Full-Time

Senior Data Scientist

Applied Machine Learning

SpyCloud

SpyCloud

201-500 employees

Threat intelligence and identity protection platform

Compensation Overview

$154k - $200k/yr

No H1B Sponsorship

Austin, TX, USA

Remote

Category
Data & Analytics (1)
Required Skills
Scikit-learn
Python
Airflow
Data Science
TensorFlow
PyTorch
Xgboost
Apache Spark
Machine Learning
MLflow
Infrastructure as Code (IaC)
Docker
Cybersecurity
AWS
Pandas
DevOps

Get referred to SpyCloud

See people who can refer or advise you

Requirements
  • At least 4 years of experience building and shipping models in production with direct, hands-on ownership of the surrounding data lifecycle.
  • Strong background in applied mathematics, including linear algebra, optimization, and statistics, and in machine learning.
  • Demonstrated experience using Natural Language Processing techniques for text classification, tagging, or entity extraction.
  • Proficiency in Python and machine-learning libraries including PyTorch, TensorFlow, scikit-learn, and XGBoost.
  • Demonstrated experience building or maintaining data and feature pipelines, such as with Airflow, Spark, or Pandas, as part of modeling work.
  • Comfort with model versioning and monitoring in production, such as with MLflow or DVC.
  • Working experience deploying models into cloud environments or containerized services.
  • Strong communication skills and the ability to translate complex problems into actionable solutions.
Responsibilities
  • Develop, train, and deploy models using structured and unstructured data for threat detection and alerting, entity resolution and risk scoring, and natural-language tagging and classification.
  • Own the full model lifecycle from data understanding and preparation through prototyping and production deployment.
  • Build preprocessing and feature-engineering pipelines required by the models.
  • Own model monitoring and evaluation, and design feedback loops to continuously improve accuracy and effectiveness.
  • Prototype new approaches and bring existing research or experimental prototypes to production-grade reliability.
  • Own data validation, transformation, and pipeline health across handoffs between research and production.
  • Work with software and data engineers to productionize models in cloud-native environments such as Amazon Web Services.
  • Partner with product managers and domain experts to define success criteria and rapidly prototype minimum viable products to test new features or signals.
  • Work with the data engineering team to access and understand diverse data sources and own transformation and validation steps.
  • Contribute to broader system design and architectural decisions.
  • Communicate model design choices, tradeoffs, and outcomes to technical and non-technical stakeholders.
  • Maintain documentation for models, pipelines, and evaluation methodologies.
  • Participate in model and compliance reviews and customer-facing discussions as needed.
Desired Qualifications
  • Deeper exposure to machine learning operations, DevOps, data engineering, infrastructure as code, or continuous integration and continuous delivery.
  • Familiarity with cybersecurity datasets or domains such as threat intelligence, account takeover, or ransomware.
  • Exposure to graph analytics, knowledge graphs, or cybersecurity frameworks such as MITRE ATT&CK.
  • Background working with unstructured data such as log files, threat reports, or breach datasets.

SpyCloud provides cyber threat intelligence and identity protection for businesses. Its Cybercrime Analytics Platform uses data recovered from the criminal underground to deliver actionable insights that help detect and prevent cyber threats such as malware, ransomware, and unauthorized access. The platform also supports de-anonymizing threat actors and linking them to crimes to aid incident response and threat attribution. Unlike many security tools that focus on one area, SpyCloud combines threat intelligence, credential monitoring, dark web monitoring, and incident response in a single platform to help enterprises protect digital assets and identities. The company's goal is to help businesses proactively prevent data breaches and other cybercrimes by continuously detecting compromised credentials, stopping unauthorized access, and monitoring the dark web for emerging threats.

Company Size

201-500

Company Stage

Growth Equity (Venture Capital)

Total Funding

$203.5M

Headquarters

Austin, Texas

Founded

2016

Get referred to SpyCloud

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Ping Identity integrations shipped April 29, 2026, embedding SpyCloud at authentication.
  • July 16, 2026 milestone topped one trillion assets, signaling data moat expansion.
  • Supply Chain Threat Protection launched January 2026 for vendor identity exposure monitoring.

What critics are saying

  • Okta and Ping can bundle similar remediation, compressing SpyCloud pricing by 2027.
  • Criminals migrate to passkeys and token theft, weakening credential-reuse defenses quickly.
  • If breach-data access shrinks, SpyCloud's core intelligence model loses the asset edge.

What makes SpyCloud unique

  • SpyCloud's one-trillion recaptured identity assets beat dark-web monitoring vendors on matching depth.
  • IDLink correlates breached credentials, cookies, devices, and domains into actionable identities.
  • Research Agent turns investigator tradecraft into natural-language workflows inside the investigations console.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Unlimited Paid Time Off

Meal Benefits

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

-1%

2 year growth

-4%
ExecutiveBiz
Jun 24th, 2026
SpyCloud unveils ai-powered Research Agent for Cybercrime Investigations.

SpyCloud unveils ai-powered Research Agent for Cybercrime Investigations. * SpyCloud has launched an AI-powered investigation agent designed to accelerate cybercrime and threat intelligence analysis * SpyCloud Research Agent enables analysts to conduct investigations using natural-language queries * The AI investigation tool can analyze diverse data types, including emails, domains, IP addresses and device identifiers SpyCloud has launched SpyCloud Research Agent, a conversational artificial intelligence investigation tool designed to help cyberthreat intelligence analysts, security operations center teams, fraud investigators and incident response leaders accelerate cybercrime investigations. SpyCloud is a sponsor of the 2026 Intel Summit on Sept. 24, where intelligence community leaders and industry partners will discuss the role of AI, cyber capabilities and data-driven technologies in modernizing intelligence operations. Register today. What does SpyCloud Research Agent do? The Austin, Texas-based company said Wednesday the AI investigation agent is now available through SpyCloud's Cybercrime Investigations console and is designed to help users investigate subjects, hypotheses or groups of assets. According to the company, Research Agent can plan investigations, sequence pivots and return findings in formats such as narrative summaries, tables, timelines or prioritized escalation recommendations. The agent works with natural-language prompts and can analyze mixed asset batches, including emails, domains, IP addresses, usernames and machine identifiers. How does Research Agent operate? Research Agent leverages SpyCloud's repository of more than 1 trillion recaptured identity assets sourced from infostealer malware logs, phishing kits, combolists and data breaches to automatically correlate fragmented identity signals during every investigation. Built on the expertise of SpyCloud's cybercrime investigators, the AI-powered tool begins by linking related credentials, devices, domains and exposure data to establish investigative context. It then applies expert-level reasoning to determine relevant investigative paths before delivering findings in formats such as narrative reports, timelines, tables or prioritized recommendations for analysts. In a LinkedIn post, Phil Fuster, vice president of federal sales at SpyCloud, said Research Agent combines conversational AI with the company's recaptured criminal-underground intelligence and investigator tradecraft to help analysts connect disparate data points and accelerate cybercrime investigations. "Analysts are connecting fragments, following threads, validating relationships, and trying to move from a single data point to an actionable conclusion as quickly as possible," said Fuster. "When AI is paired with the right data and the right investigative expertise, it can help teams move faster without taking analysts out of control," he added. How does it fit into SpyCloud's platform? Research Agent builds on SpyCloud's previous Cybercrime Investigations capabilities, including IDLink, an automated digital identity correlation engine, and AI Insights, which generates exportable identity findings reports. SpyCloud said the new agentic layer adds planning and investigative automation intended to help analysts connect data points and produce finished intelligence more quickly. Research Agent builds on SpyCloud's broader identity threat intelligence platform. In June, the company expanded its partnership with Okta through integrations that use SpyCloud's repository of more than 1 trillion recaptured identity assets and its IDLink correlation technology to automate identity threat detection and response.

ExecutiveBiz
Jun 16th, 2026
SpyCloud, Okta expand Identity Threat defense partnership.

SpyCloud, Okta expand Identity Threat defense partnership. * SpyCloud has expanded its partnership with Okta * New integrations automate identity threat detection and response * Okta is one of the sponsors of the 2026 Army Summit, which will discuss cybersecurity, AI and more As government agencies and contractors continue to strengthen cyber defenses and identity security, related topics are expected to take center stage at the 2026 Army Summit this coming Thursday. Okta is a sponsor of the event, which will feature panel discussions on cybersecurity and open ecosystems, artificial intelligence, the future of the tactical edge, the hyperconnected battlefield and other modernization priorities. Sign up now! SpyCloud said Thursday the integrations connect its repository of more than 1 trillion recaptured identity assets with Okta Workforce Identity and Okta Identity Threat Protection to enable organizations to identify and remediate compromised identities in less than five minutes. The latest development came months after SpyCloud launched a new platform, SpyCloud Supply Chain Threat Protection, designed to help government agencies and enterprises counter third-party identity threats by gaining visibility into vendor identity exposures. What is SpyCloud Okta Workforce Guardian? SpyCloud Okta Workforce Guardian is designed to continuously validate employee identities against recaptured data from the criminal underground and support automated remediation actions when exposed credentials or session cookies are identified. Built for Okta Workforce Identity, the integration provides configurable workflow templates that support universal logout, password reuse enforcement and targeted scanning with reporting capabilities. According to SpyCloud, Workforce Guardian can revoke active sessions, identify exposed credentials in use with Okta accounts and automate password reset actions based on organizational policies. What is the SpyCloud + Okta Identity Threat Protection integration? The SpyCloud and Okta ITP integration uses the OpenID Shared Signals Framework to provide identity exposure signals that can inform user risk assessments and policy-based responses. According to SpyCloud, the integration is designed to monitor for new exposures after authentication and deliver risk signals based on the type and severity of exposures. The company said those signals can support actions such as session revocation, password resets, multifactor authentication challenges and user notifications. The company added that its IDLink technology can correlate exposed credentials across corporate and personal identities to provide additional visibility into user exposure. What did SpyCloud officials say about the Okta ITP integration? In a LinkedIn post, Phil Fuster, vice president of federal sales at SpyCloud, said the integration helps federal agencies and the Department of War close the gap between identity compromise and response through automated actions delivered at machine speed. According to Fuster, SpyCloud's recaptured criminal-underground intelligence feeds Okta's risk engine through the Shared Signals Framework, enabling automated responses such as universal logout on confirmed malware exposure, step-up authentication on phishing signals and elevated risk scoring for investigations. In an article posted on ExecutiveBiz, Fuster discussed the need for continuous, identity-driven federal supply chain security and the importance of monitoring identity-based threats across the defense industrial base. SpyCloud Chief Product Officer Damon Fleury said the partnership aims to address the gap between identity compromise and security response. "Identity-based attacks succeed because there's a gap between when an authorized user is compromised and when security teams can act on it," Fleury said. "Our partnership with Okta eliminates that gap across the full identity lifecycle to stop compromised identities before they authenticate; and detects and responds to exposures once a session is live." is a staff writer at Executive Mosaic, where she writes for ExecutiveBiz about IT modernization, cybersecurity, space procurement and industry leaders' perspectives on government technology trends.

GovCon Wire
May 21st, 2026
Leah Burk to lead SpyCloud's revenue, customer efforts as COO.

Leah Burk to lead SpyCloud's revenue, customer efforts as COO. * Leah Burk has assumed new responsibilities as SpyCloud's first-ever COO * In her new role, she will lead the company's revenue operations and customer success functions * SpyCloud CEO Ted Ross said Burk was instrumental in building the operational foundation of the company's growth SpyCloud has named Leah Burk as its first-ever chief operating officer. The Austin, Texas-headquartered cybersecurity company said Tuesday that Burk, who previously served as senior vice president of revenue operations, will oversee revenue operations and customer success functions. Who is Leah Burk? Burk joined SpyCloud in 2020 as director of revenue operations. Throughout her over seven years at the company, she held the roles of vice president and eventually senior vice president. "Leah has built the operational foundation that powers SpyCloud's growth," Ted Ross, CEO of SpyCloud, stated. "Extending her leadership into customer success is a natural evolution to ensure that our identity threat protection solutions are delivered exceptionally well to the businesses that rely on us to protect their workforce, customers, and supply chain from emerging threats." Before SpyCloud, Burk served as director of global sales operations at WP Engine. Her career also includes leadership positions at Zenoss, Lifesize, Dell and Pactive Corp. Burk earned a bachelor of science degree in chemical engineering from Virginia Tech and is based in Austin, Texas. What cyber capabilities does SpyCloud offer? SpyCloud provides automated identity threat protection capabilities designed to disrupt cybercrime using recaptured darknet data, advanced analytics and artificial intelligence. The company is broadening its identity threat protection portfolio amid growing phishing, ransomware and AI-enabled cybersecurity threats. In January, SpyCloud launched SpyCloud Supply Chain Threat Protection, a platform designed to help organizations identify third-party identity exposures and vendor-related cyber risks using darknet and malware intelligence.

GlobeNewswire
Apr 29th, 2026
SpyCloud now integrates with Ping Identity's PingOne DaVinci and Advanced Identity Cloud to operationalize exposure intelligence and accelerate automated remediation.

SpyCloud now integrates with Ping Identity's PingOne DaVinci and Advanced Identity Cloud to operationalize exposure intelligence and accelerate automated remediation. April 29, 2026 09:00 ET | Source: SpyCloud AUSTIN, Texas, April 29, 2026 (GLOBE NEWSWIRE) - SpyCloud, the leader in identity threat protection, today announced new integrations with Ping Identity, a leader in securing digital identities for the world's largest enterprises, spanning two complementary platforms: PingOne DaVinci(TM), a no-code identity orchestration service, and PingOne Advanced Identity Cloud (AIC), the identity cloud built for the enterprise. Together, these integrations will enable SpyCloud to quickly deliver exposure intelligence at the point of authentication - automatically detecting and remediating compromised credentials across workforce and consumer identity journeys at scale. SpyCloud joins a growing network of technology partners developing integrations with DaVinci and AIC through the Ping Identity Global Technology Partner Program. Partner solutions that integrate with DaVinci deliver an improved customer experience in a fraction of the time, through easy drag-and-drop design of digital user journeys across multiple applications and ecosystems. The AIC integration provides patented data isolation technology to enable control, granular data residency to simplify compliance, and dedicated services that ensure maximum performance. SpyCloud provides unique identity protection solutions for workforce and consumer identities, addressing their distinct risks and needs. * Workforce Threat Protection - integrated into DaVinci flows for employees. * Consumer Threat Protection - designed for consumers within AIC journeys. SPYCLOUD WORKFORCE THREAT PROTECTION + PINGONE DAVINCI When an employee logs in, resets a password, or gets onboarded, the SpyCloud Workforce Threat Protection connector checks their credentials against SpyCloud's database of recaptured breach records, infostealer malware logs, combolists, and successful phishes, with 90%+ of passwords cracked to plaintext for accurate matching. If there's a match, the DaVinci flow responds immediately: block access, force a reset, or escalate to MFA. It drops in as a drag-and-drop connector - no custom development required. SPYCLOUD CONSUMER THREAT PROTECTION + ADVANCED IDENTITY CLOUD When a consumer logs in or creates an account, the SpyCloud Auth Node checks their credentials against SpyCloud's database - in real time, inside the PingOne Advanced Identity Cloud journey. If there's a match, the journey automatically responds: step up to MFA, force a password reset, or block access entirely. The level of response scales to the level of risk. "SpyCloud has spent years building the most comprehensive database of recaptured darknet data in the industry," said Damon Fleury, Chief Product Officer, SpyCloud. "Partnering with Ping Identity means that intelligence is actionable at the exact moment of authentication - for both workforce and consumer identities. That's a meaningful shift from reactive breach response to proactive, continuous identity protection." "Ping Identity is committed to expanding our partner ecosystem to deliver better, more seamless customer experiences," said Loren Russon, SVP of Product Management at Ping Identity. "Integrating SpyCloud's specialized intelligence into Ping's orchestration engine and Run-Time Identity platform allows organizations to automatically neutralize identity threats within dynamic user journeys, strengthening security without adding friction to the user experience." About SpyCloud SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics and AI to proactively prevent ransomware and account takeover, detect insider threats, safeguard employee and consumer identities, and accelerate cybercrime investigations. SpyCloud's data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include seven of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now. About Ping Identity At Ping Identity, Govcloudnetwork help organizations secure and manage digital identities across customers, employees, partners, and non-human entities. Whether securing millions of users, fighting fraud, simplifying third-party access, or enabling passwordless experiences, establishing trust in every digital moment shouldn't slow you down. Its enterprise identity platform is designed for scale, flexibility, and integration across cloud, hybrid, and on-prem environments. With its Runtime Identity capabilities, Ping enables organizations to adopt AI and automation by continuously verifying identity, context, and intent at every interaction, helping secure and govern AI agents in real time. Learn more at pingidentity.com. MEDIA CONTACTS Katie Hanusik REQ on behalf of SpyCloud [email protected] Ping Identity Media Relations Release Summary SpyCloud announced new integrations with Ping Identify to quickly deliver exposure intelligence at the point of authentication. Company Profile SpyCloud SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics to proactively prevent ransomware and account takeover, safeguard employee and consumer accounts, and accelerate cybercrime investigations. SpyCloud's... Location: Global Industry: Software

TechNadu
Feb 2nd, 2026
Cyber Job Moves: New Appointments Across Threat Intelligence, Identity, and Critical Infrastructure

Cyber job moves: New appointments across threat intelligence, identity, and critical infrastructure. Trevor Hilligoss - SpyCloud Trevor Hilligoss has been promoted to chief intelligence officer at SpyCloud, where he will drive the company's global intelligence strategy and advance research into cybercriminal activity. In this role, he will lead efforts to collect exposed data, analyze threat actor tactics, and turn those insights into actionable defenses. Hilligoss continues to oversee SpyCloud Labs, the organization's security research team recognized for industry excellence. (source) Jason Lancaster - SpyCloud Jason Lancaster has been named chief investigations officer at SpyCloud, with responsibility for shaping the firm's global investigations strategy and methodologies. He will guide the team that uncovers hidden threats and accelerates attribution across complex cybercrime investigations. Lancaster has been with SpyCloud since 2017, where he helped build and scale the investigations and solution engineering organization. (source) Dan Mountstephen has taken on the role of senior vice president and general manager for Asia Pacific and Japan at Okta, overseeing regional strategy and sales execution from Singapore. Okta positions identity as a core security control as organizations adopt cloud services and artificial intelligence. (source) Jeremy O'Donohue has been appointed as the managing director for state government and critical infrastructure at Kinetic IT, to look after strategy and delivery across public sector and essential services customers. He joins from Capgemini, where he led public sector operations across Australia and New Zealand. O'Donohue brings more than 20 years of experience spanning government, health, education, and critical infrastructure environments. (source) Simon Ractliffe has taken on responsibility for Rapid7's Asia-Pacific and Japan business as general manager, leading regional operations and growth strategy. In the role, he will oversee execution across threat detection and exposure management offerings. Ractliffe brings more than 30 years of experience across cybersecurity, cloud, and enterprise technology. (source) Krissy Safi - Clearwater Krissy Safi has joined Clearwater as senior vice president of consulting services, leading delivery across the company's cybersecurity and compliance consulting practice. She brings over two decades of experience building and managing global security consulting teams. Safi previously served at the US Department of State, where she worked on securing and standardizing embassy and consulate infrastructure worldwide. (source) Dave Bailey - Clearwater Dave Bailey has moved into an expanded role as vice president of consulting solutions and strategy at Clearwater. In this position, he will guide development of consulting offerings and align solution strategy with evolving client and regulatory needs. Bailey has been a senior leader within Clearwater's security services organization and has contributed to shaping its consulting portfolio. (source) Derek Whigham - Acumen Cyber Derek Whigham has joined Acumen Cyber as a non-executive director and strategic advisor, supporting the company's expansion in the UK. He has over 28 years of experience in cybersecurity and technology, most recently serving in the Chief Security Office at Lloyds Banking Group. At Acumen Whingham will focus on growth, product direction, and intelligence-led security operations. (source) Richard Lau has taken on the role of chief information officer for the Government of Bermuda, overseeing the Information and Digital Technologies office. He will lead IT strategy, infrastructure modernization, and cybersecurity under the Cabinet Office and Digital Innovation portfolio. Lau brings more than 25 years of experience in IT, cybersecurity, and critical infrastructure. (source) William Bengtson has joined ConductorOne as chief information security officer, taking responsibility for the company's security strategy as identity expands to include human, non-human, and AI agents. He has more than two decades of experience in securing cloud platforms, identity systems, and developer infrastructure. (source) Mark Francetic - Onapsis Mark Francetic has joined Onapsis as global head of partners and alliances, taking responsibility for the company's partner strategy across SAP, systems integrators, and resellers. He brings over 25 years of experience building alliance-led growth programs in cybersecurity, identity, and cloud markets. His role centers on strengthening joint go-to-market activity around SAP security. (source) John LoVerme - Onapsis John LoVerme has taken on the role of head of North America sales at Onapsis, overseeing regional sales execution and revenue growth. He brings experience scaling enterprise security businesses, including early leadership at Rapid7 and more than a decade leading global sales at Prevalent. LoVerme will focus on customer acquisition and partner-driven expansion across North America. (source) Nadine Rahman - Onapsis Nadine Rahman has joined Onapsis as head of international go-to-market, assuming responsibility for global field sales coordination, and international strategy. She brings over 20 years of experience in executive roles within SAP environments and industrial technology organizations. (source) Tim Britt has taken on the role of chief executive officer at Frontline Managed Services. He steps into the position with more than three decades of experience spanning consulting, systems integration, and managed services. At Frontline, his remit includes advancing tech-enabled services, cybersecurity capabilities, and AI-driven operations supporting law firms. (source) Arie Teter has joined DataGuard as chief product and technology officer, taking responsibility for product strategy and engineering. Based in London, he will oversee platform development. Teter brings senior product and engineering experience from cloud and cybersecurity companies. His background also includes engineering roles at Symantec and Check Point Software Technologies. (source) Rohan Pal has joined NCR Atleos as chief information officer, taking charge of the company's global technology strategy. In the role, Pal will oversee IT modernization, cybersecurity, cloud platforms, and digital product development. He has more than 25 years of technology experience in enterprise environments. Prior to Atleos, Pal served chief transformation officer at ServiceNow, with earlier senior roles spanning fintech, manufacturing, and retail organizations. (source) Dani Pickens has taken on the position of vice president of global channels at AgileBlue. Her remit covers the development of an enablement-first channel program supporting MSPs, resellers, distributors, and partners. Pickens brings a background in building and modernizing partner ecosystems within cybersecurity and cloud markets, with a focus on co-selling and execution at scale. (source) Patrick Rinski has taken on leadership of Unit 42 for Latin America at Palo Alto Networks, overseeing the company's threat intelligence and incident response operations. The role reflects increased focus on Latin America as cyber incidents grow in scale and sophistication. Rinski will guide regional response services, threat research, and advisory efforts tailored for local environments. He has over 20 years of experience in cybersecurity, risk management, and digital transformation. (source) Vinoo Srinivas Murali has taken on the position of chief revenue officer for data and AI at DigitalNet.ai, adding senior commercial leadership as the company expands adoption of its JanusAI platform and ATLAS autonomous cybersecurity system. Murali has over 25 years of enterprise sales and go-to-market experience in artificial intelligence, and cloud services. Murali previously spent 18 years at Microsoft in senior leadership roles covering Azure AI infrastructure, agentic AI, and global enterprise sales. (source)