Technical Cyber Threat Investigator

Anthropic · Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC · Safeguards (Trust & Safety) · listed January 14, 2026

The shape of it

Seniority
Not stated
Where
Hybrid
Stated pay
$230,000 – $290,000 USD
Requirements listed
8
Length
1,085 words

In the posting’s own words

We are looking for a Technical Cyber Threat Investigator to join our Threat Intelligence team. In this role, you will be responsible for detecting, investigating, and disrupting the misuse of Anthropic's AI systems for malicious cyber operations.

What it asks for · 8

  • Have demonstrated proficiency in SQL and Python for data analysis and threat detection
  • Have experience with large language models and understanding of how AI technology could be misused for cyber threats
  • Have subject matter expertise in abusive user behavior detection, such as influence operations, coordinated inauthentic behavior, or cyber threat intelligence
  • Have experience tracking threat actors across surface, deep, and dark web environments
  • Can derive insights from large datasets to make key decisions and recommendations
  • Have experience with threat actor profiling and utilizing threat intelligence frameworks (MITRE ATT&CK, etc.)
  • Have strong project management skills and ability to build processes from the ground up
  • Possess excellent communication skills to collaborate with cross-functional teams and present to leadership

Also a plus

  • Experience working with government agencies or in regulated environments
  • Background in AI safety, machine learning security, or technology abuse investigation
  • Experience building and scaling threat detection systems or abuse monitoring programs
  • Active Top Secret security clearance

What the job covers

  • Detect and investigate attempts to misuse Anthropic's AI systems for cyber operations, including influence operations, malware development, social engineering, and other adversarial activities
  • Develop abuse signals and tracking strategies to proactively detect sophisticated threat actors across our platform
  • Create actionable intelligence reports on new attack vectors, vulnerabilities, and threat actor TTPs targeting LLM systems
  • Conduct cross-platform threat analysis grounded in real threat actor behavior, using open-source research, dark web monitoring, and internal data
  • Utilize investigation findings to implement systematic improvements to our safety approach and mitigate harm at scale
  • Study trends internally and in the broader ecosystem to anticipate how AI systems could be misused, generating and publishing reports
  • Build and maintain relationships with external threat intelligence partners, information sharing communities, and government stakeholders
  • Work cross-functionally to build out our threat intelligence program, establishing processes, tools, and best practices

Tools and skills named

Models & research
  • LLM2×
  • Machine learning
Languages
  • Python
  • SQL
Security & compliance
  • Security2×
Operations & finance
  • Project management
Ways of working
  • Cross-functional

Words the posting leans on

  • threat17×
  • actor6×
  • cyber6×
  • experience5×
  • systems5×
  • threat intelligence5×
  • detection4×
  • operations4×
  • abuse3×
  • behavior3×
  • build3×
  • investigation3×
  • misuse3×
  • safety3×
  • technology3×
  • threat actor3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Anthropic on August 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.