Data Scientist
- 🇺🇸 United States
- Remote
- 5 hours ago
- Machine Learning
- Mac
- Temporal
- Python
- AI
- Pandas
- NumPy
- scikit-learn
- SciPy
- DNS
- TLS
- Zeek
- SIEM
- SQL
- Elasticsearch
- Splunk
About Us:
PUNCH Cyber Analytics Group (PUNCH) is a Virginia-based, small business founded in 2012 operating as a cohesive team that incorporates the sum of our group’s diverse skills, talents, and resources toward our collective passion: advancing data analytics to impact cyber operations. PUNCH is a two-time Inc. Magazine ‘Best Workplaces’ awardee offering unique benefits and personal touches to provide a positive work-life experience for our team. PUNCH brings unique qualifications, resources, and past-performance that make us suitable to address the goals of our diverse customer-base. Further, we have past and current experience supporting cyber operations and cyber ML-based research, with well over 100 years of collective experience from our collaborative, multi-disciplinary team.Â
Responsibilities
- Develop and evaluate machine-learning analytics for cyber defense use cases using network, sensor, alert, asset, and other operational telemetry.
- Build unsupervised and statistical models for clustering, anomaly/outlier detection, behavioral baselining, novelty detection, and pattern discovery.
- Apply techniques such as graph analytics/embeddings, nearest-neighbor methods, time-series or periodicity analysis, clustering, dimensionality reduction, and anomaly scoring to large cyber datasets.Â
- Design models and features that account for concept drift, noisy data, incomplete ground truth, and high false-positive rates common in operational cyber environments.
- Support asset discovery and entity resolution, including development of probabilistic asset graphs that associate IPs, hostnames, MAC addresses, services, certificates, device attributes, and other observations across data sources.Â
- Develop contextual features from security alerts and network telemetry, including temporal patterns, rarity/frequency, communication behavior, entity context, and related activity, and use those features to identify meaningful alert clusters and outliers.Â
- Work with cyber analysts and detection engineers to turn operational questions and adversary behaviors into measurable features, experiments, and analytics.
- Evaluate model effectiveness using appropriate quantitative metrics and operational validation; benchmark accuracy, false-positive behavior, computational performance, and usefulness to analysts.
- Develop production-quality Python code and work with engineers to integrate models into sensor-side CPU environments as well as larger GPU-enabled enterprise analytics platforms.
- Understand the practical strengths and limitations of LLMs: know when to use an LLM, when to use conventional ML/statistics, and when a deterministic rule or query is the better answer.
- Ability to build evaluation harnesses rather than judge AI output by vibes—test datasets, expected behaviors, regression tests, failure cases, and quantitative measures.
Qualifications
- BS or MS in Data Science, Computer Science, Statistics, Applied Mathematics, Engineering, Cybersecurity, or a related quantitative discipline.
- Strong Python skills and hands-on experience with common scientific/ML tooling such as pandas, NumPy, scikit-learn, SciPy, and related libraries.
- Strong understanding of unsupervised machine learning, including clustering, anomaly/outlier detection, similarity/distance methods, feature engineering, and statistical baselining.
- Experience with at least some of the following: graph analytics or graph ML, entity resolution/record linkage, probabilistic modeling, time-series analysis, change-point/concept-drift detection, nearest-neighbor methods, or dimensionality reduction.
- Experience working with large, noisy, heterogeneous datasets where labels or authoritative ground truth are limited.
- Familiarity with scalable data processing and efficient model implementation; comfortable thinking about CPU/memory constraints as well as GPU acceleration for larger workloads.
- Working knowledge of networking and cybersecurity concepts such as IP addressing, DNS, TLS, network flows, ports/services, routing, network devices, and security alerts.
- Experience with cyber/network telemetry such as Zeek, PCAP-derived data, SIEM data, IDS/IPS alerts, device configuration data, or vulnerability/asset data is highly desirable.Â
- Experience with graph/network-analysis libraries, SQL/data stores, Elasticsearch/Splunk, or similar analytic platforms is a plus.
- Experience developing analytics for cybersecurity, threat hunting, detection engineering, or defensive cyber operations is strongly preferred.
Data Scientist · PUNCH Cyber Analytics Group