Logo for CISPA Helmholtz Center for Information Security

Senior Data Scientist

Role overview

Qualifications

  • Several years of applied machine learning or statistics with models that ran in production
  • Fluency in Python and SQL
  • Real depth in classification under heavy imbalance
  • Calibration instincts

Responsibilities

  • Design, train, and ship exploit prediction models against ground-truth exploitation telemetry
  • Build evaluation that survives contact with reality including precision, recall, coverage, efficiency, and calibration
  • Solve for extreme class imbalance
  • Own monitoring and drift detection and publish methodologies and findings

About the company

CISPA Helmholtz Center for Information Security logo

CISPA Helmholtz Center for Information Security

The CISPA Helmholtz Center for Information Security is a German national Big Science Institution within the Helmholtz Association. We research information security in all its facets. Our researchers conduct cutting-edge foundational research as well as innovative application-oriented research. Our work tackles pressing challenges in cybersecurity, artificial intelligence and data privacy. CISPA research findings find their way into industrial applications and products that are available worldwide. This enables us to strengthen Germany‘s and Europe‘s competitiveness. We also promote talent and are a training ground for excellently skilled specialists and managers for the industry. In this way, we also transfer our know-how forward into the future.

Company details

Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Empirical Security is seeking an experienced Security Data Scientist focused on building the next generation of cybersecurity vulnerability models. Our unique approach leverages ground-truth telemetry to develop predictive, actionable insights that transform the way organizations identify, prioritize, and remediate vulnerabilities in cloud, appsec and traditional environments. We build models specific to individual customers, and maintain many of them side by side.

 

The role

You own models and data end to end: problem framing, features, training, evaluation, deployment, and the uncomfortable part where you explain to a customer why the vulnerability their board is worried about ranked 400th on the remediation list.

What you'll do

  • Design, train, and ship exploit prediction models against ground-truth exploitation telemetry, in cloud, appsec, and traditional infrastructure.

  • Build evaluation that survives contact with reality. Precision, recall, coverage, efficiency, calibration, and how all four decay over time. Accuracy is not a number you report once at launch.

  • Solve for extreme class imbalance. A fraction of a percent of published CVEs are ever exploited in the wild, and most of the industry's modeling failures start with pretending that isn't true.

  • Work the hard part of the dual-model architecture: partial pooling, hierarchical priors, and cold-start behavior for customers whose local telemetry is thin in month one and rich in month twelve.

  • Engineer features across scanner output, EDR, asset inventory, identity, cloud posture, and exploitation telemetry, and be honest about which ones are leakage.

  • Own monitoring and drift detection.

  • Publish. Papers, methodology write-ups, open benchmarks, conference talks. Our positioning is that we show our work.

  • Partner with engineering and our forward deployed team to move models out of notebooks and into production systems that customers depend on.

What you'll need

  • Several years of applied machine learning or statistics with models that ran in production and had consequences when they were wrong.

  • Fluency in Python and SQL, and the discipline that comes with version control, reproducible pipelines, and secure handling of customer data.

  • Real depth in classification under heavy imbalance, plus at least one of: survival and time-to-event analysis, Bayesian hierarchical modeling, or causal inference.

  • Calibration instincts. You should be visibly uncomfortable when a model outputs 0.9 and is right 60% of the time.

  • The ability to explain a model to a security executive, and to quantify uncertainty out loud rather than burying it in an appendix.

  • Enough curiosity about attacker behavior to ask why a feature works, not just whether it does.

A Final Word

Don't check off every box in the requirements listed above? Please apply anyway! Studies have shown that marginalized communities - such as women, LGBTQ+ and people of color - are less likely to apply to jobs unless they meet every single qualification. Empirical Security is dedicated to building an inclusive, diverse, equitable, and accessible workplace that fosters a sense of belonging – so if you're excited about this role but your past experience doesn't align perfectly with every qualification in the job description, we encourage you to still consider submitting an application. You may be just the right candidate for this role or another one of our openings!

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Data Scientist Related jobs

Other jobs at CISPA Helmholtz Center for Information Security

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.