Data scientist lead
Test Triangle · Leeds, United Kingdom ·
- Seniority
- Lead
- Employment
- Full time
- Category
- Data science
- Experience
- 5+ years
Test Triangle · Leeds, United Kingdom ·
State Street · Quincy, Massachusetts
JPMorgan Chase Bank, N.A. · Summit Avenue, Hudson County
State Street · Quincy, Massachusetts
Booz Allen · McLean, VA
Lead Data Scientist who designs, builds, and operationalizes enterprise Security Knowledge Graphs for attack-path analysis, threat investigation, and GraphRAG-powered AI security operations. Highly hands-on with graph platforms (Neo4j/Cypher), Python, graph ML/GNNs, Spark/Kafka data pipelines, and LLM-based retrieval, in a hybrid Leeds-based role.
LEAD DATA SCIENTIST
Security Knowledge Graphs & Cyber AI
Role Level
Lead
Experience
10+ years overall; 5+ years in AI/ML or graph analytics
Location
Flexible / Hybrid
Employment Type
Full-time
Role Purpose
Lead the design, engineering, and operationalization of enterprise Security Knowledge Graphs that connect security telemetry, assets, identities, vulnerabilities, threats, controls, and incidents into a trusted intelligence layer. The role is highly hands-on and combines data science, graph engineering, cybersecurity analytics, semantic modeling, and technical leadership to enable attack-path analysis, threat investigation, exposure prioritization, GraphRAG, and AI-assisted security operations.
Key Responsibilities
• Design the Security Knowledge Graph architecture, ontology, taxonomy, entity model, relationship model, provenance model, and lifecycle standards.
• Build production-grade graph ingestion and transformation pipelines for SIEM, EDR/XDR, IAM/PAM, CMDB, vulnerability scanners, cloud security platforms, threat intelligence feeds, security data lakes, and case-management systems.
• Develop entity extraction, identity resolution, deduplication, schema mapping, relationship inference, confidence scoring, temporal modeling, and graph enrichment capabilities.
• Model assets, applications, users, service accounts, privileges, vulnerabilities, misconfigurations, controls, alerts, incidents, indicators, threat actors, campaigns, tactics, techniques, and procedures.
• Implement graph analytics for attack paths, blast radius, privilege escalation, lateral movement, toxic combinations, identity exposure, control gaps, and vulnerability prioritization.
• Build and evaluate graph algorithms and ML models including centrality, community detection, similarity, anomaly detection, node classification, link prediction, embeddings, and Graph Neural Networks.
• Design GraphRAG and knowledge-grounded security assistants that combine graph traversal, vector retrieval, structured evidence, LLM reasoning, citations, and human approval controls.
• Partner with SOC, threat intelligence, IAM, vulnerability management, cloud security, architecture, data engineering, and product teams to convert operational problems into reusable graph-powered capabilities.
• Own technical design reviews, coding standards, model validation, observability, performance tuning, security controls, documentation, and production-readiness gates.
• Mentor data scientists and engineers while remaining accountable for prototypes, reference implementations, critical code, troubleshooting, and complex customer or stakeholder demonstrations.
Mandatory Hands-on Technical Skills
• Knowledge graphs: Ontology and semantic model design; property graphs and RDF; graph schema evolution; knowledge representation; provenance; graph quality; entity and relationship resolution.
• Graph platforms: Deep implementation experience with Neo4j and Cypher; working knowledge of at least one additional platform such as Amazon Neptune, TigerGraph, Azure Cosmos DB Gremlin, ArangoDB, or JanusGraph.
• Graph data science: Neo4j Graph Data Science, NetworkX, PyTorch Geometric or DGL; graph embeddings, pathfinding, similarity, clustering, link prediction, node classification, anomaly detection, and GNN development.
• Programming and engineering: Advanced Python and SQL; APIs; test automation; data structures; distributed processing; Git; CI/CD; containers; infrastructure awareness; production debugging and performance optimization.
• Data engineering: Spark or Databricks, Kafka or equivalent streaming, ETL/ELT, batch and real-time pipelines, data contracts, lineage, cataloguing, quality rules, and scalable cloud storage.
• Cybersecurity: SOC workflows, threat hunting, incident response, detection engineering, vulnerability and exposure management, IAM/PAM, Zero Trust, cloud security, and security control mapping.
• Security standards: Practical use of MITRE ATT&CK, STIX/TAXII, CVE, CWE, CAPEC, NIST frameworks, CIS Controls, and common threat-intelligence vocabularies.
• GenAI and GraphRAG: LLM-based extraction, retrieval orchestration, agent/tool integration, prompt design, evaluation, grounding, guardrails, explainability, and evidence traceability.
• MLOps and observability: Experiment tracking, model versioning, deployment, monitoring, drift and quality checks, auditability, access controls, secrets management, and cost/performance management.
Security Knowledge Graph Engineering Expectations
• Create canonical entity and relationship definitions with stable identifiers, temporal context, source lineage, evidence attributes, confidence scores, and access-control classifications.
• Develop reusable connectors and parsers for structured, semi-structured, and unstructured security sour
ExecRecruitment