> Markdown version of [/jobs/ext/2141271-senior-ai-ml-engineer-security-log-intelligence](https://www.wearedevelopers.com/jobs/ext/2141271-senior-ai-ml-engineer-security-log-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior AI/ML Engineer, Security Log Intelligence - **Company:** RedMimicry GmbH - **Location:** Berlin, Germany - **Experience:** Expert - **Salary:** €85,000.0 - €94,000.0 - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Automated Storage and Retrieval Systems, Profiling, Cyber Security, Data Files, Information Extraction, Information Retrieval, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Machine Learning, Language Modeling, Security Log, Security Information and Event Management, Software Engineering, Pytorch, Large Language Models, Backend, Information Technology, Machine Learning Operations, Api Design - **Published:** August 20, 2026 - **Apply:** https://www.adzuna.de/details/5847197653 ## About the Role You do not need to meet every requirement to apply. We care more about demonstrated depth, sound experimental judgement, and the ability to ship reliable systems than about a specific academic title. * Machine Learning and LLM Systems * Strong Python programming skills * Practical experience with PyTorch or a comparable framework * Experience with open-weight language models, structured outputs, embeddings, or retrieval systems * Experience with fine-tuning, PEFT, quantisation, model serving, or inference optimisation * Understanding of hallucination, calibration, distribution shift, and model failure analysis * Information Retrieval and Evaluation * Semantic retrieval, ranking, classification, or information extraction * Approximate nearest-neighbour search and vector indices * Evaluation using metrics such as Recall@K, MRR, F1, exact match, calibration, and ablation studies * Dataset construction, partitioning, and reproducible benchmarking * Software Engineering * Ability to turn experimental code into maintainable production components * Testing, profiling, observability, and performance analysis * Experience working with APIs, distributed services, and containerised environments * Cybersecurity Knowledge * Security logs, SIEM, EDR, NDR, detection engineering, incident response, or threat hunting are strong advantages * Understanding of endpoint, process, identity, and network telemetry is a plus * Research Background * MSc, PhD, or equivalent practical research experience in computer science, machine learning, data science, mathematics, or a related field * Ability to read, reproduce, and critically evaluate current research * Languages * English (required) * German (a plus) ## Description * Develop Security-Log Parsing Methods: Design and implement methods for extracting typed events from heterogeneous SIEM, EDR, NDR, operating-system, and network telemetry. * Design Embeddings and Retrieval: Select, evaluate, and tune representations and retrieval methods for security events. * Handle Ambiguity Explicitly: Implement confidence scoring, calibration, and controlled treatment of ambiguous evidence. * Ground Results in Evidence: Ensure that results are supported by traceable evidence from the original telemetry. * Build Rigorous Evaluations: Define datasets, baselines, ablations, and metrics, and analyse failure modes systematically. * Optimise Inference: Make the pipeline practical for cloud operation and on-premises deployment. * Productise the Research: Work with backend, integration, and offensive-security engineers to turn experimental methods into maintainable services. * Document the Work: Produce clear experiment records, architecture decisions, and technical reports. * Contribute to Academic Research: Contribute, at minimum as a co-author, to an academic research paper published in the context of the project. ## Related Videos - [Prompt Injection, Poisoning & More: The Dark Side of LLMs](https://www.wearedevelopers.com/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [Profiling Symfony & PHP apps with Blackfire](https://www.wearedevelopers.com/videos/265-profiling-symfony-php-apps-with-blackfire) - [How AI Models Get Smarter](https://www.wearedevelopers.com/videos/1374-how-ai-models-get-smarter) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)