117 open roles
Data scientist lead
Job description
LEAD DATA SCIENTIST Security Knowledge Graphs & Cyber AI Role Level Lead Experience 10+ years overall; 5+ years in AI/ML or graph analytics Location Flexible / Hybrid Employment Type Full-time Role Purpose Lead the design, engineering, and operationalization of enterprise Security Knowledge Graphs that connect security telemetry, assets, identities, vulnerabilities, threats, controls, and incidents into a trusted intelligence layer.
The role is highly hands-on and combines data science, graph engineering, cybersecurity analytics, semantic modeling, and technical leadership to enable attack-path analysis, threat investigation, exposure prioritization, GraphRAG , and AI-assisted security operations.
Key Responsibilities
- Design the Security Knowledge Graph architecture, ontology, taxonomy, entity model, relationship model, provenance model, and lifecycle standards.
- Build production-grade graph ingestion and transformation pipelines for SIEM, EDR/XDR, IAM/PAM, CMDB, vulnerability scanners, cloud security platforms, threat intelligence feeds, security data lakes, and case-management systems.
- Develop entity extraction, identity resolution, deduplication, schema mapping, relationship inference, confidence scoring, temporal modeling, and graph enrichment capabilities.
- Model assets, applications, users, service accounts, privileges, vulnerabilities, misconfigurations, controls, alerts, incidents, indicators, threat actors, campaigns, tactics, techniques, and procedures.
- Implement graph analytics for attack paths, blast radius, privilege escalation, lateral movement, toxic combinations, identity exposure, control gaps, and vulnerability prioritization.
- Build and evaluate graph algorithms and ML models including centrality, community detection, similarity, anomaly detection, node classification, link prediction, embeddings, and Graph Neural Networks.
- Design GraphRAG and knowledge-grounded security assistants that combine graph traversal, vector retrieval, structured evidence, LLM reasoning, citations, and human approval controls.
- Partner with SOC, threat intelligence, IAM, vulnerability management, cloud security, architecture, data engineering, and product teams to convert operational problems into reusable graph-powered capabilities.
- Own technical design reviews, coding standards, model validation, observability, performance tuning, security controls, documentation, and production-readiness gates.
- Mentor data scientists and engineers while remaining accountable for prototypes, reference implementations, critical code, troubleshooting, and complex customer or stakeholder demonstrations. Mandatory Hands-on Technical Skills
- Knowledge graphs: Ontology and semantic model design; property graphs and RDF; graph schema evolution; knowledge representation; provenance; graph quality; entity and relationship resolution.
- Graph platforms: Deep implementation experience with Neo4j and Cypher ; working knowledge of at least one additional platform such as Amazon Neptune, Tiger. Graph , Azure Cosmos DB Gremlin, ArangoDB , or Janus. Graph .
- Graph data science: Neo4j Graph Data Science, NetworkX , Py. Torch Geometric or DGL; graph embeddings, pathfinding, similarity, clustering, link prediction, node classification, anomaly detection, and GNN development.
- Programming and engineering: Advanced Python and SQL; APIs; test automation; data structures; distributed processing; Git; CI/CD; containers; infrastructure awareness; production debugging and performance optimization.
- Data engineering: Spark or Databricks, Kafka or equivalent streaming, ETL/ELT, batch and real-time pipelines, data contracts, lineage, cataloguing, quality rules, and scalable cloud storage.
- Cybersecurity: SOC workflows, threat hunting, incident response, detection engineering, vulnerability and exposure management, IAM/PAM, Zero Trust, cloud security, and security control mapping.
- Security standards: Practical use of MITRE ATT&CK, STIX/TAXII, CVE, CWE, CAPEC, NIST frameworks, CIS Controls, and common threat-intelligence vocabularies.
- GenAI and GraphRAG : LLM-based extraction, retrieval orchestration, agent/tool integration, prompt design, evaluation, grounding, guardrails, explainability, and evidence traceability.
- MLOps and observability: Experiment tracking, model versioning, deployment, monitoring, drift and quality checks, auditability, access controls, secrets management, and cost/performance management. Security Knowledge Graph Engineering Expectations
- Create canonical entity and relationship definitions with stable identifiers, temporal context, source lineage, evidence attributes, confidence scores, and access-control classifications.
- Develop reusable connectors and parsers for structured, semi-structured, and unstructured security sour
Description copied from Test Triangle's careers page. Read the full posting before you apply.
More jobs at Test Triangle
Solution Train Engineer
Test Triangle· Dublin 1, IrelandLinux application programming
Test Triangle· Dublin 1, IrelandWireless SME
Test Triangle· London, United KingdomDomain Consultant-SME
Test Triangle· Horsham, United KingdomLead Java Developer
Test Triangle· Dublin 1, Ireland