Project description
AMD is building a hardware-assisted security platform that uses silicon-level Performance Monitoring Counters (PMCs) and on-chip machine learning to detect advanced endpoint threats, including ransomware, fileless malware, and cryptojacking, at the processor layer, below OS-based evasion.
The platform collects CPU behavioral telemetry, classifies it through an ML inference engine, and exposes threat signals to security-software partners through a standardized API.
The project covers the full engineering path from silicon telemetry and data generation through ML training and validation, real-time inference, lab qualification, and partner integration.
The ML Engineer will lead the model-development and validation workstream, covering feature engineering, classifier development, model evaluation, inference optimization, and collaboration with systems engineers on runtime integration.
The role can be performed remotely from anywhere in Poland. Additional implementation details will be shared during the recruitment process in line with the applicable confidentiality requirements.
Responsibilities
- Design, train, and evaluate machine-learning classifiers using CPU behavioral telemetry, with an initial focus on distinguishing malicious and benign activity.
Perform feature engineering on hardware performance-counter data, including branch behavior, cache-miss patterns, instruction-mix ratios, and other processor-level measurements.
Frame and label datasets, select relevant input features, and determine suitable sampling and windowing parameters.
Develop evaluation frameworks covering precision, recall, F1 score, ROC-AUC, false-positive rate, detection performance, and inference latency.
Analyze model behavior across representative workloads and threat variants, identify coverage gaps, and iteratively improve accuracy and robustness.
Evaluate classification and anomaly-detection approaches, including methods suitable for limited or imbalanced malicious-data scenarios.
Optimize and quantize models for efficient inference on GPU or NPU hardware while balancing detection quality, latency, model size, and system overhead.
Export models to production-compatible inference formats and collaborate with real-time and systems engineers on runtime integration.
Define experiments, compare model architectures, and document the rationale behind feature, model, threshold, and operating-point decisions.
Document training-data provenance, model architecture, evaluation results, operating parameters, known limitations, and reproducibility requirements.
Maintain version control and reproducibility for training pipelines, experiment configurations, datasets, and model artifacts.
Work closely with the Lab Engineer, Real-Time Developer, and Technical Team Lead to align data collection, model development, and end-to-end platform validation.
SKILLS
Must have
- 4+ years of industry experience in applied machine learning, machine-learning engineering, or data science.
Strong proficiency in Python and hands-on experience with at least one major ML framework, such as PyTorch, TensorFlow, or scikit-learn.
Practical experience designing, training, and evaluating binary or multi-class classification models.
Experience working with tabular, time-series, event, sensor, telemetry, or other structured numerical data.
Solid understanding of model evaluation and validation, including cross-validation, precision, recall, F1 score, ROC-AUC, class imbalance, threshold selection, and false-positive analysis.
Experience with feature engineering, data preparation, experiment design, and iterative model improvement.
Understanding of model optimization for inference, including quantization, pruning, ONNX export, or equivalent techniques.
Experience taking ML work beyond exploratory notebooks into reproducible engineering workflows or production-oriented environments.
Ability to clearly document model decisions, evaluation results, data assumptions, experiment configurations, and known limitations.
Ability to cooperate with software and systems engineers on model integration and runtime constraints.
University degree in computer science, electrical engineering, computer engineering, data science, mathematics, or an equivalent field.
Nice to have
Experience with anomaly detection, novelty detection, outlier detection, or one-class classification.
Background in cybersecurity, malware analysis, endpoint threat detection, fraud detection, behavioral analytics, or another adversarial detection domain.
Familiarity with hardware performance counters, system telemetry, processor profiling, or low-level behavioral data used as ML input features.
Experience with time-window selection, signal framing, sampling strategies, feature selection, or feature pruning for sequential telemetry.
Experience training or optimizing models for deployment on GPU, NPU, edge, embedded, or other hardware accelerators.
Hands-on experience with ONNX, ONNX Runtime, OpenVINO, TensorRT, TensorFlow Lite, or comparable inference runtimes.
Experience balancing model accuracy against latency, model size, compute utilization, power, or system-overhead constraints.
Experience with explainability or model-interpretability techniques applicable to classification and anomaly-detection systems.
Experience with imbalanced datasets, limited positive samples, synthetic data, or evaluation under dataset shift.
Understanding of processor architecture, system performance, or hardware/software interaction.
Research-to-production experience, including reproducible experimentation, model versioning, deployment, monitoring, or regression testing.