CAREERS AT SPOTLIGHT

CAREERS AT SPOTLIGHT

Open positions:

  • At Spotlight Security, we’re on a mission to revolutionize the defense of critical infrastructure with agentic AI. Backed by grant funding, our team builds adaptive machine-learning agents that detect, remediate, and autonomously reconfigure firewalls against evolving threats. Our vision is clear: empower utilities, energy providers, manufacturing plants, and other mission-critical operational technology with intelligent defenses that learn from every attack. We move fast, think big, and never settle—join us as we redefine what’s possible in cybersecurity.

    Senior Machine Learning Engineer:

    Location: New York, NY (hybrid)
    Employment Type: Contract

    Senior ML Engineer will not only build great models but also ensure they roll out smoothly, securely, and reliably inside customer data centers, to lead our on-prem proof of concept.

    What You’ll Do

    • Architect, implement, and maintain end-to-end ML pipelines to fine-tune large language models (LLMs) on Azure ML and AWS SageMaker to translate detected anomalies into remediation code.

    • Research and develop deep-learning architectures (e.g., CNNs, RNNs) that learn complex patterns for advanced threat detection

    • Collaborate with our security research team to curate labeled datasets from live firewall, IDS/IPS logs, historic firewall logs NetFlow, PCAP, and offense/defense adversarial learning.

    • Optimize model performance for latency, throughput, and resource efficiency; deploy models in Kubernetes or serverless environments

    • Build monitoring and alerting systems to detect model drift, false positives, and maintain continuous calibration

    • Design and automate on-prem installation workflows (Ansible/Terraform/Helm) for air-gapped and corporate-network environments.

    • Implement FIPS-compliant encryption and secure key management; integrate audit-grade logging and RBAC.


    What We’re Looking For

    • Degree or long term working experience in computer science, machine learning, or related fields, ideally 7+ years building and deploying deep-learning models, preferably in cybersecurity or anomaly detection

    • Solid understanding of GPU/CPU architecture, OS patching, and air-gapped network deployments.

    • Hands-on expertise with TensorFlow and PyTorch; proficiency in Python, Docker, and Kubernetes

    • Demonstrated experience fine-tuning LLMs on Azure ML, AWS SageMaker, or comparable platforms, using Weights and Biases or similar tools.

    • Bonus: Solid understanding of network security data formats (NetFlow, PCAP), threat-hunting methodologies, and SOAR/SIEM integrations.

    If you’re energized by moving the needle on  AI capabilities, driven to protect critical systems, and eager to make an immediate impact, we want to hear from you. Apply today at https://www.spotlightsecurity.ai/apply and help us illuminate the path to safer infrastructure.

  • At Spotlight Security, we’re on a mission to revolutionize the defense of critical infrastructure with agentic AI. Backed by grant funding, our team builds adaptive machine-learning agents that detect, remediate, and autonomously reconfigure firewalls against evolving threats. Our vision is clear: empower utilities, energy providers, manufacturing plants, and other mission-critical operational technology with intelligent defenses that learn from every attack. We move fast, think big, and never settle—join us as we redefine what’s possible in cybersecurity.

    Software Engineer:

    Location: New York, NY (hybrid)
    Employment Type: Contract


    As a Software Engineer at Spotlight Security, you’ll architect and deliver resilient, scalable services and own their deployment and operation within our clients’ data and operations centers.


    What You’ll Do

    • Design and implement the environment that powers our AI-driven security agents.

    • Integrate machine-learning and natural-language processing components into production systems

    • Work within virtual systems that mimic client-side security architectures to implement configuration logic end-to-end, then develop a system to prompt a human-in-the-loop network analyst for review.

    • Automate on-prem installs (Ansible playbooks, Helm charts) for air-gapped or corporate networks

    • Package containers and models for offline registry use, and orchestrate client-side update/rollback procedures.

    • Develop and maintain end-to-end integration tests against isolated staging labs.

    • Build robust data ingestion pipelines for real-time telemetry from firewalls, IDS/IPS, and SIEM platforms

    • Validate OS and hardware compatibility—managing drivers, package repositories, and proxy settings for client environments.

    • Wrap the fine-tuned LLM in a robust API, enforce rate limits, and manage versioned model endpoints. 

    • Define Terraform or CloudFormation modules for staging and production environments in AWS/Azure.

    • Collaborate with ML Engineers to containerize and deploy models in AWS and Azure environments

    • Write clean, maintainable code

    What We’re Looking For

    • Excellent communication skills and a track record of building software from the ground up

    • Experience deploying software on-prem or in air-gapped environments.

    • B.S. or M.S. in Computer Science or related field

    • 3+ years professional software development experience, ideally with cybersecurity or ML/NLP projects

    • Data structure experience building microservices to pull firewall configs and logs in real-time via vendor APIs (e.g., Palo Alto PAN-OS, Cisco ASA REST).

    • Strong programming skills in Python, Java, or Go; solid grasp of data structures and algorithms

    • Familiarity with cloud platforms (AWS, Azure), container orchestration (Kubernetes), and CI/CD pipelines

    • Knowledge of MacOS, Windows, Linux internals, and their respective command-line interfaces

    • Experience with ML frameworks (TensorFlow/PyTorch) and NLP libraries (spaCy, NLTK, Hugging Face). 

    • Bonus: security-focused experience (OAuth, PKI, network protocols), or hands-on with Palo Alto PAN-OS/Cisco ASA SDKs

    If you’re energized by moving the needle on  AI capabilities, driven to protect critical systems, and eager to make an immediate impact, we want to hear from you. Apply today at https://www.spotlightsecurity.ai/apply and help us illuminate the path to safer infrastructure.

  • At Spotlight Security, we’re on a mission to revolutionize the defense of critical infrastructure with agentic AI. Backed by grant funding, our team builds adaptive machine-learning agents that detect, remediate, and autonomously reconfigure firewalls against evolving threats. Our vision is clear: empower utilities, energy providers, manufacturing plants, and other mission-critical operational technology with intelligent defenses that learn from every attack. We move fast, think big, and never settle—join us as we redefine what’s possible in cybersecurity.

    Cybersecurity Data Analyst:

    Location: New York, NY (hybrid)
    Employment Type: Contract


    Cybersecurity Data Analyst will not only uncover threats and enrich data for our ML engines but also ensure that every component installs, runs, and scales reliably within client data-center environments.

    What You’ll Do

    • Monitor and analyze network activity using SIEM tools (Splunk, Elastic), IDS/IPS, and firewall logs to uncover suspicious behavior

    • Build Python/PowerShell scripts to ingest logs from SIEM (Splunk/Elastic), IDS/IPS, and firewalls.

    • Package and version analyst scripts and parsers as self-contained modules, with internal artifact registry support for air-gapped clients.

    • Parse raw data into structured events and enrich with contextual metadata for use in fine-tuning large language models.

    • Implement and audit security controls aligned with NIST, ISO 27001/27002, CIS Benchmarks, and SOC 2 requirements

    • Partner with machine learning team to label and enrich data feeds for threat-detection models

    • Produce clear, actionable dashboards and reports for both technical and executive stakeholders

    • Establish unified logging schema and parsing conventions across all network sources and automated alerts for pipeline failures.

    What We’re Looking For

    • 2 or 4 year degree in Cybersecurity, Information Systems, or a related discipline

    • 2+ years hands-on experience in a SOC, network analyst, or threat-hunting role

    • Solid understanding of firewalls, network segmentation, and best-practice configurations

    • Proficiency with SIEM platforms, IDS/IPS technologies, and scripting (Python, PowerShell)

    • Hands-on with ingestion frameworks (Kafka Connect, Fluentd, Logstash) including back-pressure and retry designs.

    • Knowledge of MacOS, Windows, Linux internals, and their respective command-line interfaces

    • Demonstrated ability to instrument and monitor custom pipelines via Prometheus, Grafana, or equivalent.

    • Comfort authoring runbooks and delivering training for client SOC teams.

    • Familiarity with mobile-OS threats (iOS, Android) and endpoint-security concepts

    • Bonus: CompTIA Network+ or Cisco's CCNA/CCNP or other comparable network-focused certification

    • Bonus: Experience building machine learning and AI security tools

    If you’re energized by moving the needle on  AI capabilities, driven to protect critical systems, and eager to make an immediate impact, we want to hear from you. Apply today at https://www.spotlightsecurity.ai/applyand help us illuminate the path to safer infrastructure.