OpenAI6 days ago

Data Scientist, Cybersecurity

Salary not specified
MARKET
15,900median for this role
Data Scientist · 115 jobs with disclosed pay
5,000half of the offers: 12,796–20,50043,793
The employer didn't disclose pay — compare with the market yourself.
Полная занятостьУдалёнка

Responsibilities

  • 01Define how we measure AI-agent security. Establish metrics and evaluation frameworks for security-control coverage, agent behavior, sensitive actions, access patterns, detection quality, and emerging risks
  • 02Improve security controls without introducing unnecessary friction. Quantify the effectiveness and operational costs of safeguards, including false positives, blocked actions, escalations, approval delays, and recovery paths. Help teams make controls safer, more precise, and easier to use
  • 03Build the data foundations for security decisions. Partner with engineering and data teams to improve instrumentation, connect fragmented telemetry, establish trusted datasets, and surface important coverage and data-quality gaps
  • 04Strengthen detection and response. Identify meaningful signals of anomalous behavior, risky access, sensitive-data exposure, and other security-relevant activity. Evaluate whether interventions improve detection quality, response times, and real-world security outcomes
  • 05Shape AI-powered cybersecurity products. Partner with product, engineering, and research teams to assess how effectively AI systems identify security issues, support developer and enterprise workflows, and create measurable customer value
  • 06Develop evaluation systems for security findings. Define quality measures for findings, including accuracy, severity, actionability, duplication, resolution, and downstream impact. Connect model behavior and product changes to outcomes such as triage, remediation, and vulnerability reduction
  • 07Understand the complete security workflow. Measure how users discover, investigate, validate, prioritize, and resolve security issues. Identify opportunities to improve activation, adoption, retention, and enterprise value across customer-facing cybersecurity products
  • 08Design rigorous measurement and experimentation strategies. Evaluate new models, security controls, product features, and workflows through controlled experiments, staged rollouts, observational analyses, and other methods appropriate for high-stakes environments
  • 09Translate analysis into security and product strategy. Identify the highest-value decisions, clarify tradeoffs, recommend where teams should invest, and communicate findings clearly to technical partners and senior leadership
  • 10Help establish a new security data science capability. Build a focused roadmap, create durable operating rhythms across Data Science and Security, and help shape how this discipline grows over time

Requirements

  • 015+ years of experience in data science, applied research, analytics, or a related quantitative field, with a track record of owning ambiguous, high-impact problems
  • 02Experience in cybersecurity, trust and safety, fraud or abuse prevention, privacy, platform integrity, or another domain involving adversarial behavior and difficult-to-measure risks
  • 03Strong proficiency in SQL and Python, including experience investigating complex datasets, working through incomplete instrumentation, and building reproducible analytical workflows
  • 04Experience defining meaningful metrics and evaluation frameworks when ground truth is limited, outcomes are delayed, or important risks cannot be observed directly
  • 05Strong judgment in experimentation, causal inference, observational analysis, and the practical limitations of different measurement approaches
  • 06The ability to partner effectively with security engineers, product managers, software engineers, researchers, data engineers, and senior leaders
  • 07A demonstrated ability to translate technical analysis into concrete improvements in products, systems, controls, or organizational priorities
  • 08Comfort operating independently, defining a roadmap, and bringing structure to a domain without established processes or industry standards