Senior AI/ML Engineer, Security Log Intelligence — Opportunihub
Job

Senior AI/ML Engineer, Security Log Intelligence

RedMimicry GmbH · Berlin

At a glance

Type
Job
Organisation
RedMimicry GmbH
Location
Berlin
Work mode
On-site
Deadline
Rolling / not stated
Posted
18 Aug 2026

About this job

<p>We are building a new capability that turns fragmented, noisy security logs into explainable, AI-powered threat analysis, delivered inside the RedMimicry platform.</p> <p>As Senior AI/ML Engineer at RedMimicry, you will lead the applied AI/ML work behind new analysis capabilities for our breach and attack emulation platform. The core challenge is extracting useful structure from heterogeneous, partially unstructured security telemetry and relating it to known attacker activity.</p> <p>The problem is broader than prompt engineering. You will determine where LLMs, embeddings, retrieval, learned ranking, and deterministic heuristics are justified. The standard is measurable improvement against reproducible baselines, not architectural fashion. Everything you build must operate under realistic latency, reliability, and deployment constraints.</p> <p>This is a fixed-term position running until 31 October 2027.</p> <h2>Tasks</h2> <ul> <li><strong>Develop Security-Log Parsing Methods:</strong> Design and implement methods for extracting typed events from heterogeneous SIEM, EDR, NDR, operating-system, and network telemetry.</li> <li><strong>Design Embeddings and Retrieval:</strong> Select, evaluate, and tune representations and retrieval methods for security events.</li> <li><strong>Handle Ambiguity Explicitly:</strong> Implement confidence scoring, calibration, and controlled treatment of ambiguous evidence.</li> <li><strong>Ground Results in Evidence:</strong> Ensure that results are supported by traceable evidence from the original telemetry.</li> <li><strong>Build Rigorous Evaluations:</strong> Define datasets, baselines, ablations, and metrics, and analyse failure modes systematically.</li> <li><strong>Optimise Inference:</strong> Make the pipeline practical for cloud operation and on-premises deployment.</li> <li><strong>Productise the Research:</strong> Work with backend, integration, and offensive-security engineers to turn experimental methods into maintainable services.</li> <li><strong>Document the Work:</strong> Produce clear experiment records, architecture decisions, and technical reports.</li> <li><strong>Contribute to Academic Research:</strong> Contribute, at minimum as a co-author, to an academic research paper published in the context of the project.</li> </ul> <h2>Requirements</h2> <p>You do not need to meet every requirement to apply. We care more about demonstrated depth, sound experimental judgement, and the ability to ship reliable systems than about a specific academic title.</p> <ul> <li> <p><strong>Machine Learning and LLM Systems</strong></p> </li> <li> <p>Strong Python programming skills</p> </li> <li> <p>Practical experience with PyTorch or a comparable framework</p> </li> <li> <p>Experience with open-weight language models, structured outputs, embeddings, or retrieval systems</p> </li> <li> <p>Experience with fine-tuning, PEFT, quantisation, model serving, or inference optimisation</p> </li> <li> <p>Understanding of hallucination, calibration, distribution shift, and model failure analysis</p> </li> <li> <p><strong>Information Retrieval and Evaluation</strong></p> </li> <li> <p>Semantic retrieval, ranking, classification, or information extraction</p> </li> <li> <p>Approximate nearest-neighbour search and vector indices</p> </li> <li> <p>Evaluation using metrics such as Recall@K, MRR, F1, exact match, calibration, and ablation studies</p> </li> <li> <p>Dataset construction, partitioning, and reproducible benchmarking</p> </li> <li> <p><strong>Software Engineering</strong></p> </li> <li> <p>Ability to turn experimental code into maintainable production components</p> </li> <li> <p>Testing, profiling, observability, and performance analysis</p> </li> <li> <p>Experience working with APIs, distributed services, and containerised environments</p> </li> <li> <p><strong>Cybersecurity Knowledge</strong></p> </li> <li> <p>Security logs, SIEM, EDR, NDR, detection engineering, incident response, or threat hunting are strong advantages</p> </li> <li> <p>Understanding of endpoint, process, identity, and network telemetry is a plus</p> </li> <li> <p><strong>Research Background</strong></p> </li> <li> <p>MSc, PhD, or equivalent practical research experience in computer science, machine learning, data science, mathematics, or a related field</p> </li> <li> <p>Ability to read, reproduce, and critically evaluate current research</p> </li> <li> <p><strong>Languages</strong></p> </li> <li> <p>English (required)</p> </li> <li> <p>German (a plus)</p> </li> </ul> <h2>Benefits</h2> <ul> <li>Work from anywhere in Germany, and use our Berlin office as often as you like</li> <li>30 days of paid time off, and a quiet inbox while you are away</li> <li>Company-paid Deutschlandticket</li> <li>Annual budget for the courses and certifications you pick yourself</li> <li>Modern tooling and extensive use of AI</li> <li>Light process, clear communication, focus on what really matters</li> </ul> <p>A close match is enough. If the role speaks to you, apply with your CV and anything else you would like us to see. What follows is short and transparent, a few conversations with the team and then your first week in Berlin. We are an equal opportunity employer and welcome applications from all backgrounds and genders. Questions about the role or the process are welcome at any point.</p> <p>Find <a href="https://www.arbeitnow.com">Jobs in Germany</a> on Arbeitnow</a>

How to apply

  1. 1 Read the full details above and confirm you meet the eligibility criteria.
  2. 2 Prepare your documents — an updated CV, and any cover letter, proposal or certificates required.
  3. 3 Click Apply on official site to complete your application on RedMimicry GmbH’s official page.
  4. 4 Submit as early as possible — many close once filled.
Apply on official site

Sourced from arbeitnow. Always verify details on the official website. Opportunihub never charges you to apply.

Frequently asked questions

How do I apply for Senior AI/ML Engineer, Security Log Intelligence?

Review the full details and eligibility on this page, prepare your documents, then use the “Apply on official site” button to complete your application on RedMimicry GmbH’s official page.

Is this opportunity remote or location-based?

This opportunity is based in Berlin. Check the official listing for any relocation or on-site requirements.

Is Senior AI/ML Engineer, Security Log Intelligence free to apply for?

Opportunihub lists this Job for free. Legitimate Jobs do not ask for payment to apply — never pay a fee to submit an application.