Machine Learning Engineer I - Message Security Products
WFA Digital Insight
Abnormalsecurity’s Misdirected Email Detection team tackles a niche but critical problem: outbound emails sent to the wrong recipient. The Machine Learning Engineer I will own the full ML lifecycle for this product, moving beyond model tinkering to deliver production‑ready pipelines that power real‑time scoring. What sets this role apart is the blend of hands‑on feature engineering, hypothesis‑driven experimentation, and cross‑functional collaboration with product and engineering leads. Candidates will be expected to translate research ideas into reliable detections, run rigorous offline and online tests, and respond to on‑call alerts that directly affect customer security posture. The position sits at the intersection of data science and operational reliability, making it ideal for engineers who enjoy both creative model work and the discipline of production monitoring.
Job Description
About the Role
Abnormal AI is seeking a Machine Learning Engineer - I (MLE) to join the Misdirected Email Detection (MED) team. The MED team plays a critical role in preventing accidental data loss by detecting and blocking misdirected outbound emails, delivering protection at scale without adding operational burden to customer SOCs.
This is a highly applied role for MLEs who thrive on building, iterating, and experimenting. Rather than focusing solely on model training, you will also be responsible for developing practical, end-to-end ML solutions. This includes but is not limited to generating and refining features, testing hypotheses, averaging signals, and translating research ideas into production-grade systems, all while collaborating cross-functionally to turn customer needs into measurable product improvements. The ideal candidate combines a tinkerer's mindset with technical rigor, balancing innovation with production excellence to drive experimentation, scale solutions, and deliver reliable detection capabilities that create meaningful customer impact in real-world environments.
What you will do
- Partner with Product Manager, Tech Lead and engineering stakeholders to align technical deliverables to roadmap milestones and ensure successful GA launches across supported environments.
- Own the full ML lifecycle for Misdirected Email, including data wrangling, feature engineering, model training and evaluation, deployment, and monitoring. Deliver iterative improvements with measurable reliability and customer impact.
- Run rigorous experiments and evaluations (offline metrics, online A/B testing, post-launch monitoring), set thresholds, and conduct targeted error analysis to prevent regressions.
- Communicate effectively across time zones, maintain high-quality technical documentation, and contribute to shared team knowledge.
- Participate in shared on-call rotation for owned components, with responsibilities focused on detection efficacy and realtime scoring systems. Priorities include resolving efficacy-related alerts, investigating high-visibility false positives, and addressing reported false positives/false negatives from customers or internal teams.
Must Haves
- BS degree in Computer Science, Machine Learning, Artificial Intelligence, Information Systems, or a related engineering or quantitative field.
- 1+ years building and operating applied ML features in production systems.
- Proven experience contributing to end-to-end ML systems, including data wrangling (text and structured), feature engineering, model selection, training, evaluation, and production deployment with monitoring.
- Demonstrated ability to implement and reason about algorithms, develop features, average and combine signals, and apply numerical computing effectively.
- Demonstrated ability to interrogate production data, identify behavioral or trend shifts, and launch targeted experiments to improve model efficacy.
- Understanding of online vs offline pipelines, data tables and labeling workflows to effectively leverage tooling to support safe, scalable model deployments.
- Experience running offline metrics, online A/B tests, setting thresholds, and monitoring drift and performance, with guardrails and rollback strategies to ensure reliable iteration.
- Strong written and asynchronous communication skills. Effective working independently and across distributed, cross-functional teams.
Nice to Have
- Experience with our stack: Python, Go, AWS, Spark, Databricks
- Experience in email security/DLP or misdirected email prevention domains and customer-focused ML deployments.
- Experience writing detectors/rules to complement ML models for safe launches and rapid iteration.
- Experience with operationalising research into reliable, customer-facing systems, with emphasis on scalability, performance, and detection accuracy in real-world environments.
- Prior experience contributing to a small team or project to deliver a feature or component from scratch.
#LI-UC1
A note on AI in our process:
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.
Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.
How to Stand Out
- Highlight any production‑grade ML pipelines you have built, especially those involving text data or real‑time scoring.
- Prepare a short case study that walks through your end‑to‑end process: data wrangling, feature engineering, model selection, deployment, and monitoring.
- Demonstrate familiarity with Python and cloud services (AWS, Spark) in your technical interview; a quick coding exercise is likely.
- Emphasize strong written communication by sharing clear documentation or blog posts you have authored about past projects.
- During on‑call scenario questions, focus on how you triage false positives/negatives and implement guardrails.
- If you have any experience in email security or DLP, bring it up early to differentiate yourself.
- Be prepared to discuss how you measure model drift and what rollback strategies you have used in production.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.