> Markdown version of [/jobs/ext/45972-senior-machine-learning-engineer-security](https://www.wearedevelopers.com/jobs/ext/45972-senior-machine-learning-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Machine Learning Engineer (Security) - **Company:** Proton - **Location:** Paris, France - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Airflow, Computer Networks, Data Cleansing, Information Engineering, Information Leak Prevention, Data Security, Elasticsearch, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Machine Learning, NumPy, Redis, Tensorflow, Security Information and Event Management, Data Processing, Large Language Models, Prompt Engineering, Deep Learning, Pandas, Storage Technologies, Apache Kafka, Machine Learning Operations, Vertica, Data Pipelines, Security Orchestration, Automation & Response - **Published:** May 30, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=771060edbeff76ea ## About the Role Do you have experience in VPN?, + Proven experience in machine learning engineering or data science, ideally in a cybersecurity or operations context. + Proficiency in Python, with strong knowledge of ML frameworks. + Experience with data manipulation and analysis using Pandas, NumPy or similar tools. + Familiarity with security data sources (e.g., SIEM logs, EDR telemetry, network flow, authentication logs). + Solid understanding of ML lifecycle: data preparation, model training, evaluation, deployment, and monitoring. + Experience with data pipelines and storage technologies (e.g., Airflow, Kafka, Redis, Elasticsearch, Clickhouse, etc.). + Ability to work independently and collaborate effectively with both ML and security specialists. Preferred + Prior experience in threat detection, SOC operations, or security automation. + Knowledge of adversarial ML, graph analytics, or behavioral modeling in security contexts. + Experience integrating ML models into SIEM pipelines or automated detection frameworks. + Exposure to LLMs and AI engineering (e.g., prompt engineering, RAG, agent design), and awareness of LLM-specific risks like prompt injection and data leakage. ## Description The Security Machine Learning Engineer will play a key role in transforming our Security Operations Center (SOC) from reactive to proactive by integrating advanced machine learning and data-driven approaches into our detection and response workflows. This role bridges traditional cybersecurity operations and modern ML-driven analytics, enabling our team to automatically identify emerging threats, anomalous behaviour, and new attack patterns at scale. As a secondary focus, the role could also leverage LLMs and AI engineering to automate analyst workflows and reduce operational toil. The engineer will sit directly within the security team, ensuring that the solutions built are operationally relevant, and aligned with our security priorities, while also working closely with the internal Machine Learning team (MSA) to leverage their expertise and best practices. What you will do: * ML-Driven Detection & Automation + Design, develop, and deploy machine learning models to enhance security detection, anomaly identification, and incident response. + Integrate ML outputs into the SOC workflow to enable smarter and faster triage. + Continuously evaluate and tune models to reduce false positives and improve detection precision. + Ensure model outputs are interpretable and actionable for SOC analysts. Data Engineering for Security + Build and maintain data pipelines to collect, process, and transform security-relevant data (e.g., logs, network traffic, endpoint events) into ML-ready datasets. + Collaborate with security engineering team to ensure scalable and secure data handling (eg. parsing, processing, storage). AI Engineering & LLM-Powered Automation + Explore and build LLM-powered tools to automate repetitive SOC tasks (e.g., alert triage, evidence gathering, incident summarisation, report generation). + Apply appropriate guardrails and evaluation to ensure outputs are accurate, auditable, and safe to act on in operational contexts. Research & Innovation + Stay current on advancements in security data science, adversarial ML, and automated threat detection. + Prototype and test new ML and AI techniques (e.g., unsupervised anomaly detection, graph-based threat correlation). + Contribute to improving detection content through statistical analysis and clustering. Operations & Maintenance + Deploy models into production securely and responsibly, ensuring reliability and scalability. + Implement monitoring, alerting, and retraining mechanisms for deployed ML models. + Document methodologies and performance metrics for auditability and knowledge sharing., + SOC analysts leverage ML-powered detections to identify threats faster. + Reduction in alert fatigue and false positives through adaptive and data-driven models. + Strong collaboration established between the security and MSA ML teams, sharing expertise and best practices. + Security data becomes more accessible, structured, and usable for analytical and predictive use cases. + New, intelligent detections, enrichment, and incident response automations become part of the SOC's standard toolkit. ## Related Videos - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Vectorize all the things! Using linear algebra and NumPy to make your Python code lightning fast.](https://www.wearedevelopers.com/videos/562-vectorize-all-the-things-using-linear-algebra-and-numpy-to-make-your-python-code-lightning-fast) - [Advanced Typing in TypeScript](https://www.wearedevelopers.com/videos/496-advanced-typing-in-typescript) - [Machine Learning: Promising, but Perilous](https://www.wearedevelopers.com/videos/627-machine-learning-promising-but-perilous) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [Prompt Injection, Poisoning & More: The Dark Side of LLMs](https://www.wearedevelopers.com/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [How machine learning can help us tell fact from fiction](https://www.wearedevelopers.com/magazine/509-how-machine-learning-can-help-us-tell-fact-from-fiction) - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)