Technical Threat Investigator, Threat Intel Engineering
Conducts deep investigations into sophisticated threat actors misusing AI models and targeting OpenAI, leveraging OSINT, telemetry, and scripting to identify disruptions. Builds scalable tooling and automations to enhance detection and safety, partnering cross-functionally for impact.
About the job
Responsibilities
- Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI's models, products, and broader ecosystem.
- Think like an adversary—model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity.
- Leverage internal telemetry, OSINT, vendor data, and in-house safety systems to produce high-confidence findings on adversarial use of our models in cyber operations, platform abuse, and threats targeting OpenAI.
- Translate investigative findings into concrete improvements across detection, enforcement, intel, and safety pipelines.
- Build tooling, scripts, automations, and agentic workflows that scale investigative throughput and reduce manual effort.
- Prototype solutions in ambiguous and emerging problem spaces, including new product surfaces, novel attacker behaviors, and areas where existing coverage may be limited.
- Partner closely with teams across Security, Safety Systems, Product Policy, and Integrity to operationalize findings and drive meaningful outcomes.
- Produce clear, high-signal written outputs and recommendations that inform decision-making across technical and executive stakeholders.
Requirements
- Experience in threat intelligence, incident response, offensive security, or a closely related field.
- Solid experience investigating sophisticated threat actors, including model misuse, platform abuse, or other adversarial activity in complex environments.
- Strong understanding of adversary behavior, infrastructure, and tradecraft, and the ability to apply that understanding to proactive investigations.
- Demonstrated ability to independently drive deep technical investigations from ambiguous signals through to clear, actionable findings.
- Experience using AI to extend or accelerate investigative workflows.
- Strong scripting ability and comfort building lightweight automation, investigative tooling, or workflows that improve scale and repeatability.
- Strong ability to leverage telemetry from diverse systems and vendors to drive investigations, including directly querying, extracting, and stitching together data where needed.
- Strong written and verbal communication skills, especially the ability to translate technical investigations into high-signal outputs for diverse stakeholders.
- Comfort operating independently in ambiguous, fast-moving problem spaces with minimal oversight.
Skills
Osint, Threat Intelligence, Incident Response, Offensive Security, Scripting, Automation, Telemetry Analysis, AI Workflows, Adversary Tradecraft, Investigative Tooling
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.