1

Online Anomaly Detection Jobs (NOW HIRING)

$140 - $282/hr

Anomaly Detection: Proven track record of developing algorithms for map anomaly detection, sensor-to-map misalignments, or online scene-change identification. * Safety-Critical Systems: Knowledge of ...

New

As online scams and digital fraud become one of the most pervasive consumer harms across Europe ... Deploy AI-powered fraud detection: pattern recognition, anomaly detection, and automated flagging ...

next page

Showing results 1-20

Online Anomaly Detection information

What is the difference between Online Anomaly Detection vs Data Analyst?

AspectOnline Anomaly DetectionData Analyst
Required CredentialsBachelor's in CS, Data Science, or related fields; knowledge of machine learningBachelor's or higher in Statistics, Data Science, or related fields
Work EnvironmentTech companies, cybersecurity, finance, real-time data systemsBusiness, finance, marketing, reporting teams
Employer & Industry UsageUsed in industries requiring real-time monitoring and alertingUsed across various industries for data interpretation and reporting

Online Anomaly Detection focuses on real-time identification of unusual patterns in data streams, often requiring knowledge of machine learning and programming. Data Analysts interpret data, generate reports, and support decision-making. While both roles work with data, Online Anomaly Detection emphasizes automation and real-time analysis, whereas Data Analysts focus on historical data analysis and insights.

What cities are hiring for Online Anomaly Detection jobs?

Cities with the most Online Anomaly Detection job openings:

What are the most commonly searched types of Anomaly Detection jobs?

The most popular types of Anomaly Detection jobs are:

What states have the most Online Anomaly Detection jobs?

States with the most job openings for Online Anomaly Detection jobs include:

Infographic showing various Online Anomaly Detection job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 62% Full Time, 34% Part Time, 1% Temporary, and 2% Contract. Highlights an 82% Physical, 1% Hybrid, and 17% Remote job distribution.

Staff Security Detection Engineer, Machine Learning

SoFi

Seattle, WA

Full-time

Posted 22 days ago


Job description

The role: 

We're seeking a Staff Security Detection Engineer to build and mature SoFi's machine learning-driven detection and anomaly detection program. You will own the detection and model lifecycle end to end; feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines. You'll partner closely with our Security Operations Center (SOC), Security Operations Engineering, and Fraud programs to turn high-volume telemetry into high-confidence, low-noise detections at scale.

What you'll do: 

  • Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets.
  • Operationalize models and detections from notebook to production, including enrichment, correlation, and response playbook hooks (detection-as-code, CI/CD, model versioning, and rollback).
  • Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality.
  • Partner with the SOC to triage, tune, and close detection feedback loops; use analyst dispositions as labels to retrain and improve models, reduce noise, and document runbooks.
  • Collaborate with Threat Intelligence, Security Architecture, and Fraud stakeholders to translate threat hypotheses and scenarios into repeatable, model-backed analytics with clear success metrics.
  • Establish model governance: offline and online evaluation, drift and data-quality monitoring, periodic retraining and re-baselining, explainability/traceability, and privacy-by-design controls.
  • Participate in root-cause and post-incident reviews to identify new signals, features, and coverage gaps; backlog and deliver the resulting models and detections.
  • Contribute to reference architectures, standards, and documentation for the ML detection platform, data lake, and pipelines across the security organization.
  • Mentor engineers and analysts on applied ML, anomaly detection, detection tuning, data quality, and pipeline reliability.

What you'll need: 

  • 7+ years hands-on experience building and operating machine learning models for detection or anomaly detection in production (e.g., security, fraud, or abuse), across both supervised and unsupervised approaches.
  • Hands-on experience with data lake and big-data technologies (e.g., Snowflake, Databricks, Spark, Delta/Iceberg, S3/GCS) for storing, transforming, and querying large-scale security telemetry.
  • Strong programming and query skills in Python and SQL, with hands-on use of the ML and data stack (e.g., pandas, scikit-learn, PyTorch or TensorFlow) for feature engineering, model training, and automation.
  • Solid understanding of security telemetry sources; identity and access (SSO, IGA, PAM), endpoint/EDR, network/proxy, cloud (AWS/GCP/Azure), and SaaS audit logs, and how to shape them into model features.
  • Working knowledge of anomaly detection techniques (statistical baselining, clustering, isolation forests, autoencoders, time-series methods) and the end-to-end model lifecycle.
  • Familiarity with security frameworks and adversary tradecraft (MITRE ATT&CK, kill chain) and how they map to detectable behaviors and model features.
  • Experience collaborating with SOC/DFIR and fraud/risk teams; excellent written communication for models, detections, runbooks, and stakeholder updates.
  • Ability to balance detection coverage, model precision, and operational load; metrics-driven mindset (precision/recall, false-positive rate, MTTD, alert fatigue).
  • Bachelor's degree in computer science, data science, statistics, a related field, or equivalent practical experience.

Nice to have: 

  • Experience with streaming and real-time data engineering (e.g., Kafka, Kinesis, Pub/Sub, Flink, Spark Streaming) for near-real-time model scoring.
  • Experience building and deploying ML models on AWS (e.g., SageMaker, S3, Glue, Athena, Lambda) for training, feature pipelines, and inference.
  • MLOps practices - feature stores, model registries, experiment tracking, canary and shadow releases for reliable model deployment and retraining.
  • Graph-based ML and analytics for entity relationships, risk propagation, and community detection.
  • Experience applying deep learning or LLM-based approaches to security, log, or sequence data.
  • Experience leveraging LLMs to design, analyze, and test detections.
  • Relevant certifications (e.g., AWS/GCP machine learning or data engineering, Databricks, or equivalent).