Data scientist lead
Job Summary
LEAD DATA SCIENTIST
Security Knowledge Graphs & Cyber AI
Role Level | Lead | Experience | 10 years overall; 5 years in AI/ML or graph analytics |
Location | Flexible / Hybrid | Employment Type | Full-time |
Role Purpose
Lead the design engineering and operationalization of enterprise Security Knowledge Graphs that connect security telemetry assets identities vulnerabilities threats controls and incidents into a trusted intelligence layer. The role is highly hands-on and combines data science graph engineering cybersecurity analytics semantic modeling and technical leadership to enable attack-path analysis threat investigation exposure prioritization GraphRAG and AI-assisted security operations.
Key Responsibilities
Design the Security Knowledge Graph architecture ontology taxonomy entity model relationship model provenance model and lifecycle standards.
Build production-grade graph ingestion and transformation pipelines for SIEM EDR/XDR IAM/PAM CMDB vulnerability scanners cloud security platforms threat intelligence feeds security data lakes and case-management systems.
Develop entity extraction identity resolution deduplication schema mapping relationship inference confidence scoring temporal modeling and graph enrichment capabilities.
Model assets applications users service accounts privileges vulnerabilities misconfigurations controls alerts incidents indicators threat actors campaigns tactics techniques and procedures.
Implement graph analytics for attack paths blast radius privilege escalation lateral movement toxic combinations identity exposure control gaps and vulnerability prioritization.
Build and evaluate graph algorithms and ML models including centrality community detection similarity anomaly detection node classification link prediction embeddings and Graph Neural Networks.
Design GraphRAG and knowledge-grounded security assistants that combine graph traversal vector retrieval structured evidence LLM reasoning citations and human approval controls.
Partner with SOC threat intelligence IAM vulnerability management cloud security architecture data engineering and product teams to convert operational problems into reusable graph-powered capabilities.
Own technical design reviews coding standards model validation observability performance tuning security controls documentation and production-readiness gates.
Mentor data scientists and engineers while remaining accountable for prototypes reference implementations critical code troubleshooting and complex customer or stakeholder demonstrations.
Mandatory Hands-on Technical Skills
Knowledge graphs: Ontology and semantic model design; property graphs and RDF; graph schema evolution; knowledge representation; provenance; graph quality; entity and relationship resolution.
Graph platforms: Deep implementation experience with Neo4j and Cypher; working knowledge of at least one additional platform such as Amazon Neptune TigerGraph Azure Cosmos DB Gremlin ArangoDB or JanusGraph.
Graph data science: Neo4j Graph Data Science NetworkX PyTorch Geometric or DGL; graph embeddings pathfinding similarity clustering link prediction node classification anomaly detection and GNN development.
Programming and engineering: Advanced Python and SQL; APIs; test automation; data structures; distributed processing; Git; CI/CD; containers; infrastructure awareness; production debugging and performance optimization.
Data engineering: Spark or Databricks Kafka or equivalent streaming ETL/ELT batch and real-time pipelines data contracts lineage cataloguing quality rules and scalable cloud storage.
Cybersecurity: SOC workflows threat hunting incident response detection engineering vulnerability and exposure management IAM/PAM Zero Trust cloud security and security control mapping.
Security standards: Practical use of MITRE ATT&CK STIX/TAXII CVE CWE CAPEC NIST frameworks CIS Controls and common threat-intelligence vocabularies.
GenAI and GraphRAG: LLM-based extraction retrieval orchestration agent/tool integration prompt design evaluation grounding guardrails explainability and evidence traceability.
MLOps and observability: Experiment tracking model versioning deployment monitoring drift and quality checks auditability access controls secrets management and cost/performance management.
Security Knowledge Graph Engineering Expectations
Create canonical entity and relationship definitions with stable identifiers temporal context source lineage evidence attributes confidence scores and access-control classifications.
Develop reusable connectors and parsers for structured semi-structured and unstructured security sour Required Skills: infrastructure