Threat Intel Manager, Model Exploitation & Fraud

Anthropic · San Francisco, CA · Safeguards (Trust & Safety) · listed July 8, 2026

The shape of it

Seniority
Manager
Where
Hybrid
Stated pay
$375,000 – $455,000 USD
Requirements listed
7
Length
1,285 words

In the posting’s own words

We are looking for a threat intel manager to build and run our Model Exploitation & Fraud team within Threat Intelligence. This team detects, investigates, and disrupts the large-scale exploitation of Anthropic's AI systems. Model distillation, unauthorized access, account farming and reseller abuse, and fraud and scam operations.

What it asks for · 7

  • Have led and managed investigative, fraud, platform integrity, or threat intelligence teams, ideally ones built around senior, deeply specialized individual contributors
  • Have strong domain fluency in scaled abuse — fraud patterns, account abuse, unauthorized access, or platform exploitation economics — sufficient to set priorities, pressure-test findings, and earn the confidence of expert investigators
  • Are proficient enough in SQL and Python to review data-heavy casework, pressure-test conclusions, and provide surge capacity when the team needs it
  • Have experience overseeing investigations that track threat actors across surface, deep, and dark web environments, including reseller and access-broker communities
  • Have working familiarity with large language models and a strong grasp of how models can be distilled, extracted, or exploited at scale
  • Have built processes, detection systems, or programs from scratch and can show what changed because of them
  • Communicate crisply with executives, engineers, and external partners alike

Also a plus

  • Experience at a major technology platform on trust and safety, fraud, or abuse investigations at scale
  • Background in financial crime investigation or fraud analytics
  • Experience working directly with U.S. government stakeholders on threat reporting
  • A track record of partnering with, growing, and retaining senior technical specialists, including defining clear scope between management and senior IC tracks
  • Fluency in Mandarin Chinese and/or Russian with nuanced regional and geopolitical context
  • Active Top Secret security clearance

What the job covers

  • Own strategy, priorities, and outcomes for the Model Exploitation & Fraud mission area; define what we detect, investigate, action, and share
  • Hire, manage, and develop a team of technical threat investigators; set the quality bar for casework and intelligence reporting
  • Design clear lanes between this role and the team's senior individual contributors: strategy, people leadership, and program ownership sit with you, while ownership of the deepest technical investigations and tradecraft stays with the senior experts closest to the work
  • Capable of independently leading complex investigations.
  • Direct, prioritize, and resource complex investigations into model distillation, unauthorized AI R&D usage, unauthorized access, coordinated account abuse, and fraud/scam networks, partnering with the senior investigators who lead the deepest technical casework and clearing blockers from their path
  • Drive the redesign of triage for a very high-volume detection pipeline: partner with investigators and engineering to build abuse signals, clustering, and agentic investigation workflows that separate sophisticated actors from noise
  • Expand the team's coverage into fraud and scams, building the detection and investigation playbooks from the ground up
  • Own the external engagement program for the area, including regular intelligence sharing with U.S. government partners and industry peers, ensuring the investigators driving the work are visible in those channels
  • Anticipate how resellers, proxies, and third-party platforms change the abuse surface, and shape coverage accordingly
  • Work with policy, enforcement, and engineering to convert findings into bans, product mitigations, and safety-by-design improvements
  • Define and report the team's metrics; brief Safeguards and company leadership on the threat landscape

Tools and skills named

Languages
  • Python
  • SQL
Go to market
  • Partnerships
Models & research
  • LLM
Security & compliance
  • Security

Words the posting leans on

  • fraud8×
  • investigations8×
  • abuse7×
  • investigators7×
  • senior7×
  • threat7×
  • model6×
  • technical6×
  • platform5×
  • area4×
  • casework4×
  • exploitation4×
  • reseller4×
  • systems4×
  • actors3×
  • build3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Anthropic

every open role at Anthropic

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Anthropic on August 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.