# Staff Security Detection Engineer, Machine Learning at SoFi

- Company: SoFi
- What the company does: Backed by IVP.
- Company website: https://www.sofi.com
- Type: Startups (AI role)
- Level: Senior
- Location: WA - Seattle; CA - San Francisco
- Work setup: On-site
- Posted: 2026-07-30
- Apply by: 2026-10-12
- Apply: https://sofi.com/careers/job/7818418003?gh_jid=7818418003
- Page: https://www.1752.vc/careers/jobs/sofi-staff-security-detection-engineer-machine-learning/

## About the role

We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning–driven detection and anomaly detection program. You will own the detection and model lifecycle end to end; feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines.

## What they're looking for

- 7+ years hands-on experience building and operating machine learning models for detection or anomaly detection in production (e.g., security, fraud, or abuse), across both supervised and unsupervised approaches
- Hands-on experience with data lake and big-data technologies (e.g., Snowflake, Databricks, Spark, Delta/Iceberg, S3/GCS) for storing, transforming, and querying large-scale security telemetry
- Strong programming and query skills in Python and SQL, with hands-on use of the ML and data stack (e.g., pandas, scikit-learn, PyTorch or TensorFlow) for feature engineering, model training, and automation
- Solid understanding of security telemetry sources, identity and access (SSO, IGA, PAM), endpoint/EDR, network/proxy, cloud (AWS/GCP/Azure), and SaaS audit logs, and how to shape them into model features
- Working knowledge of anomaly detection techniques (statistical baselining, clustering, isolation forests, autoencoders, time-series methods) and the end-to-end model lifecycle
- Familiarity with security frameworks and adversary tradecraft (MITRE ATT&CK, kill chain) and how they map to detectable behaviors and model features

Tags: Information Security
