Threat Intel Manager, Model Exploitation & Fraud
Anthropic · San Francisco, CA · Safeguards (Trust & Safety) · listed July 8, 2026
The shape of it
Seniority
Manager
Where
Hybrid
Stated pay
$375,000 – $455,000 USD
Requirements listed
7
Length
1,285 words
In the posting’s own words
We are looking for a threat intel manager to build and run our Model Exploitation & Fraud team within Threat Intelligence. This team detects, investigates, and disrupts the large-scale exploitation of Anthropic's AI systems. Model distillation, unauthorized access, account farming and reseller abuse, and fraud and scam operations.
What it asks for · 7
- Have led and managed investigative, fraud, platform integrity, or threat intelligence teams, ideally ones built around senior, deeply specialized individual contributors
- Have strong domain fluency in scaled abuse — fraud patterns, account abuse, unauthorized access, or platform exploitation economics — sufficient to set priorities, pressure-test findings, and earn the confidence of expert investigators
- Are proficient enough in SQL and Python to review data-heavy casework, pressure-test conclusions, and provide surge capacity when the team needs it
- Have experience overseeing investigations that track threat actors across surface, deep, and dark web environments, including reseller and access-broker communities
- Have working familiarity with large language models and a strong grasp of how models can be distilled, extracted, or exploited at scale
- Have built processes, detection systems, or programs from scratch and can show what changed because of them
- Communicate crisply with executives, engineers, and external partners alike
Also a plus
- Experience at a major technology platform on trust and safety, fraud, or abuse investigations at scale
- Background in financial crime investigation or fraud analytics
- Experience working directly with U.S. government stakeholders on threat reporting
- A track record of partnering with, growing, and retaining senior technical specialists, including defining clear scope between management and senior IC tracks
- Fluency in Mandarin Chinese and/or Russian with nuanced regional and geopolitical context
- Active Top Secret security clearance
What the job covers
- Own strategy, priorities, and outcomes for the Model Exploitation & Fraud mission area; define what we detect, investigate, action, and share
- Hire, manage, and develop a team of technical threat investigators; set the quality bar for casework and intelligence reporting
- Design clear lanes between this role and the team's senior individual contributors: strategy, people leadership, and program ownership sit with you, while ownership of the deepest technical investigations and tradecraft stays with the senior experts closest to the work
- Capable of independently leading complex investigations.
- Direct, prioritize, and resource complex investigations into model distillation, unauthorized AI R&D usage, unauthorized access, coordinated account abuse, and fraud/scam networks, partnering with the senior investigators who lead the deepest technical casework and clearing blockers from their path
- Drive the redesign of triage for a very high-volume detection pipeline: partner with investigators and engineering to build abuse signals, clustering, and agentic investigation workflows that separate sophisticated actors from noise
- Expand the team's coverage into fraud and scams, building the detection and investigation playbooks from the ground up
- Own the external engagement program for the area, including regular intelligence sharing with U.S. government partners and industry peers, ensuring the investigators driving the work are visible in those channels
- Anticipate how resellers, proxies, and third-party platforms change the abuse surface, and shape coverage accordingly
- Work with policy, enforcement, and engineering to convert findings into bans, product mitigations, and safety-by-design improvements
- Define and report the team's metrics; brief Safeguards and company leadership on the threat landscape
Tools and skills named
Languages
- Python
- SQL
Go to market
- Partnerships
Models & research
- LLM
Security & compliance
- Security
Words the posting leans on
- fraud8×
- investigations8×
- abuse7×
- investigators7×
- senior7×
- threat7×
- model6×
- technical6×
- platform5×
- area4×
- casework4×
- exploitation4×
- reseller4×
- systems4×
- actors3×
- build3×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Anthropic
- Account Executive, AI NativeNew York City, NY; San Francisco, CA | New York City, NY
- Account Executive - DNBSingapore
- Account Executive, Public SectorSydney, Australia
- Account Executive - Public Sector (ASEAN)Singapore
- Accounting, Revenue Internal ControlsSan Francisco, CA | Seattle, WA
- AI Fluency Education LeadSan Francisco, CA | New York City, NY