Startups

Senior Data Scientist

Empirical Security · Remote · Remote

← All jobs
About Empirical Security

Backed by Costanoa Ventures.

About the role

You own models and data end to end: problem framing, features, training, evaluation, deployment, and the uncomfortable part where you explain to a customer why the vulnerability their board is worried about ranked 400th on the remediation list. Design, train, and ship exploit prediction models against ground-truth exploitation telemetry, in cloud, appsec, and traditional infrastructure. Found on 1752vc Careers, the job board for startup and VC roles.

What they're looking for

  • Several years of applied machine learning or statistics with models that ran in production and had consequences when they were wrong
  • Fluency in Python and SQL, and the discipline that comes with version control, reproducible pipelines, and secure handling of customer data
  • Real depth in classification under heavy imbalance, plus at least one of: survival and time-to-event analysis, Bayesian hierarchical modeling, or causal inference
  • Calibration instincts. You should be visibly uncomfortable when a model outputs 0.9 and is right 60% of the time
  • The ability to explain a model to a security executive, and to quantify uncertainty out loud rather than burying it in an appendix
  • Enough curiosity about attacker behavior to ask why a feature works, not just whether it does
More about this role

Empirical Security is seeking an experienced Security Data Scientist focused on building the next generation of cybersecurity vulnerability models. Our unique approach leverages ground-truth telemetry to develop predictive, actionable insights that transform the way organizations identify, prioritize, and remediate vulnerabilities in cloud, appsec and traditional environments. We build models specific to individual customers, and maintain many of them side by side.

You own models and data end to end: problem framing, features, training, evaluation, deployment, and the uncomfortable part where you explain to a customer why the vulnerability their board is worried about ranked 400th on the remediation list.

Design, train, and ship exploit prediction models against ground-truth exploitation telemetry, in cloud, appsec, and traditional infrastructure.

Build evaluation that survives contact with reality. Precision, recall, coverage, efficiency, calibration, and how all four decay over time. Accuracy is not a number you report once at launch.

Solve for extreme class imbalance. A fraction of a percent of published CVEs are ever exploited in the wild, and most of the industry's modeling...

Read the full posting on Empirical Security's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.