Staff Security Detection Engineer, Machine Learning

SoFi

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Seattle, WASan Francisco, CA
Salary
$144,000–$247,500 / yr
Posted
43 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $202k
This role $196k
$132k most similar roles pay here $260k

This role pays less than 53% of similar roles. Most pay $161,250–$241,750 — the shaded band above. At the midpoint, this role pays about $196k versus about $202k for comparable roles.

Based on 240 similar postings.

Employer

About SoFi

SoFi Technologies is a fintech company offering student and personal loans, mortgages, credit cards, investing, banking, and insurance products, positioning itself as a one-stop financial services platform. Industry: Financial Technology & Personal Finance

SoFi currently has 17 open roles on FindRole.

Listed pay typically runs $156,800–$247,500 across 17 roles with salary data.

Most-posted roles

View all roles at SoFi

At a glance

TL;DR · Staff Security Detection Engineer, Machine Learning

As a Staff Security Detection Engineer, Machine Learning, you will join the security team to build and mature a machine learning-driven detection and anomaly detection program. You will own the end-to-end model lifecycle, including feature engineering, training, tuning, and validation across large-scale security data lakes and streaming pipelines. Your daily work involves designing models for unsupervised clustering, time-series baselines, isolation forests, and autoencoders to transform high-volume telemetry into high-confidence detections. You will utilize Python, SQL, Spark, Snowflake, Databricks, and the PyTorch or TensorFlow stacks to process identity, endpoint, network, cloud, and SaaS logs. By collaborating with SOC and Fraud teams, you will translate threat hypotheses into model-backed analytics while managing MLOps practices like model versioning and drift monitoring to solve complex security and fraud detection challenges within a high-scale data environment.

What you'll do

  • Design and maintain machine learning models for anomaly detection using techniques like clustering, time-series baselines, and autoencoders.
  • Operationalize models from development to production using detection-as-code, CI/CD pipelines, and automated response hooks.
  • Engineer and tune features from identity, endpoint, network, cloud, and application telemetry to improve model signal quality.
  • Partner with the SOC to triage detections, create feedback loops, and use analyst data to retrain models.
  • Translate threat intelligence and fraud scenarios into repeatable, model-backed analytics with measurable precision and recall targets.
  • Establish model governance including drift monitoring, data quality checks, and explainability controls.
  • Participate in post-incident reviews to identify new signals and address coverage gaps in the detection pipeline.
  • Mentor engineers and analysts on applied machine learning, data quality, and detection tuning.

What we're looking for

  • Bachelor’s degree in computer science, data science, statistics, or a related field.
  • 7+ years of experience building and operating machine learning models for detection or anomaly detection in production.
  • Proficiency in Python and SQL using ML and data stacks like pandas, scikit-learn, PyTorch, or TensorFlow.
  • Experience with big-data technologies such as Snowflake, Databricks, Spark, Delta/Iceberg, S3, or GCS.
  • Knowledge of anomaly detection techniques including statistical baselining, clustering, isolation forests, autoencoders, and time-series methods.
  • Understanding of security telemetry sources across identity, endpoint, network, cloud, and SaaS platforms.
  • Familiarity with security frameworks and adversary tradecraft such as MITRE ATT&CK or the kill chain.
  • Ability to communicate complex models, detections, and runbooks effectively to technical and non-technical stakeholders.

More like this

Similar roles

Security Engineer (Detection Engineering)

SpaceX

Redmond, WA 49 days ago $130,000$155,000
Python Go C++ Rust Kubernetes SIEM ETL Incident Response Automation Linux Windows macOS Security Operations Detection Engineering

Senior Security Engineer, Cloud Threat Detection

The Hartford

Hartford, CT +3 23 days ago $128,400$192,600
AWS GCP Splunk SIEM Python PowerShell Bash MITRE ATT&CK SOAR CloudTrail GuardDuty CrowdStrike Wiz Orca SentinelOne Microsoft Defender XDR Identity and Access Management (IAM)
5+ yrs exp Hybrid

Senior ML Engineer

Salesforce

Remote (Bellevue, WA) 11 days ago $148,500$223,900
Python Apache Kafka Flink Ray Spark PySpark MLOps CI/CD Docker Kubernetes Apache Airflow Feature Stores Graph Analytics Supervised Learning Anomaly Detection Clustering MITRE ATT&CK OCSF
3+ yrs exp Remote

Security Data Solutions Engineer

State Street

Quincy, MA +4 37 days ago $120,000$202,500
Python SQL Spark Kafka Databricks Snowflake Splunk Microsoft Sentinel QRadar Elastic Cribl OpenTelemetry FluentBit AWS Azure Google Cloud ETL ELT DevSecOps NIST CSF MITRE ATT&CK
8+ yrs exp Hybrid

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 72 days ago $90,000$154,000
Incident Response Sentinel Defender Azure Kubernetes Python Mitre Att&ck Automation Detection Engineering
4+ yrs exp

Staff Security Engineer, Detection & Response

Robinhood

Bellevue, WA +2 112 days ago $217,000$255,000
Incident Response Detection Engineering Kubernetes SOAR AI Threat Hunting Threat Intelligence Vulnerability Management Blockchain DeFi
8+ yrs exp Hybrid