PhD Position in Explainable Incident Response

2 weken geleden


Enschede, Overijssel, Nederland University of Twente Voltijd

In the realm of cybersecurity, the increasing deployment of machine learning (ML) solutions in Security Operations Centres (SOCs) has led to a surge in false positives and a lack of understanding in how these systems work. The forensic analysis of incidents and incident response remain largely manual procedures, resulting in analyst burnout and 'alert fatigue'.

The objective of this PhD project is to create 'AI-assisted practitioners' for incident response by developing novel ML algorithms that reduce analyst workload and provide decision-making assistance. We propose to develop explainable ML algorithms that summarize large volumes of observable data (intrusion alerts, network & system logs) in order to discover contextually meaningful patterns from them. The student will explore multi-modal learning and generative AI to produce actionable explanations from these discovered patterns that are tailored to the operator's expertise. The evaluation of these algorithms will be done under closed-world and open-world settings. For the closed-world setting, a major challenge is the lack of suitable datasets to evaluate ML models. The student will set up a testbed together with our industry collaborators for the collection of intrusion alert datasets. For the open-world setting, the student will deploy these algorithms in real SOC environments in order to measure the extent of workload reduction experienced by security analysts. In doing so, we aim to develop technologies that are not only novel but also have real-world applications.

The PhD student will be embedded within the Semantics, Cybersecurity, and Services (SCS) group at University of Twente. The student will have the opportunity to participate in internships and/or collaboration with industry partners under the TUCCR initiative. The SCS group offers a stimulating, supportive, and diverse research environment, as well as plenty of opportunities for personal and professional growth.

Your Profile

  • You are a highly motivated and enthusiastic researcher, aspiring to do world-class research and have real-world impact.
  • You have a MSc degree with excellent grades in computer science, or similar; Applications from students who are about to finish their MSc degree studies will be considered as well.
  • You are interested in the domain of cybersecurity and have a solid background in systems security and/or data science/artificial intelligence; Some industrial experience in a cybersecurity role and prior experience with writing scientific papers are of additional advantage.
  • You know your way around UNIX/Linux systems and can code in Python.
  • You are curious and interested in learning how things work and how to make them better.
  • You have a creative mind-set and excellent analytical and communication skills.
  • You have good team spirit and like to work in an interdisciplinary and internationally oriented environment.
  • You are proficient in English.

Our Offer

  • As a PhD candidate at UT, you will be appointed to a full-time position for four years, with a qualifier in the first year, within a very stimulating and exciting scientific environment;
  • The University offers a dynamic ecosystem with enthusiastic colleagues;
  • Your salary and associated conditions are in accordance with the collective labour agreement for Dutch universities (CAO-NU);
  • You will receive a gross monthly salary ranging from € 2.770,- (first year) to € 3.539,- (fourth year);
  • There are excellent benefits including a holiday allowance of 8% of the gross annual salary, an end-of-year bonus of 8.3%, and a solid pension scheme;
  • The flexibility to work (partially) from home;
  • A minimum of 232 leave hours in case of full-time employment based on a formal workweek of 38 hours. A full-time employment in practice means 40 hours a week, therefore resulting in 96 extra leave hours on an annual basis;
  • Free access to sports facilities on campus;
  • A family-friendly institution that offers parental leave (both paid and unpaid);
  • You will have a training programme as part of the Twente Graduate School where you and your supervisors will determine a plan for a suitable education and supervision;
  • We encourage a high degree of responsibility and independence, while collaborating with close colleagues, researchers and other staff.


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Job DescriptionIn today's digital landscape, cybersecurity threats are becoming increasingly sophisticated. To combat these threats, organizations are turning to machine learning (ML) solutions to enhance their security operations. However, the deployment of ML systems in Security Operations Centres (SOCs) has created new challenges. One of the primary...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Job DescriptionIn today's digital landscape, cybersecurity threats are becoming increasingly sophisticated. To combat these threats, organizations are turning to machine learning (ML) solutions to enhance security coverage and reduce the number of missed attacks. However, these ML systems often create many false positives, making it difficult to understand...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    In the realm of cybersecurity, the increasing deployment of machine learning (ML) solutions in Security Operations Centres (SOCs) has led to a surge in false positives and a lack of understanding in how these systems work. To address this, the University of Twente is seeking a highly motivated PhD candidate to develop novel ML algorithms that reduce analyst...


  • Enschede, Overijssel, Nederland Universiteit Twente Voltijd

    About the PositionWe are seeking a highly motivated PhD researcher to join our team at the University of Twente. The successful candidate will be part of the Semantics, Cybersecurity, and Services (SCS) group, which focuses on advancing the development of innovative online services with improved quality through context alignment and reduced security and...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    At the University of Twente, we are seeking a highly motivated PhD candidate to join our Semantics, Cybersecurity, and Services (SCS) group. The successful candidate will be part of a dynamic ecosystem with enthusiastic colleagues, working on a challenging project that addresses the increasing adoption of machine learning (ML) in Security Operations Centres...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    PhD Researcher in Explainable Incident ResponseIn today's digital landscape, cybersecurity threats are becoming increasingly sophisticated, making it challenging for security analysts to respond effectively. To address this issue, we are seeking a highly motivated PhD researcher to work on developing explainable AI algorithms for incident response. The goal...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Job DescriptionIn the realm of cybersecurity, the increasing deployment of machine learning (ML) solutions in Security Operations Centres (SOCs) has led to a surge in false positives and a lack of understanding of how these systems work. The forensic analysis of incidents and incident response are largely manual procedures, resulting in analyst burnout and...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    In the realm of cybersecurity, the increasing deployment of machine learning solutions in Security Operations Centres (SOCs) has led to a surge in false positives and a lack of understanding in how these systems work. The forensic analysis of incidents and incident response are largely manual procedures, resulting in analyst burnout and 'alert fatigue'.The...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Job DescriptionIn today's digital landscape, cybersecurity threats are becoming increasingly sophisticated. To combat these threats, organizations are turning to machine learning (ML) solutions to enhance security coverage and reduce the number of missed attacks. However, these ML systems often create many false positives and can be difficult to understand,...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    PhD Position in Artificial MicroswimmersWe are seeking a highly motivated and skilled PhD candidate to join our research team at the University of Twente. The successful candidate will work on developing artificial microswimmers capable of autonomous motion and transport in 3D.About the ProjectThe primary objective of this project is to develop a unique...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    PhD Position in Artificial MicroswimmersWe are seeking a highly motivated and skilled PhD candidate to join our research team at the University of Twente. The successful candidate will work on developing artificial microswimmers capable of autonomous motion and transport in 3D.About the ProjectThe primary objective of this project is to develop a unique...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    PhD Position in Artificial MicroswimmersWe are seeking a highly motivated and curious PhD candidate to join our research team at the University of Twente. The successful candidate will work on developing artificial microswimmers capable of autonomous motion and transport in 3D.About the ProjectThe primary objective of this project is to develop a unique...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    PhD Position in Artificial MicroswimmersWe are seeking a highly motivated and skilled PhD candidate to join our research team at the University of Twente. The successful candidate will work on developing artificial microswimmers capable of autonomous motion and transport in 3D.About the ProjectThe primary objective of this project is to develop a unique...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    We are seeking a highly motivated PhD researcher to join our team at the University of Twente, MESA+ Institute for Nanotechnology, to work on a fully funded PhD position in the field of active soft matter. The primary objective of this project is to develop a unique experimental model system to better understand the dynamic self-organization of...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    PhD Position in Artificial MicroswimmersWe are seeking a highly motivated and skilled PhD candidate to join our research team at the University of Twente, MESA+ Institute for Nanotechnology. The successful candidate will work on developing artificial microswimmers capable of autonomous motion and transport in 3D.About the ProjectThe primary objective of this...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    About the PositionThe University of Twente is seeking a highly motivated and enthusiastic PhD candidate to join the Radio Systems group. The successful candidate will be part of a dynamic and international research environment, working on the development of novel dual-scenario beamforming concepts for joint communication and sensing (JCAS) in future 6G...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Research Opportunity: Decentralized Multiagent Reinforcement LearningWe are seeking a highly motivated PhD candidate to join our research team in the field of decentralized multiagent reinforcement learning. The successful candidate will be responsible for designing and developing novel algorithms for equilibrium selection control in decentralized multiagent...


  • Enschede, Overijssel, Nederland Universiteit Twente Voltijd

    Job DescriptionWe are seeking a highly motivated PhD candidate to join our research team in the field of numerical mathematics. The successful candidate will work on the development of reduced-order models of port-Hamiltonian systems, focusing on both analysis and application.The project involves the review and development of new methods for model reduction...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Job DescriptionWe are seeking a highly motivated PhD researcher to join our team at the University of Twente. The successful candidate will be part of a 3-year project focused on developing a resilience toolbox for multimodal logistics.Main ObjectivesDevelop a resilience toolbox to support companies and public stakeholders in developing resilient...


  • Enschede, Overijssel, Nederland University of Twente Voltijd

    Job Opportunity at the University of TwenteThe University of Twente is seeking a highly motivated and enthusiastic researcher to join our Integrated Circuit Design (ICD) group. As a PhD researcher, you will be part of a dynamic and collaborative team working on various aspects of analog and Radio Frequency (RF) Integrated Circuits.About the ICD GroupThe ICD...