SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Detection Engineer, Machine Learning

SoFi - Seattle, WA, USA - Hybrid - posted 2026-07-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SoFi is seeking a Staff Security Detection Engineer to design, build, and operationalize machine learning models for security anomaly detection and threat identification at scale. This is a high-impact individual contributor role focused on the full detection and model lifecycle: feature engineering, model training, tuning, validation, and production deployment across large-scale security data lakes and streaming pipelines. You will own end-to-end responsibility for building unsupervised and supervised ML models (clustering, time-series baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets. Key responsibilities include operationalizing models from notebook to production with CI/CD, model versioning, and rollback; engineering features from identity, endpoint, network, cloud, and SaaS telemetry; and establishing model governance including drift monitoring, retraining, and explainability controls. You'll partner closely with the Security Operations Center (SOC), Security Operations Engineering, and Fraud teams to translate threat hypotheses into repeatable, model-backed analytics. You'll participate in root-cause and post-incident reviews to identify coverage gaps, mentor engineers and analysts on applied ML and anomaly detection, and contribute to reference architectures and standards for the ML detection platform. Required: 7+ years hands-on experience building and operating ML models for detection/anomaly detection in production (security, fraud, or abuse); expertise with data lake technologies (Snowflake, Databricks, Spark, Delta/Iceberg); strong Python and SQL skills with ML stack experience (pandas, scikit-learn, PyTorch, TensorFlow); solid understanding of security telemetry sources and anomaly detection techniques; familiarity with MITRE ATT&CK and adversary tradecraft; experience collaborating with SOC/DFIR and fraud teams; metrics-driven mindset; Bachelor's in CS, data science, statistics, or equivalent. Nice to have: streaming/real-time data engineering (Kafka, Kinesis, Spark Streaming); AWS ML experience (SageMaker, Glue, Athena); MLOps practices (feature stores, model registries, experiment tracking).

Similar roles