Dragos Logo

Dragos

Senior AI/ML Engineer

Reposted Yesterday
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Design, build, and deploy production-grade ML systems for ICS/xOT cybersecurity, including threat detection, anomaly detection, NLP/LLM applications, and scalable data pipelines with observability and MLOps practices for cloud and on-prem environments.
The summary above was generated by AI

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role 

We're looking for a Machine Learning Application Engineer to join our Engineering team. This role sits at the intersection of data engineering and applied ML. You'll be taking existing model types and putting them to work inside our product and data pipelines. You won't be training models from scratch or managing ML infrastructure, but you will be doing the thoughtful applied work of figuring out which techniques fit which problems, wiring them into our workflows, and making sure the outputs are reliable and useful. 

You'll work closely with AI Engineers, Data Engineers, and product teams to bring ML-driven capabilities into the Dragos platform. Things like clustering network behaviors, classifying assets, and surfacing anomalies that matter for ICS/OT security analysts. 

Responsibilities 

  • Apply clustering, classification, anomaly detection, and other established ML techniques to cybersecurity data problems in the ICS/OT domain.
  • Integrate ML model outputs into existing data pipelines and product workflows, supporting both batch and near-real-time processing patterns.
  • Understand model behavior and translate research outputs into reliable pipeline components.
  • Work with Data Engineers to ensure ML-driven stages of the pipeline have clear data contracts, appropriate observability, and sane failure modes.
  • Evaluate open-source and third-party models for fit against specific use cases,  knowing when to apply an existing tool versus when to escalate to a model-building effort.
  • Write clean, maintainable Python or Rust that other engineers can reason about, test, and extend.
  • Troubleshoot ML component behavior in production to diagnose issues with output quality, data drift, or unexpected edge cases.
  • Communicate clearly about what a model is doing, where it's uncertain, and how its outputs should (and shouldn't) be used downstream. 

Qualifications 

  • 5+ years of software engineering experience, with meaningful time spent working with ML outputs or data pipelines in a production context.
  • Strong Python skills; SQL proficiency; comfort reading and reasoning about data at scale.
  • Hands-on experience applying ML techniques including clustering (k-means, DBSCAN, hierarchical), classification, and anomaly detection. Familiarity with scikit-learn and the surrounding Python ML ecosystem; you don't need to have implemented a neural net, but you should know how to use one responsibly.
  • Solid understanding of data pipeline concepts: how data flows, where it gets transformed, what can go wrong, and how to make failures visible.
  • Ability to evaluate whether a model's outputs are actually trustworthy for a given use case — not just whether accuracy metrics look good.
  • Strong written and verbal communication; comfortable explaining tradeoffs to both technical and non-technical stakeholders.
  • Cybersecurity domain knowledge — especially around threat detection, network behavior, or ICS/OT operations is a meaningful plus, but not a prerequisite. 

Nice to Have 

  • Experience working with graph-based representations of network topology or asset relationships.
  • Familiarity with stream processing or event-driven architectures.
  • Exposure to containerized environments (Docker, Kubernetes) as a consumer/deployer, not necessarily an operator. 

Compensation: 

  • Salary:  $190,000
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

 



#LI-NH1 #LI-REMOTE 


Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Similar Jobs at Dragos

2 Hours Ago
Remote
Senior level
Senior level
Security • Cybersecurity
Lead and manage an adversary hunting team focused on OT threat groups. Perform hands-on hunting using Synapse and Storm Query Language, produce WorldView reports and detection artifacts, collaborate with intelligence and malware analysis, refine KPIs, support incident response surges, recruit and develop staff, and represent the team externally.
Top Skills: CensysDiamond ModelIcs Cyber Kill ChainJoe SandboxMitre Att&Ck For IcsNetflowShodanStorm Query LanguageSynapseVirustotalYara
Yesterday
Remote
Senior level
Senior level
Security • Cybersecurity
Hunt, identify, and analyze adversary tools, malware, and tradecraft targeting ICS/OT. Develop and maintain analysis tools and scripts, contribute to threat assessments and customer advisories, leverage intel and network analysis tools, recommend automation and telemetry improvements, and support incident response and external communications.
Top Skills: C#CensysDiamond ModelJoe SandboxKill ChainMitre Att&CkNetflowPythonShodanStorm Query LanguageSynapseVirustotal
Yesterday
Remote
Senior level
Senior level
Security • Cybersecurity
Design, build, and deploy production ML systems for ICS/xOT cybersecurity, including threat detection, anomaly detection, NLP/LLM features, data pipelines, observability, MLOps, and containerized deployments across cloud and on-prem environments.
Top Skills: Ci/CdCloud-Native ArchitecturesContainerized DeploymentDockerGoHuggingfaceJavaJvmKubernetesLlmsMessage QueuingMlflow (Or Similar)Model VersioningNlpPipeline OrchestrationPythonPyTorchRagRustScikit-LearnSQLStream ProcessingTensorFlow

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account