Technical Threat Investigator, Threat Intel Engineering

Remote San Francisco FullTime

Posted 4mo ago

Job Location

San Francisco

Tech Stack

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

As a Technical Threat Investigator at OpenAI, you will play a crucial role in safeguarding the company and the broader ecosystem from sophisticated adversaries. This deeply investigative position requires you to conduct complex, end-to-end investigations into threat actors to understand their methodologies, infrastructure, and integration of AI into their operations. Your insights will be instrumental in proactively identifying malicious activity and driving improvements in detection, disruption, enforcement, and safety across the organization. You will translate your findings into scalable, durable solutions by building and owning lightweight tooling, automating processes, and developing AI-assisted workflows to enhance the speed, repeatability, and effectiveness of investigations.

Responsibilities

  • Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI’s models, products, and ecosystem.
  • Model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity.
  • Leverage internal telemetry, OSINT, vendor data, and safety systems to produce high-confidence findings on adversarial use of models in cyber operations, platform abuse, and threats targeting OpenAI.
  • Translate investigative findings into concrete improvements across detection, enforcement, intel, and safety pipelines.
  • Build tooling, scripts, automations, and agentic workflows to scale investigative throughput and reduce manual effort.
  • Prototype solutions in ambiguous and emerging problem spaces, including new product surfaces and novel attacker behaviors.
  • Partner closely with Security, Safety Systems, Product Policy, and Integrity teams to operationalize findings and drive outcomes.
  • Produce clear, high-signal written outputs and recommendations for technical and executive stakeholders.

Requirements

  • Experience in threat intelligence, incident response, offensive security, or a related field.
  • Solid experience investigating sophisticated threat actors, including model misuse, platform abuse, or other adversarial activity.
  • Strong understanding of adversary behavior, infrastructure, and tradecraft, applied to proactive investigations.
  • Demonstrated ability to independently drive deep technical investigations from ambiguous signals to actionable findings.
  • Experience using AI to extend or accelerate investigative workflows.
  • Strong scripting ability and comfort building lightweight automation and investigative tooling.
  • Strong ability to leverage telemetry from diverse systems and vendors, including querying and stitching together data.
  • Strong written and verbal communication skills, with the ability to translate technical investigations for diverse stakeholders.
  • Comfort operating independently in ambiguous, fast-moving problem spaces with minimal oversight.

About OpenAI

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.