Security ML - Principal Data Scientist


At Elastic, we see endless possibility in a world of endless data. And we use the power of search to help people and organizations turn that possibility into results. Elastic is the leading platform for search-powered solutions. With solutions in Enterprise Search, Observability, and Security, we help improve customer and employee search experiences, keep critical applications running smoothly, and protect against cyber threats. Elastic enables organizations worldwide to use the power of Elastic, including Netflix, Uber, BBC, Microsoft, and thousands of others.

Elastic was built on a foundation of being free and open, which trickles down to how we work. We’re a distributed organization and have been from the beginning. Being distributed isn’t just a way of doing business—it’s a mentality that is at the core of our culture.

The Elastic Security Machine Learning team is looking for a Principal Data Scientist to lead the maturation of our malware detection models across Windows, macOS, and Linux endpoints. You will work closely with ML Engineers and Data Scientists to identify model blindspots, detect drift patterns, and confidently label never-before-seen samples.

We need a self-starter who is ready to dig into volumes of data to better answer:

  • How does model performance change over time?
  • How do you tune a model to detect malicious activity at an extremely small base rate?
  • What categories of software is the model incorrectly classifying?
  • How do we ensure reproducible results in an inherently adversarial environment?

If you are ready to solve these challenges and more, we look forward to hearing from you!

What you will be doing

Your primary focus will be to mature our malware protection capability by 

  • Gathering implicit and explicit feedback from the platform to continually improve models
  • Develop strategies to label unknown samples from production environments confidently
  • Determine sampling strategies to maximize our dataset during training
  • Gain a deep understanding of XGBoost parameters to tune models
  • Monitor model performance to identify model blindspots and propose new features
  • Help define and communicate Go/No-go metrics for model release
  • Lead a quarterly FP/FN retrospective
  • Support Elastic Security in third-party evaluations of Malware Protection models

What you will bring along

  • 4+ years of machine learning experience
  • Experience training models using XGBoost
  • Experience using or developing ML pipelines, including the collection, normalization, storage, and API access of complex event data
  • Proficient Python programming skills
  • Ability to synthesize evaluation metrics, customer feedback, and internal analysis to communicate model performance
  • Support production models as a subject matter expert
  • Enthusiasm for providing novel contributions to the information security research community on machine learning techniques

Bonus Points

  • Malware or security background
  • Experience with PyTorch or Tensorflow frameworks
  • Experience with any part of the Elastic stack

Additional Information - We Take Care of Our People

As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.

We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.

  • Competitive pay based on the work you do here and not your previous salary
  • Health coverage for you and your family in many locations
  • Ability to craft your calendar with flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Double your charitable giving - We match up to $1500 (or local currency equivalent)
  • Up to 40 hours each year to use toward volunteer projects you love
  • Embracing parenthood with minimum of 16 weeks of parental leave

The typical starting Total Cash Compensation range for new hires in this role is between $152,200 and $209,300, which consists of a Base Salary or a Base Salary plus a Target Commission, depending on the specific role. The Base Salary offered may vary depending on factors including skills and experience.

Additionally, this role is currently eligible to participate in Elastic’s equity plan as well as a range of health & wellbeing, retirement savings, and other benefits within a holistic total rewards offering.

Different people approach problems differently. We need that. Elastic is committed to diversity as well as inclusion. We are an equal opportunity employer and committed to the principles of affirmative action. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status or any other basis protected by federal, state or local law, ordinance or regulation. If you require any reasonable accessibility support, please email

Applicants have rights under Federal Employment Laws, view posters linked below:
Family and Medical Leave Act (FMLA) Poster; Equal Employment Opportunity (EEO) Poster; and Employee Polygraph Protection Act (EPPA) Poster.

Please see here for our Privacy Statement.

Learn about Elastic's Culture

Notify Me of Open Positions

Sign in with your social account to receive emails when Elastic posts open positions you might be interested in:

Powered By Ongig