Applied Data Scientist — Intent Drift Detection Backslash Security · Realtime AI-agent protection About Backslash We are builders who want to secure the next generation of software development from the inside out. Softwa…
Skills: Applied Data Science, Python, PyTorch, HuggingFace, LLM
Senior Sales Engineer – Backslash Security (USA) - Central / West Coast Backslash Security is redefining endpoint security for the AI era. As organizations rapidly adopt AI agents, copilots, and autonomous workflows, new…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
Posted 6d ago
~40 hrs/week
Responsibilities
You will own the end-to-end development of intent-drift detection models for AI agents, including data strategy and pipeline design. You will be responsible for training and optimizing small models to run locally on developer machines with high performance.
Requirements
The role requires 3-5 years of experience in applied data science, specifically in problem framing, data strategy, and model evaluation. Candidates must be proficient in Python, PyTorch, and local fine-tuning of small language models.
Full job description
Applied Data Scientist — Intent Drift Detection
Backslash Security · Realtime AI-agent protection
About Backslash
We are builders who want to secure the next generation of software development from the inside out.
Software development has entered a new era defined by vibe-coding, MCP servers, and AI agents. While these tools allow developers to build faster than ever, they also introduce a completely new frontier of security challenges that exist directly on the engineer's machine.
Backslash is building the security layer for this new reality. We provide the essential guardrails and visibility needed to secure AI-driven workflows. By actively protecting developer computers and monitoring IDE-based AI interactions, we ensure the future of coding is as secure as it is fast.
The Role
AI coding agents run with enormous privilege on developer machines. When untrusted content steers one off its task, classical security sees only the final action — never that the agent's intent drifted. Detecting that drift, in realtime, on-device, is an open problem. No one has solved it. You will.
You will own intent-drift detection end-to-end — from the data to the model:
Build the Dataset: Design and generate the data that defines what "drift" looks like, and co-design the pipeline that creates it.
Train Small, Ship Local: Fine-tune, distill, and shrink the models that detect drift in realtime — small enough to run fully on-device, no cloud.
Shape the Architecture: Decide what's a model, what's a rule, and what's a gate. The detector's design is your call.
Measure What Matters: Build the evaluation harness — realtime detection at very low false-positive rates on a developer's machine is the product.
You own intent-drift analysis as a problem, not a ticket.
Requirements
Applied Data Science End-to-End: 3–5 years turning ambiguous problems into working models — problem framing, data collection and labeling strategy, feature/representation design, training, and evaluation. You've owned a dataset and the model that consumed it.
Small-Model Fluency: Comfortable fine-tuning small open models locally — DeBERTa-class encoders, ≤8B decoders, LoRA, quantization, single-GPU workflows.
Applied-Research Mindset: You approach an open research problem with passion and a practical, ship-it attitude.
Independence: You want an impactful, strategic problem in LLM security — not a ticket queue.
Startup DNA: Can-do, fast, a true partner. Non-negotiable.
Local-first by design. Python, PyTorch, HuggingFace, ≤8B models.
Bonus Points For
Security Background: Prompt injection, MITRE ATLAS, agent security — or the hunger to learn it fast.
Adversarial ML: Experience with LLM evaluation, red-teaming, or building adversarial datasets.
Endpoint Software: Familiarity with software that runs locally on developer machines with a low resource footprint.
Backslash secures the agentic AI fabric across all endpoints, providing visibility, governance and real-time protection.
Industry
Computer and Network Security
Company size
11-50 employees
Founded
2022
Headquarters
Tel-Aviv
LinkedIn followers
3,918
Backslash Security - Agentic AI endpoints. Secured.
Your developers are no longer just writing code. They're running AI coders, agents, MCP servers, Skills, hooks, and plugins - a fast-spreading agentic fabric that lives on every developer workstation and citizen-developer endpoint. Unseen, ungoverned, and unprotected, it's the enterprise's new attack surface.
Backslash gives security teams full control over the agentic AI stack - at the endpoint.
→ See it. End-to-end visibility across your AI inventory, from agents and MCPs to Skills, hooks, LLMs, and plugins. Risky components isolated and prioritized for remediation, instantly.
→ Govern it. Centralized policies that enforce secure configurations, contextual permissions, and allowlisting of trusted components — hardening your environment against shadow AI and vibe coding risk.
→ Protect it. Real-time detection of prompt injection, data exfiltration, privilege escalation, and drift across every agentic action — with a harness-layer audit trail that traditional EDRs miss.
Backslash covers the tools your teams already use, including Claude, GitHub Copilot, Cursor, Windsurf, Antigravity, Codex, and OpenClaw, plus the MCPs and Skills connected to them.
The result: security teams finally get to be the department of YES.
Say yes to AI coding. Securely. → backslash.security/demo
Offices: 28 HaArba'a St., Tel-Aviv, IL · 28 HaArba'a St., Tel-Aviv, 19709, IL
AI SecurityAI code securityCursorAIWindsurfAgentic AI EndpointsAgentic AIAgentic securityAI Coding securitySkills securityHooks security
Backslash secures the agentic AI fabric across all endpoints, providing visibility, governance and real-time protection.
Industry
Computer and Network Security
Company size
11-50 employees
Founded
2022
Headquarters
Tel-Aviv
LinkedIn followers
3,918
Backslash Security - Agentic AI endpoints. Secured.
Your developers are no longer just writing code. They're running AI coders, agents, MCP servers, Skills, hooks, and plugins - a fast-spreading agentic fabric that lives on every developer workstation and citizen-developer endpoint. Unseen, ungoverned, and unprotected, it's the enterprise's new attack surface.
Backslash gives security teams full control over the agentic AI stack - at the endpoint.
→ See it. End-to-end visibility across your AI inventory, from agents and MCPs to Skills, hooks, LLMs, and plugins. Risky components isolated and prioritized for remediation, instantly.
→ Govern it. Centralized policies that enforce secure configurations, contextual permissions, and allowlisting of trusted components — hardening your environment against shadow AI and vibe coding risk.
→ Protect it. Real-time detection of prompt injection, data exfiltration, privilege escalation, and drift across every agentic action — with a harness-layer audit trail that traditional EDRs miss.
Backslash covers the tools your teams already use, including Claude, GitHub Copilot, Cursor, Windsurf, Antigravity, Codex, and OpenClaw, plus the MCPs and Skills connected to them.
The result: security teams finally get to be the department of YES.
Say yes to AI coding. Securely. → backslash.security/demo
Offices: 28 HaArba'a St., Tel-Aviv, IL · 28 HaArba'a St., Tel-Aviv, 19709, IL
AI SecurityAI code securityCursorAIWindsurfAgentic AI EndpointsAgentic AIAgentic securityAI Coding securitySkills securityHooks security