Safeguards Enforcement Analyst, Account Takeover & Credential Abuse
Safeguards Enforcement Analyst focused on account takeover and credential abuse. Investigate compromise incidents, design remediation workflows, partner with engineering on detection, enforce AI usage policies, and develop scalable enforcement programs for platform safety.
About the job
Key Responsibilities
- Investigate credential-compromise incidents across first-party and third-party platforms, tracing actor behavior across accounts and surfaces.
- Design and operate remediation workflows for compromised accounts: revocation, customer notification, and standards for restoring access.
- Partner with Engineering and Data Science teams to improve how we separate compromised-customer traffic from willful abuse.
- Enforce usage policies with a focus on detecting and mitigating potentially harmful use of AI systems.
- Work with threat intelligence on emerging credential-abuse patterns and the actors behind them.
- Support the Safeguards policy design team by providing detailed feedback on policy gaps based on real enforcement scenarios.
- Keep up to date with emerging AI policy enforcement best practices, and use these to inform our decision-making and workflows.
- Write the policy framework for compromise scenarios, including cases where Anthropic can't independently verify a customer's security posture.
- Act as the enforcement SME when account compromise intersects with active abuse investigations.
Minimum Qualifications
- Experience in trust and safety, fraud investigation, security operations, or a related field.
- Subject matter expertise in one or more of: account takeover, credential abuse, session security, or incident response.
- Experience designing or operating enforcement, remediation, or customer-recovery flows — not just detection.
- Comfort using data (SQL or similar tools) to trace actor behavior across accounts and to measure what's working.
- A thoughtful perspective on the tension between protecting the platform and restoring access for legitimate compromised customers.
- Strong written communication skills, with experience producing clear briefs about messy incidents for technical and non-technical stakeholders.
- Excellent judgment and the ability to collaborate with team members while navigating rapidly evolving priorities and workstreams.
Preferred Qualifications
- Familiarity with credential-theft ecosystems or threat intelligence tooling.
- Experience working with fraud/risk vendors (e.g., device or network intelligence platforms).
- Experience with API platform abuse specifically, not just consumer-account ATO.
- A deep interest in AI safety and responsible technology development.
- Experience writing effective prompts for generative AI systems in a content review or enforcement context.
Compensation & Logistics
- Annual Salary: $245,000—$285,000 USD
- Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
- Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
Skills
Trust And Safety, Fraud Investigation, Security Operations, Account Takeover, Credential Abuse, Incident Response, SQL, Threat Intelligence, Policy Enforcement, Ai Safety
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.