PUNCH Cyber Analytics Group (PUNCH) is a Virginia-based, small business founded in 2012 operating as a cohesive team that incorporates the sum of our group's diverse skills, talents, and resources toward our collective passion: advancing data analytics to impact cyber operations. PUNCH is a two-time Inc. Magazine ‘Best Workplaces' awardee offering unique benefits and personal touches to provide a positive work-life experience for our team. PUNCH brings unique qualifications, resources, and past-performance that make us suitable to address the goals of our diverse customer-base. Further, we have past and current experience supporting cyber operations and cyber ML-based research, with well over 100 years of collective experience from our collaborative, multi-disciplinary team.
Responsibilities
Develop and evaluate machine-learning analytics for cyber defense use cases using network, sensor, alert, asset, and other operational telemetry.
Build unsupervised and statistical models for clustering, anomaly/outlier detection, behavioral baselining, novelty detection, and pattern discovery.
Apply techniques such as graph analytics/embeddings, nearest-neighbor methods, time-series or periodicity analysis, clustering, dimensionality reduction, and anomaly scoring to large cyber datasets.
Design models and features that account for concept drift, noisy data, incomplete ground truth, and high false-positive rates common in operational cyber environments.
Support asset discovery and entity resolution, including development of probabilistic asset graphs that associate IPs, hostnames, MAC addresses, services, certificates, device attributes, and other observations across data sources.
Develop contextual features from security alerts and network telemetry, including temporal patterns, rarity/frequency, communication behavior, entity context, and related activity, and use those features to identify meaningful alert clusters and outliers.
Work with cyber analysts and detection engineers to turn operational questions and adversary behaviors into measurable features, experiments, and analytics.
Evaluate model effectiveness using appropriate quantitative metrics and operational validation; benchmark accuracy, false-positive behavior, computational performance, and usefulness to analysts.
Develop production-quality Python code and work with engineers to integrate models into sensor-side CPU environments as well as larger GPU-enabled enterprise analytics platforms.
Understand the practical strengths and limitations of LLMs: know when to use an LLM, when to use conventional ML/statistics, and when a deterministic rule or query is the better answer.
Ability to build evaluation harnesses rather than judge AI output by vibes—test datasets, expected behaviors, regression tests, failure cases, and quantitative measures.
Qualifications
BS or MS in Data Science, Computer Science, Statistics, Applied Mathematics, Engineering, Cybersecurity, or a related quantitative discipline.
Strong Python skills and hands-on experience with common scientific/ML tooling such as pandas, NumPy, scikit-learn, SciPy, and related libraries.
Strong understanding of unsupervised machine learning, including clustering, anomaly/outlier detection, similarity/distance methods, feature engineering, and statistical baselining.
Experience with at least some of the following: graph analytics or graph ML, entity resolution/record linkage, probabilistic modeling, time-series analysis, change-point/concept-drift detection, nearest-neighbor methods, or dimensionality reduction.
Experience working with large, noisy, heterogeneous datasets where labels or authoritative ground truth are limited.
Familiarity with scalable data processing and efficient model implementation; comfortable thinking about CPU/memory constraints as well as GPU acceleration for larger workloads.
Working knowledge of networking and cybersecurity concepts such as IP addressing, DNS, TLS, network flows, ports/services, routing, network devices, and security alerts.
Experience with cyber/network telemetry such as Zeek, PCAP-derived data, SIEM data, IDS/IPS alerts, device configuration data, or vulnerability/asset data is highly desirable.
Experience with graph/network-analysis libraries, SQL/data stores, Elasticsearch/Splunk, or similar analytic platforms is a plus.
Experience developing analytics for cybersecurity, threat hunting, detection engineering, or defensive cyber operations is strongly preferred.
Numbers & Facts
Location
Reston, VA
Skills
Analysis Skillsunmatched
Artificial Intelligence (AI)unmatched
Benchmarkingunmatched
CPU (Central Processing Unit)unmatched
Computer Scienceunmatched
Cross-Functionalunmatched
Cyber Threat Huntingunmatched
DNS (Domain Name System)unmatched
Data Analysisunmatched
Data Processingunmatched
Data Scienceunmatched
Data Setsunmatched
Elasticsearchunmatched
Failure Analysisunmatched
GPU (Graphics Processing Unit)unmatched
IP Addressingunmatched
Internet Securityunmatched
Intrusion Detection Systemsunmatched
Intrusion Prevention Systemsunmatched
Machine Learningunmatched
Machine Toolunmatched
Mathematicsunmatched
Media Access Control (MAC)unmatched
Memory Hardwareunmatched
Metricsunmatched
Network Performance/Analysisunmatched
Network Routingunmatched
Network Securityunmatched
Operational Supportunmatched
Python Programming/Scripting Languageunmatched
Regression Testingunmatched
SQL (Structured Query Language)unmatched
SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
Security Information and Event Management (SIEM)unmatched
Small Businessunmatched
Software Engineeringunmatched
Splunkunmatched
Statistical Modelingunmatched
Statisticsunmatched
Team Playerunmatched
Telemetryunmatched
Test Caseunmatched
Time Series Analysisunmatched
Use Casesunmatched
Web Analyticsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.