Skip to content
AnthropicAnthropic

Threat Intel Manager, Model Exploitation & Fraud

Lead the Model Exploitation & Fraud team in Threat Intelligence at Anthropic. Set strategy, hire and manage technical investigators, direct complex investigations into AI model distillation, account abuse, and fraud networks, and engage with U.S. government partners. Requires management experience with senior ICs, domain expertise in scaled abuse, and proficiency in SQL/Python.

About the job

Key Responsibilities

  • Own strategy, priorities, and outcomes for the Model Exploitation & Fraud mission area; define what we detect, investigate, action, and share.
  • Hire, manage, and develop a team of technical threat investigators; set the quality bar for casework and intelligence reporting.
  • Design clear lanes between this role and the team's senior individual contributors: strategy, people leadership, and program ownership sit with you, while ownership of the deepest technical investigations and tradecraft stays with the senior experts closest to the work.
  • Capable of independently leading complex investigations.
  • Direct, prioritize, and resource complex investigations into model distillation, unauthorized AI R&D usage, unauthorized access, coordinated account abuse, and fraud/scam networks, partnering with the senior investigators who lead the deepest technical casework and clearing blockers from their path.
  • Drive the redesign of triage for a very high-volume detection pipeline: partner with investigators and engineering to build abuse signals, clustering, and agentic investigation workflows that separate sophisticated actors from noise.
  • Expand the team's coverage into fraud and scams, building the detection and investigation playbooks from the ground up.
  • Own the external engagement program for the area, including regular intelligence sharing with U.S. government partners and industry peers, ensuring the investigators driving the work are visible in those channels.
  • Anticipate how resellers, proxies, and third-party platforms change the abuse surface, and shape coverage accordingly.
  • Work with policy, enforcement, and engineering to convert findings into bans, product mitigations, and safety-by-design improvements.
  • Define and report the team's metrics; brief Safeguards and company leadership on the threat landscape.

Minimum Qualifications

  • Have led and managed investigative, fraud, platform integrity, or threat intelligence teams, ideally ones built around senior, deeply specialized individual contributors.
  • Have strong domain fluency in scaled abuse — fraud patterns, account abuse, unauthorized access, or platform exploitation economics — sufficient to set priorities, pressure-test findings, and earn the confidence of expert investigators.
  • Are proficient enough in SQL and Python to review data-heavy casework, pressure-test conclusions, and provide surge capacity when the team needs it.
  • Have experience overseeing investigations that track threat actors across surface, deep, and dark web environments, including reseller and access-broker communities.
  • Have working familiarity with large language models and a strong grasp of how models can be distilled, extracted, or exploited at scale.
  • Have built processes, detection systems, or programs from scratch and can show what changed because of them.
  • Communicate crisply with executives, engineers, and external partners alike.

Preferred Qualifications

  • Experience at a major technology platform on trust and safety, fraud, or abuse investigations at scale.
  • Background in financial crime investigation or fraud analytics.
  • Experience working directly with U.S. government stakeholders on threat reporting.
  • A track record of partnering with, growing, and retaining senior technical specialists, including defining clear scope between management and senior IC tracks.
  • Fluency in Mandarin Chinese and/or Russian with nuanced regional and geopolitical context.
  • Active Top Secret security clearance.

Education and Experience

  • Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience.
  • Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience.
  • Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position.

Skills

SQL, Python, Threat Intelligence, Fraud Detection, Model Distillation, Account Abuse, Dark Web Investigation, LLMs, Government Engagement

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Anthropic

Anthropic

San Francisco, CA
Platform Security Engineer, DRTM / Secure Launch
$320k+/yrHybrid8+ YOESecurity Engineering

Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.