AI/ML Lead, Applied AI for Security
"We are building the detection brain for Agentic SecOps."
ABOUT TRENCH
Security Operations is entering a fundamentally different era. AI can change how security signals are understood, correlated and acted upon. But building reliable AI for Security Operations requires more than putting an LLM on top of security data.
Trench is building an agentic operating system for Security Operations. We are looking for an AI/ML Lead, Applied AI for Security to build the models that power Trench's detection brain, from security-focused SLMs and UEBA to synthetic data, evaluation and production MLOps.
This is a hands-on leadership role. You will set the ML direction, build models that work on real security data and help turn research into production.
THE ROLE
You will work across Applied AI, Security ML and MLOps. You will solve hard problems around understanding security telemetry, detecting anomalous behaviour, fine-tuning models for security tasks and building reliable AI systems that operate in production. You will work closely with Security R&D, Detection Engineering and Platform teams to turn model capabilities into trustworthy security outcomes.
WHAT YOU'LL OWN
- Security SLMs: Fine-tune small language models for security tasks such as alert triage, investigation summarization, detection generation and log understanding using approaches such as SFT, LoRA and QLoRA.
- UEBA & anomaly detection: Build models that identify anomalous, risky and malicious behaviour across high-cardinality security telemetry using unsupervised, sequence and graph-based approaches.
- Synthetic security data: Build pipelines to generate attack and behavioural data for training, augmentation and testing where real-world labels are scarce.
- ML in production: Own training, feature engineering, model serving, inference, monitoring, drift detection and feedback loops across the ML lifecycle.
- Evaluation & red-teaming: Build rigorous evaluation frameworks, benchmarks and guardrails so models can be measured before and after deployment.
- Lead the direction: Stay hands-on, define the ML roadmap and mentor the team as it grows.
MINDSET
- You are a builder. You take models from experiments to production, not just notebooks and papers.
- You care about measurement. You don't ship a model you cannot evaluate.
- You understand the problem before the model. You know when to fine-tune, when to prompt, when to use RAG and when a traditional ML approach is better.
- You use AI by default. You actively explore agentic frameworks and AI tooling to solve real problems.
- You work with messy data. Real security data is noisy, incomplete and constantly changing. You enjoy solving that problem.
- You want to build something new. We are not adding AI to another SIEM. We are building models that can fundamentally change how Security Operations detects and responds to threats.
WHAT WE'RE LOOKING FOR
- 8 to 15 years of strong applied ML experience with a track record of shipping ML to production.
- Hands-on LLM / SLM fine-tuning using SFT, LoRA, QLoRA or similar techniques.
- Strong judgement on fine-tuning vs prompting vs RAG.
- Experience building Agentic AI using frameworks such as LangGraph, CrewAI, Agno or similar.
- Strong MLOps experience across training, serving, experiment tracking, model registry and monitoring.
- Experience with anomaly detection, UEBA, sequence or graph models.
- Strong Python and modern ML stack including PyTorch and Hugging Face.
- Strong evaluation discipline and production mindset.
- High ownership and comfort working with real-world data.
BONUS POINTS
- Security, fraud or anomaly detection experience.
- SIEM, EDR, identity or security telemetry experience.
- Synthetic data generation and programmatic labelling.
- Model optimization, quantization, distillation or GPU optimization.
- AI agents with tool use and production workflows.
- Feature stores and ML over columnar or streaming data.
- Open-source ML contributions.
WHY THIS ROLE
You will build the intelligence behind a new operating model for Security Operations. The problems are hard:
- How do we make models understand security telemetry?
- How do we detect behaviour that static rules cannot?
- How do we train reliable models when security labels are scarce?
- How do we make AI agents measurably better over time?
If these problems excite you, this is the role.
HOW TO APPLY
Email career@trenchsecurity.ai with a short note about a model you took to production and how you evaluated it. Include your GitHub, papers or LinkedIn.
No formal cover letter needed. Show us what you've built. Show us how you think.