We are seeking a highly skilled Senior Machine Learning Engineer (5+ Years of Experience) to serve as the Core Technical Owner of our Operational Technology Network Intrusion Detection System (NIDS). In this pivotal role, you will lead the transformation of massive streams of semi-structured network telemetry(primarily JSON) into real-time, actionable security intelligence. You will design and deploy ML pipelines that effectively distinguish between cyber threats and physical equipment anomalies, ensuring maximum uptime and zero-trust safety for our industrial clients.
The candidate will have responsibilities across the following functions:
Advanced ML Pipeline and Data Engineering:
- High-Performance Telemetry Ingestion: Design optimised parsers and data pipelines to ingest, flatten, and feature-engineer complex, nested JSON network packets and industrial protocol payloads at scale.
- Model Development: Build, train, and validate unsupervised anomaly detection, time-series forecasting, and deep learning architectures optimised for zero-day threat detection.
- Differentiated Classification: Architect algorithms capable of cleanly separating Security Incidents (e. g., lateral movement, unauthorised commands) from Operational Anomalies (e. g., PLC misconfiguration, equipment drift, packet drops).
AI Innovation and Feature Engineering:
- Explainable AI (XAI): Integrate frameworks like SHAP or LIME into the alerting engine to ensure OT operators receive transparent, human-readable Root Cause Analysis (RCA).
- Automated Asset Discovery: Deploy clustering techniques to fingerprint, profile, and inventory all network assets automatically based on traffic metadata patterns.
- Predictive Maintenance: Leverage historical telemetry to predict physical network switch failures and bandwidth congestion before they disrupt operations.
- Smart Policy Synthesis: Utilise traffic flow analytics to automatically recommend zero-trust firewall configurations and micro-segmentation policies.
Production Deployment and MLOps:
- Edge Deployment: Containerise and deploy resource-efficient models (using Docker/Kubernetescapable of running seamlessly at the industrial edge or centralised cloud.
- Robust MLOps: Establish robust MLOps practices using tools like MLflow, Weights and Biases, or Kubeflow to track model drift, concept drift, and performance degradation in dynamic environments.
Requirements:
- 5+ yearsof professional experience actively building, scaling, and productionizing machine learning systems.
- Programming: Expert-level Python, including core data stacks (NumPy, Pandas, Scikit-Learn).
- Deep Learning: Hands-on experience building custom architectures using PyTorch or TensorFlow.
- Data Engineering: Deep familiarity handling massive, nested JSON datasets. Experience with stream-processing (Apache Kafka, Spark, Flink) is required.
- Security/OT: Understanding of networking (TCP/IP, OSI model, PCAP). Familiarity with OT protocols (Modbus, DNP3 BACnet, PROFINET) is a massive plus.
- Modelling: Proven track record withUnsupervised/Semi-Supervisedarchitectures (Isolation Forests, Autoencoders, GNNs).
Preferred Qualifications:
- Must have a deep understanding of MLOps pipelines and optimisation tools for edge computing (e. g., ONNX, TensorRT).
- Good to have prior experience building Network Intrusion Detection Systems (NIDS) or working in Cybersecurity/SIEM product development.
- Advanced Degree: Bachelor's, Master's, or PhD in Computer Science, Data Science, Cybersecurity, or a related quantitative field.

