Cyber Threat Defense Sr AI/ML Engineer

Bank of America
Boston, MA, United States
about 1 month ago
Apply on www.bostonjobsite.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Application Integration Architecture Microsoft Azure Cyber Security Data Cleansing Information Security Management Intrusion Detection and Prevention Python (Programming Language) Machine Learning Open Source Technology Software Architecture
+20 more
Tensorflow Red Team (Cyber Security) Security Information and Event Management Google Cloud Feature Engineering Pytorch Retrieval-Augmented Generation Large Language Models Model Validation Generative AI Malware Cyber Threat Analysis Scikit Learn Information Technology HuggingFace Cybercrime Machine Learning Operations Cyber Warfare Data Pipelines Security Orchestration, Automation & Response

Job description

Bank of America’s Global Information Security (GIS) team is seeking a Cyber Threat Defense Sr AI/ML Engineer to build and integrate advanced AI and machine learning capabilities into our cyber defense ecosystem. This person will drive innovation across preventative, detective, and responsive security controls by engineering the full spectrum of intelligent automation: deterministic and scripted automation, custom machine learning models, large language models (LLMs), and agentic AI systems. This is a senior individual contributor role balancing hands-on engineering with technical leadership, working closely with leadership and engineering teams to drive AI integration into cyber defense.

This engineer will focus on applying AI to defend against modern threats, including threat actors who are themselves leveraging AI, and will partner with security subject matter experts across GIS on defending the bank’s own use of AI. The ideal candidate is an experienced AI/ML engineer with deep fundamentals in machine learning theory and practice, strong production engineering discipline, and a working understanding of cybersecurity, who knows that the right solution is sometimes a script, sometimes a model, and sometimes an agent.

Role Responsibilities

  • Design, build, and deploy AI-powered capabilities for threat hunting, anomaly detection, and automated incident response over large-scale security telemetry.
  • Develop and operationalize custom machine learning models and LLM-based workflows tailored to cybersecurity use cases, owning the lifecycle from data preparation and feature engineering through training, evaluation, deployment, and monitoring.
  • Match the technique to the problem: apply deterministic automation, classical machine learning, or generative AI (or a combination) based on the problem structure, the available data, and the operational risk profile.
  • Build LLM-based tooling that multiplies analyst effectiveness, such as investigation support, detection engineering assistance, and knowledge retrieval.
  • Partner with GIS operational and technical teams to identify opportunities for AI-driven enhancements to security controls and architecture.
  • Prototype and evaluate emerging AI technologies for applicability in cyber threat detection and response.
  • Collaborate with offensive security teams to develop AI-enhanced red teaming and adversarial emulation capabilities.
  • Contribute to architectural decisions that support scalable, well-governed AI integration across GIS security controls.
  • Promote responsible and ethical use of AI in security operations, partnering with model governance stakeholders on bias mitigation and explainability.
  • Act as a technical expert on AI-driven cybersecurity initiatives, advising senior leadership and mentoring engineers and analysts., Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.

View your “Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf) “ poster.

View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .

Requirements

  • 7+ years of hands-on machine learning engineering experience, including fine-tuning, evaluating, and deploying custom models in production.
  • Strong command of machine learning fundamentals, including model training and evaluation (model weights, loss functions, precision, recall, F1, calibration), feature engineering, embeddings, and real-world data issues such as class imbalance, label noise, and model drift. Candidates whose AI experience consists primarily of using generative AI tools, agents, or APIs will not meet this bar; candidates should expect to discuss models they have personally trained and evaluated.
  • Proficiency in Python and hands-on experience with ML frameworks such as PyTorch or scikit-learn, including model evaluation harnesses and experiment tracking.
  • Hands-on experience building LLM-powered applications and agentic AI systems (e.g., retrieval-augmented generation, fine-tuning, tool use, orchestration), grounded in the ML fundamentals above.
  • Experience delivering production systems at scale involving data pipelines, model deployment, MLOps, and automation.
  • Experience with enterprise cloud AI development platforms (e.g., Azure AI Foundry, Amazon Bedrock, Google Cloud Vertex AI) or equivalent open-source or self-hosted model infrastructure.
  • Working understanding of cybersecurity fundamentals (the attack lifecycle, common attacker techniques, and defensive controls) and of how AI can enhance defensive operations.
  • Familiarity with AI governance and model risk management concepts, such as model validation, explainability, and responsible AI.
  • Strong communication and presentation skills, including the ability to translate complex technical concepts for senior executives and cross-functional stakeholders.
  • Bachelor’s degree in computer science, a related quantitative field, or equivalent applied experience; advanced degree (MS/PhD) preferred., * Experience applying ML or AI to cybersecurity problems such as detection engineering, threat hunting, malware analysis, or security automation.
  • Experience working with security telemetry at scale (e.g., EDR, SIEM, network, or identity data).
  • Understanding of offensive security tactics and threat actor behaviors, and of how AI can enhance red teaming, attack path mapping, and threat modeling.
  • Hands-on offensive security experience (e.g., CTF competitions, red team tooling development, or published security research).
  • Experience with the open-source LLM ecosystem (e.g., Hugging Face, LangChain), LLM guardrails, and agent orchestration frameworks.
  • Familiarity with adversarial machine learning and AI security risks.
  • Experience with AI-enhanced SOAR (Security Orchestration, Automation, and Response) platforms.
  • Prior work in regulated industries, including model risk and compliance considerations in financial services.

Skills:

  • Artificial Intelligence
  • Critical Thinking
  • Threat Analysis
  • Cyber Security
  • Data Privacy and Protection
  • Data and Trend Analysis
  • Stakeholder Management

About the company

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!, Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.

This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.

Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:

Are Not FDIC Insured Are Not Bank Guaranteed May Lose Value

Are Not Deposits Are Not Insured by Any Federal Government Agency Are not a condition to Any Banking Service or Activity

Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.

Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation (“BofA Corp.”).

Bank of America Private Bank is a division of Bank of America, N.A.

Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.

© 2026 Bank of America Corporation. All rights reserved.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.bostonjobsite.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Utilizing industry threat models for AI security

Balázs Kiss · World Congress 2023

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:35 min

Preventing remote code execution in PyTorch models

Balázs Kiss · World Congress 2023

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:31 min

Dual usage of machine learning in cybersecurity

Wolfgang Ettlinger +1 · World Congress 2023

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all