openqareer

Data Scientist

Punch Cyber · Удалённо · United States

# Data Scientist **Punch Cyber** · United States · `Remote` · `Full Time` 💼 **Уровень роли:** `Mid-level` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Himalayas (JSON API)* --- ### Top Skills & Match 🎯 **Ключевой стек роли:** `[Data-Scientist]` `[Machine-Learning-Engineer]` `[Principal-Cybersecurity-Data-Scientist]` `[Machine-Learning-Scientist]` `[Analytics-Engineer]` `[Data-Science-Expert]` `[Data-Science]` `[Data-Science-Specialist]` `[Data-Scientist-Analytics]` --- ### About the Role About Us: PUNCH Cyber Analytics Group (PUNCH) is a Virginia-based, small business founded in 2012 operating as a cohesive team that incorporates the sum of our group’s diverse skills, talents, and resources toward our collective passion: advancing data analytics to impact cyber operations. PUNCH is a two-time Inc. Magazine ‘Best Workplaces’ awardee offering unique benefits and personal touches to provide a positive work-life experience for our team. PUNCH brings unique qualifications, resources, and past-performance that make us suitable to address the goals of our diverse customer-base. Further, we have past and current experience supporting cyber operations and cyber ML-based research, with well over 100 years of collective experience from our collaborative, multi-disciplinary team. Responsibilities - Develop and evaluate machine-learning analytics for cyber defense use cases using network, sensor, alert, asset, and other operational telemetry. - Build unsupervised and statistical models for clustering, anomaly/outlier detection, behavioral baselining, novelty detection, and pattern discovery. - Apply techniques such as graph analytics/embeddings, nearest-neighbor methods, time-series or periodicity analysis, clustering, dimensionality reduction, and anomaly scoring to large cyber datasets. - Design models and features that account for concept drift, noisy data, incomplete ground truth, and high false-positive rates common in operational cyber environments. - Support asset discovery and entity resolution, including development of probabilistic asset graphs that associate IPs, hostnames, MAC addresses, services, certificates, device attributes, and other observations across data sources. - Develop contextual features from security alerts and network telemetry, including temporal patterns, rarity/frequency, communication behavior, entity context, and related activity, and use those features to identify meaningful alert clusters and outliers. - Work with cyber analysts and detection engineers to turn operational questions and adversary behaviors into measurable features, experiments, and analytics. - Evaluate model effectiveness using appropriate quantitative metrics and operational validation; benchmark accuracy, false-positive behavior, computational performance, and usefulness to analysts. - Develop production-quality Python code and work with engineers to integrate models into sensor-side CPU environments as well as larger GPU-enabled enterprise analytics platforms. - Understand the practical strengths and limitations of LLMs: know when to use an LLM, when to use conventional ML/statistics, and when a deterministic rule or query is the better answer. - Ability to build evaluation harnesses rather than judge AI output by vibes—test datasets, expected behaviors, regression tests, failure cases, and quantitative measures. Qualifications - BS or MS in Data Science, Computer Science, Statistics, Applied Mathematics, Engineering, Cybersecurity, or a related quantitative discipline. - Strong Python skills and hands-on experience with common scientific/ML tooling such as pandas, NumPy, scikit-learn, SciPy, and related libraries. - Strong understanding of unsupervised machine learning, including clustering, anomaly/outlier detection, similarity/distance methods, feature engineering, and statistical baselining. - Experience with at least some of the following: graph analytics or graph ML, entity resolution/record linkage, probabilistic modeling, time-series analysis, change-point/concept-drift detection, nearest-neighbor methods, or dimensionality reduction. - Experience working with large, noisy, heterogeneous datasets where labels or authoritative ground truth are limited. - Familiarity with scalable data processing and efficient model implementation; comfortable thinking about CPU/memory constraints as well as GPU acceleration for larger workloads. - Working knowledge of networking and cybersecurity concepts such as IP addressing, DNS, TLS, network flows, ports/services, routing, network devices, and security alerts. - Experience with cyber/network telemetry such as Zeek, PCAP-derived data, SIEM data, IDS/IPS alerts, device configuration data, or vulnerability/asset data is highly desirable. - Experience with graph/network-analysis libraries, SQL/data stores, Elasticsearch/Splunk, or similar analytic platforms is a plus. - Experience developing analytics for cybersecurity, threat hunting, detection engineering, or defensive cyber operations is strongly preferred. Originally posted on Himalayas

Наблюдалась 2026-10-10, впервые 2026-10-10, источник — Himalayas (JSON API).

Открыть у работодателя