Technical Threat Investigator, Threat Intel Engineering

OpenAI OpenAI · AI Frontier · San Francisco, CA · Security

This role focuses on investigating sophisticated threat actors targeting OpenAI's models and infrastructure, building tooling and AI-assisted workflows to enhance threat detection, disruption, and safety improvements. The primary focus is on understanding adversary behavior and developing scalable solutions to combat misuse of AI models.

What you'd actually do

  1. Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI’s models, products, and broader ecosystem.
  2. Think like an adversary — model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity.
  3. Leverage internal telemetry, OSINT, vendor data, and in-house safety systems to produce high-confidence findings on adversarial use of our models in cyber operations, platform abuse, and threats targeting OpenAI.
  4. Translate investigative findings into concrete improvements across detection, enforcement, intel, and safety pipelines.
  5. Build tooling, scripts, automations, and agentic workflows that scale investigative throughput and reduce manual effort.

Skills

Required

  • Experience in threat intelligence, incident response, offensive security, or a closely related field.
  • Solid experience investigating sophisticated threat actors, including model misuse, platform abuse, or other adversarial activity in complex environments.
  • A strong understanding of adversary behavior, infrastructure, and tradecraft, and the ability to apply that understanding to proactive investigations.
  • Demonstrated ability to independently drive deep technical investigations from ambiguous signals through to clear, actionable findings.
  • Experience using AI to extend or accelerate investigative workflows.
  • Strong scripting ability and comfort building lightweight automation, investigative tooling, or workflows that improve scale and repeatability.
  • Strong ability to leverage telemetry from diverse systems and vendors to drive investigations, including directly querying, extracting, and stitching together data where needed.
  • Strong written and verbal communication skills, especially the ability to translate technical investigations into high-signal outputs for diverse stakeholders.
  • Comfort operating independently in ambiguous, fast-moving problem spaces with minimal oversight.

Nice to have

  • Experience with AI-assisted workflows
  • Experience building agentic workflows

What the JD emphasized

  • deep, end-to-end investigations
  • sophisticated threat actors
  • AI is integrated into their workflows
  • build and own lightweight tooling
  • automate where it matters
  • create AI-assisted workflows
  • investigative findings
  • detection, enforcement, intel, and safety pipelines
  • agentic workflows
  • ambiguous and emerging problem spaces
  • novel attacker behaviors
  • threat intelligence
  • incident response
  • offensive security
  • investigating sophisticated threat actors
  • model misuse
  • platform abuse
  • adversarial activity
  • adversary behavior
  • infrastructure
  • tradecraft
  • proactive investigations
  • independently drive deep technical investigations
  • ambiguous signals
  • clear, actionable findings
  • using AI to extend or accelerate investigative workflows
  • scripting ability
  • lightweight automation
  • investigative tooling
  • scale and repeatability
  • telemetry from diverse systems and vendors
  • directly querying, extracting, and stitching together data
  • Comfort operating independently
  • ambiguous, fast-moving problem spaces
  • minimal oversight

Other signals

  • investigate sophisticated threats
  • build tooling to scale and augment analysis
  • deliver intelligence that shapes security strategy
  • AI is integrated into their workflows
  • build and own lightweight tooling
  • automate where it matters
  • create AI-assisted workflows