Senior Machine Learning Engineer, Cybersecurity / Threat Detection
Role overview
You will tackle one of the most critical challenges in cybersecurity: detecting threats within privileged access sessions with high accuracy and low latency. Privileged accounts are prime targets for attackers, and the ML systems you build will serve as a first line of defense against anomalous and malicious behavior across SSH, RDP, VNC, and database connections. This role focuses on a hybrid detection approach combining vision-language models (VLMs) and domain-adapted ML models. You will work in a Python-based environment processing real-time session data via WebSocket, WebRTC, and protocol-level interfaces. The role is well-suited for engineers who enjoy both research-oriented work (datasets, evaluation, model training) and applied production engineering (inference systems, integration, and optimization).
Responsibilities
- check_circle Design, curate, and maintain datasets for training and evaluating threat detection models
- check_circle Build custom ML models for domain-specific threat classification and risk assessment
- check_circle Engineer and optimize prompts for vision-language models to analyze session behavior
- check_circle Create evaluation frameworks and benchmarks to measure accuracy, robustness, and reliability
- check_circle Develop Python-based inference services within Dockerized environments
- check_circle Integrate AI/ML capabilities with WebSocket, WebRTC, and low-level system interfaces for real-time analysis
- check_circle Write clean, maintainable code and produce clear technical documentation
- check_circle Monitor, troubleshoot, and optimize models in production for performance, scalability, and reliability
Basic qualifications
- 5+ years of professional experience in machine learning research or development
- Strong proficiency in Python
- Hands-on experience with dataset collection, curation, and labeling for ML training
- Experience designing model evaluation frameworks and performance benchmarks
- Experience working with vision-language models or large language models (e.g., GPT, Claude, Gemini, Qwen)
- Familiarity with prompt engineering techniques and LLM frameworks
- Experience building and deploying ML inference systems using Docker
- Working knowledge of graph data structures and their practical applications
- Familiarity with Git-based workflows and model repositories (e.g., Hugging Face)
- Experience using cloud platforms for ML deployment and inference (AWS, GCP, and/or Azure)
- Bachelor’s or Master’s degree in Computer Science, Machine Learning, Cybersecurity, or equivalent practical experience
- U.S. Person status required due to GovCloud involvement
- Experience with security, fraud, abuse detection, or anomaly detection systems
- Familiarity with PAM, identity, or privileged access environments
- Exposure to AWS Bedrock or similar managed AI services
- Knowledge of network protocols and low-level system interfaces
Benefits
- check_circle Medical, Dental & Vision (Inclusive of domestic partnerships)
- check_circle Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
- check_circle Voluntary Short/Long Term Disability Insurance
- check_circle 401k (Roth/Traditional)
- check_circle A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
- check_circle Above market annual bonuses
- check_circle Data We Collect
- check_circle Contact details, CV/resume, cover letter
- check_circle Employment history, qualifications, work eligibility
- check_circle Application responses and uploaded documents
- check_circle Interview notes, assessments, communications
- check_circle Scheduling information
- check_circle Recruiter/referral information who submit your profile
- check_circle References (with your consent, before final offer)
- check_circle Public professional profiles
- check_circle Background verification (post offer)
- check_circle We may ask you to voluntarily provide diversity information including race/ethnicity, gender, disability status and veteran status (US). Providing this information is optional and Keeper collects this data in order to comply with EEOC and similar requirements
- check_circle How We Use Your Data
- check_circle Assess your application and suitability
- check_circle Manage interviews and recruitment workflow
- check_circle Consider you for other/future roles (we may seek your consent to keep your information on our systems beyond the retention period specified)
- check_circle Comply with employment law obligations
- check_circle Legal Basis
- check_circle Legitimate Interests (recruitment management, security and integrity of the hiring process)
- check_circle Contracting steps (for progressed candidates)
- check_circle Legal and regulatory compliance obligations; explicit consent where required
- check_circle Who We Share Information With
- check_circle HR, hiring managers, interviewers*, IT support for system administration
- check_circle Note - diversity and equal opportunity data is not shared with hiring managers.
- check_circle Applicant tracking, recruitment systems and assessment providers
- check_circle Background verification vendors (post offer)
- check_circle Recruitment agencies (where applicable)
- check_circle Tools to support communication, collaboration and to securely store your data
- check_circle International Transfers
- check_circle Security
- check_circle Retention
- check_circle You opt into our talent database for further retention by providing consent (extended retention)
- check_circle You're hired (transfers to employee records)
- check_circle Your Rights
- check_circle Access, correct, or delete your data, subject to applicable law and retention requirements
- check_circle Object to or restrict processing
- check_circle Withdraw consent (where applicable)
- check_circle Request data portability
- check_circle Lodge a complaint with your data protection authority
- check_circle Automated Decisions
- check_circle Contact - Candidates can send privacy questions to: [email protected]
About the company
Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our award-winning, zero-trust, privileged access management platform deploys in minutes and seamlessly integrates with any tech stack and identity application to provide visibility, security, control, reporting and compliance across an entire enterprise. Trusted by millions of individuals and thousands of organizations, Keeper is an innovator of best-in-class password management, secrets management, privileged access, secure remote access and encrypted messaging. Learn more at KeeperSecurity.com.