Passer au contenu principal
Publiée 6 août 2026

R&D Engineer - Thesis: Artificial Intelligence for cybersecurity in distributed and hybrid IT environments

Ekinops S.A.
Valbonne, Auvergne-Rhône-Alpes 1360, France CDI

Topic:
• Artificial intelligence for cybersecurity in distributed and hybrid IT environments

Industrial supervision team:
• Quentin Jacquemart (Ekinops)
• Amine Ismail (Ekinops)

Academic supervision team:
• Davide Balzarotti (Eurecom)

Location:
• Sophia-Antipolis, France

For over 20 years, Ekinops has been driving innovation in network systems. We provide solutions focused on the needs of communication service providers and enterprises worldwide. We provide open, trusted, and innovative network connectivity and enable our customers' success by delivering high value-added software-driven solutions. Today, over 120 international service providers, including numerous Tier 1 carriers around the world, trust our people and technologies. Over 50% of our 550+ strong team works in our multinational Agile R&D centers. Our company has a strong international background, with sales offices strategically located around the world. Ekinops is also recognized for its ESG commitments with its rating in the EthiFinance ESG Ratings report and its Gold Medal awarded by EcoVadis.
Context

Modern security strategies - such as those found in SASE and SSE solutions - combine security services deployed both in the cloud and at the edge. Their hybrid architecture spans endpoint agents, edge gateways, routers, firewalls, proxies, identity and access services, and cloud-native inspection engines. These platforms must now support an ever-expanding scope of security and governance requirements. Traditional antivirus capabilities continue to protect hosts and infrastructure from known threats, but modern systems must also defend data, identities, applications, their interactions, and, of course, end users. To this end, they incorporate data loss prevention, content inspection, traffic steering and filtering, proxy-based inspection, application access governance, device posture evaluation, policy enforcement, and auditing capabilities.

These distributed yet interconnected components generate a continuous stream of heterogeneous security data including operational events, identity and access indicators, application and service interactions, data-handling activities, and contextual information from end users. Traditional detection approaches struggle to interpret these multidimensional, dynamic information patterns. They were designed to identify threats based on a handful of discriminative indicators, not to reason simultaneously across network, identity, and data domains. Nor are they able to detect multiple subtle behavioural changes that become significant when several of them are considered together.

In addition, the threat landscape has grown more dynamic. AI enables attack techniques to evolve far faster than handcrafted detection rules can be written. Even the most conventional attacks can be subtly modified to evade traditional rule-based detection. Modern detection systems must correlate weak signals across time, context, and systems. At the same time, the growing maturity of AI technologies can harness the scale, diversity, and richness of cloud- and edge-generated telemetry to provide more adaptive, context-aware, and holistic detection approaches.

In this context, AI becomes an essential building block of modern cybersecurity. By unifying cloud and edge telemetry, AI-based systems can detect behavioural shifts, correlate weak or distributed indicators, and construct high-level models of threat activity. Generative and agentic AI further introduce new defensive capabilities, from interpreting and synthesizing events to proposing or orchestrating response actions, supporting continuous trust assessments, and adapting decision-making to context in real time. Rather than simply enhancing detection, these AI systems enable unified visibility and faster operational response in highly dynamic, distributed environments.

The research challenge to address in this PhD thesis is to leverage modern AI techniques to transform the wealth of security data from cloud and edge sources, extracted from Ekinops' SASE platform, into actionable security intelligence. Doing so requires moving beyond incremental refinements of traditional systems and developing AI-based approaches capable of interpreting complex environments, integrating heterogeneous viewpoints, and supporting security controls and response actions that must operate at scale and in real time. The aim is to design, implement, and validate methods that demonstrably strengthen detection and response across all classes of threats.

Research plan

The work is organized in four phases:
• First, conduct a comprehensive state-of-the-art review of threat detection and related security measures - from traditional techniques to AI-driven approaches - and of the open datasets commonly used for evaluation, with emphasis on the limitations of both the methods and the datasets.
• Second, based on that review and the available data, identify and develop one or more research directions to improve detection robustness beyond standalone signatures or rules, using multidimensional data streams and AI.
• Third, define evaluation frameworks-datasets, scenarios, and metrics-for the selected directions, to assess the effectiveness and limitations of the proposed methods.
• Finally, deepen and validate the chosen approaches and deliver demonstrable scientific and industrial outcomes (e.g., publications, prototypes, and results on representative use cases).

Profile

Applicants should hold a Master's or engineering degree (300 ECTS) in computer science, networking and telecommunications, cybersecurity, artificial intelligence, data science, or a related field.

The successful candidate will have a strong interest in cybersecurity, data analysis, and artificial intelligence - particularly as applied to threat detection. In addition, critical thinking, rigor, autonomy, and strong organizational skills are essential to carry out sustained research throughout the PhD.

Candidates are expected to be proficient in Python or Go for developing prototypes and conducting experiments. This includes solid experience with standard development tools (e.g., Git) and comfortable use of Linux (command line, scripting, remote access, system configuration, Docker). Familiarity with network and security analysis tools (such as tcpdump, Wireshark, tshark, Snort, or Suricata) would be an advantage. Prior experience with machine learning and data processing (e.g., scikit-learn, PyTorch, TensorFlow, NumPy) is also expected.

A strong command of English is essential for collaboration with supervisors and technical teams, as well as for publishing and presenting research findings at international conferences and in scientific journals.

Recruitment process

At Ekinops, we believe diversity makes us stronger! We hire talents based on skills, experience, and potential-nothing else. No matter your age, gender, background, or abilities, what matters to us is what you bring to the team. Join us and thrive in an inclusive, open-minded workplace where everyone has a voice!

S’inscrire aux alertes d’offres d’emploi