect OpenAI... ...life and disability coverageAnnual learning and development stipend to fuel your...Work at officeLocal areaRemote workFlexible hours$208k - $312k
...from idea to production with speed, security, and exceptional developer experience... ...the Role:We are looking for a Security Engineer to join our Detection Response team. In this role, you will... ...equity.Inclusive Healthcare Package.Learn and Grow - we provide mentorship and...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hoursShift work- ...solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize,... ..., inclusion, respect, and accountability.Senior Security Engineer, Detection and ResponseRemote Location: Austin TX, Seattle, WA,...ApprenticeshipLocal areaRemote workFlexible hoursShift work
$230k - $260k
...foundational to everything we build.We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows we use to... ...at Notion.You’ll work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude to identify gaps, prioritize...Local area$204k - $280.5k
...power of tech, data, and machine learning to connect this thriving community... ...this roleThe Enterprise Security team at Faire owns the... ...s scope includes endpoint detection, data loss prevention,... ...and AI governance. As our Staff Security Engineer focusing on Enterprise AI,...Work experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week$220k
...with deep expertise in AI and machine learning. Our platform is perfecting... ..., and Craft Ventures.The Security Team @ PaveSecurity at Pave... ...As Pave's Corporate Security Engineer, you'll own the corporate side... ...built internal apps: publish detection, automated review checks,...Work at officeFlexible hours3 days per week$174.5k - $240k
...re using the power of tech, data, and machine learning to connect this thriving community of... ...the role:As a Senior Enterprise Security Engineer, you will help protect Faire's corporate... ...misuse.Support and help run our endpoint detection and response platform, email security...Work experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week$146.3k - $257.7k
...the roleThis is where security meets innovation at enterprise... ...scale. As a security engineer, applications at... ...open to Mid, Sr. and Staff level candidates Benefits... ...planning supportEarly-detection cancer testing through... ...training, etc.Learning and development stipendCompany...Full timeWork at officeLocal area$180k - $240k
...build the foundation for agent engineering in the real world, helping... ...Bridgewater.About the TeamThe Security team ensures that while AI moves... ...roleYou'll be the hands-on detection and response engineer... ...responsible for how we see, stop, and learn from threats across LangChain...Work at officeFlexible hours$122.5k - $165k
...Salary: $122,500 - 165,000 per year Requirements: We expect at least 2 years of experience in detection, incident response, or security engineering. We look for experience handling security incidents, especially those with an engineering component. We require...Full timeRemote workFlexible hoursNight shift$180k - $247k
Secure Every Identity, from AI to HumanIdentity... ...belongs to you.The Staff Product Security Engineer OpportunityThe Security... ...(scripts, scanners, detection logic, or evaluation... ...and policies. To learn more about our Total... ...artificial intelligence, machine learning, or other...Local areaWorldwideFlexible hours$123.7k - $254.67k
...recruiting process here.Pinterest is seeking an experienced Security Engineer to build and implement detection and response improvements and adapt to emerging... ...for relocation assistance. Visit our PinFlex page to learn more about our working model.#LI-REMOTE#LI-JT1At...Work at officeLocal areaRemote workRelocationRelocation package$113.03k - $140k
...wallet that simplifies how individuals securely prove their identity online. Consumers... ...to have a secure digital identity. To learn more, visit ID.me is a full-time, in-... ...Role Summary We are seeking a Threat Detection Engineer to join our security engineering and operations...Full timeTemporary workWork experience placementWork at officeRemote workFlexible hoursShift work$165k - $239k
...Security Software Engineer Hover helps people design, improve, and protect the properties they... ...authentication and automating vulnerability detection. Our mission is to make the best... ...like managing rich geospatial and machine learning workloads, hardening cloud...Full timeFor contractorsWork at officeLocal areaFlexible hours$180k - $258k
...backed by best-in-class data science (and, soon, a dash of machine learning) to automate much of this complexity so healthcare... ...written by our founders. The RoleWe're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems...Flexible hours$200k - $330k
...for Google Workspace. What you'll doLead Security for Our Platform. Take charge of... ...Functional Teams. Partner closely with engineering, product, and GRC to embed security throughout... ...especially those leveraging AI/ML for detection or monitoring.Familiarity with...Full timeFlexible hours$134k - $205k
....We’re looking for a Senior Corporate Security Engineer to help secure the systems, identities... ...building, testing, and tuning custom detection logic and familiarity with Query Languages... ...you invest in your future.Education & learning stipend for personal growth and...Remote workWork from homeFlexible hours$123.7k - $254.67k
...experience. We need strong expertise in intrusion detection and incident response, with an engineering mindset in a modern cloud-first environment. We... ...understanding of networking technologies and network security, including TCP/IP fundamentals. We prefer depth in...Full timeRemote workRelocation packageFlexible hours$148k - $203.5k
Secure Every Identity, from AI to HumanIdentity is the... ...too, let's talk.The Staff Order-to-Cash AnalystOkta... ...manual reconciliation, detect anomalies in O2C and revenue... ...plans and policies. To learn more about our Total... ...intelligence, machine learning, or other automated...Contract workLocal areaWorldwideFlexible hours$105.4k - $207.8k
...and Resilience, you will help deliver security engineering solutions that modernize client security operations across monitoring, detection, response, and automation. In this... ...technologiesExperience applying artificial intelligence, machine learning, or large language model workflows to...Local areaVisa sponsorship- ...platforms, or workflows you use today.ROLE OVERVIEWAs an Enterprise Security Engineer at Benchling you’ll be joining a team responsible for... ...third-party integration accessBuild processes and tooling to detect shadow IT, unauthorized OAuth app grants, and SaaS tools that...Work at officeLocal areaFlexible hours3 days per week
$232k - $290k
...real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be... ...AI.Build and scale Ripple's Shadow AI detection capability, surfacing unsanctioned AI... ...environment with experienced industry leadersA learning environment where you can dive deep...Full timeWork at officeLocal area$275k - $300k
...and Nexus Venture Partners. Learn more at postman.com or connect... ...About the TeamThe Information Security organization at Postman... ...Principal Offensive Security Engineer who is as much a strategist as... ...internal red team playbooks and detection hypotheses for Security Operations...Work at officeFlexible hours3 days per week$134k - $184.8k
Secure Every Identity, from AI to HumanIdentity is the... ...) organization is the engine that powers Okta's global... ...do their best work.The Staff Security Engineer... ...plans and policies. To learn more about our Total Rewards... ...intelligence, machine learning, or other automated...Local areaWorldwideFlexible hoursShift work- Saviynt is searching for a strategic Staff Product Manager to drive the Identity Threat Detection and Response (ITDR) initiative. This role requires a visionary leader to define product strategy and roadmap, ensuring adaptive defenses against identity-centric attacks....
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Detection Engineer, Machine Learning. Be the first to apply!
- assistant engineering manager San Francisco, CA
- assistant civil engineer San Francisco, CA
- assistant mechanical engineer San Francisco, CA
- assistant engineer San Francisco, CA
- staff engineer San Francisco, CA
- staff data engineer San Francisco, CA
- software engineer staff San Francisco, CA
- assistant electrical engineer San Francisco, CA
- staff design engineer San Francisco, CA
- senior staff engineer San Francisco, CA


