> Markdown version of [/jobs/ext/2718025-staff-principal-ai-ml-engineer-threat-detection-engineering](https://www.wearedevelopers.com/jobs/ext/2718025-staff-principal-ai-ml-engineer-threat-detection-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff/Principal AI/ML Engineer - Threat Detection Engineering - **Company:** AppGate Cybersecurity, Inc. - **Location:** New York, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Apache HTTP Server, Artificial Neural Networks, Audit Trail, Continuous Integration, Information Leak Prevention, Data Security, Monitoring of Systems, Identity and Access Management, Intrusion Detection and Prevention, Machine Learning, Zero Trust Network Access, Session Management, Data Streaming, Parquet, Network Access Control, Delivery Pipeline, Large Language Models, Mitre Att&ck, Deep Learning, Kubernetes, Apache Flink, Apache Kafka, Spark Streaming, Machine Learning Operations, Virtual Agents - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-staff-principal-ai-ml-engineer-threat-detection-engineering-appgate-cybersecurity-inc-8240667 ## About the Role * 7+ years of production AI/ML engineering experience, with a strong preference for candidates who have built threat detection, UEBA, ITDR, or identity security platforms at leading security or cloud companies. * Detection algorithm expertise: Hands-on experience designing detections for identity-based threats - credential compromise, privilege escalation, insider activity, behavioral anomalies, and data exfiltration. * MLOps & Productionization: Experience building and operating scalable MLOps platforms for AI/ML systems, including model lifecycle management, CI/CD for ML pipelines, feature stores, automated retraining, model monitoring/drift detection, experiment tracking, and deployment orchestration using Kubernetes, MLflow, Kubeflow, SageMaker, or equivalent tooling in high-throughput production environments. * ML proficiency: Experience building AI-powered security systems using large language models, deep learning, and agentic AI techniques for threat detection, anomaly analysis, contextual investigation, and intelligent remediation. * Data & streaming engineering: Real-time or near-real-time pipeline experience (Kafka, Flink, Spark Streaming, or equivalent); familiarity with lakehouse formats (Apache Iceberg, Parquet). * Security domain knowledge: MITRE ATT&CK, identity threat kill chains, ZTNA or network access control systems, and audit log analysis. * Bonus: Experience with detection-as-code frameworks (Sigma, YARA), ZTNA platforms, LLMs or GNNs applied to security, or publications at USENIX, CCS, NeurIPS, or ICML. * Mindset: Mission-driven, production-focused, signal-obsessed. You measure precision and recall, you eliminate alert fatigue, and you care that your work protects real systems. ## Description We're looking for a AI/ML Engineer (Senior/Staff/Principal) - Threat Detection who will design, build, and operationalize the detection algorithms, ML inference pipelines, and risk aggregation systems that power our autonomous threat detection platform. You'll work at the intersection of identity security, behavioral analytics, and applied machine learning - building production systems that analyze ZTNA audit logs in near real-time, surface high-fidelity threat signals, and feed into our Risk Sentinel enforcement engine to continuously harden access decisions. Key Responsibilities * Your engineering work will directly enable next-generation capabilities, including: * Threat Detection Engine: Build advanced detections to identify threats early, including identity compromise, privilege escalation, impossible travel, and data exfiltration across identity, network, device, and session telemetry. * ML Anomaly Detection: Production models using Isolation Forest, One-Class SVM, and Autoencoder neural networks to surface behavioral outliers that rules miss. * Risk Aggregation & Enforcement: Design/develop accurate and explainable risk scoring systems that continuously normalize and correlate detection signals into dynamic user, device, and session risk scores that directly drive adaptive access enforcement decisions. * Real-Time Detection Pipeline: Build scalable, low-latency streaming pipelines that process ZTNA events in near real time, enabling resilient, high-throughput security analytics. * AI Agent Security: Define and implement security controls for autonomous AI agents, including detection of agent drift, unauthorized resource access, prompt injection attacks, privilege escalation, data leakage, and other emerging threats in Agentic AI systems. * Autonomous Remediation (Roadmap): Leverage agentic AI to automate threat investigation, contextual analysis, and remediation workflows, enabling intelligent containment and response for high-confidence security incidents. * Design and implement detection algorithms spanning authentication, authorization, network/location, data access, session management, and temporal behavioral domains. * Train, evaluate, and deploy ML models on real-world identity and network telemetry; tune for production precision and recall targets. * Architect and operate the detection pipeline - from audit log ingestion through risk aggregation and Risk Sentinel integration. * Define the detection taxonomy - categorizing, prioritizing, and lifecycle-managing the full detection library using a scalable detection family model. * Instrument and improve signal quality - measuring MTTD, false positive rates, and MITRE ATT&CK coverage; partnering with red teams to validate detections against real attack scenarios. * Collaborate cross-functionally with security, product, and platform engineering to align detection coverage with customer threat models and roadmap priorities. ## Related Videos - [Hack Me If You Can: Designing Unbreakable LLM Guardrails](https://www.wearedevelopers.com/videos/100209-hack-me-if-you-can-designing-unbreakable-llm-guardrails) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Parquet, Delta, Iceberg & Ducklake - An introduction for developers](https://www.wearedevelopers.com/videos/100075-parquet-delta-iceberg-ducklake-an-introduction-for-developers) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development)