Insider Risk Investigator - Technical & Human Intelligence

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

This role focuses on investigating insider risks within an AI company, leveraging AI tools to enhance investigation workflows and data analysis. The primary responsibility is to conduct end-to-end investigations, triage alerts, and collaborate with various teams to protect company assets. While AI tools are used, the core function is risk investigation, not AI model development.

What you'd actually do

  1. Triage custom technical detection alerts
  2. Independently conduct end-to-end insider risk investigations while working closely with IT, Detection and Response, Legal, HR and other cross-functional teams
  3. Monitor and triage external threats targeting employees
  4. Conduct sensitive interviews of employees or other involved parties
  5. Perform technical analysis of logs from SIEM, DLP, UEBA systems

Skills

Required

  • 5-8 years of experience in insider risk, corporate investigations or a related domain
  • 3-5 years experience in conducting investigative interviews
  • Experience conducting OSINT for threat assessment, or counterintelligence
  • Experience leveraging DLP, UEBA, SIEM, SOAR and other insider risk security tooling for detections and investigations
  • Broad understanding of internal and external investigations, cybersecurity, interview techniques, risk assessment and managing strong cross-functional relationships
  • Ability to communicate complex security findings clearly and concisely to non-technical stakeholders (written and verbal)
  • Track record of rapid response to time-sensitive security requests
  • Comfort operating across organizational boundaries (Security, People, Legal, IT)
  • Exceptional communication, collaboration skills and the ability to lead projects with little guidance
  • Demonstrated ability to operate independently with minimal oversight while managing sensitive cases

Nice to have

  • Experience working in the technology industry or at/with AI/ML companies
  • Experience with counterintelligence investigations and nation-state threat actor TTPs
  • Background in open-source intelligence collection and analysis
  • Track record of AI/LLM adoption for productivity gains in investigative work
  • Experience contributing to a high growth startup environment
  • Specialized knowledge of risks unique to the AI sector
  • Experience with data exfiltration investigations across multiple vectors (email, cloud, removable media)
  • Experience working in government, defense, or high-security environments

What the JD emphasized

  • Track record of rapid response to time-sensitive security requests
  • Demonstrated ability to operate independently with minimal oversight while managing sensitive cases
  • AI-native approach: You leverage LLMs to work smarter, not just harder