Threat Intel Manager, Model Exploitation & Fraud

Anthropic Anthropic · AI Frontier · San Francisco, CA · Safeguards (Trust & Safety)

This role focuses on building and leading a team to detect, investigate, and disrupt the large-scale exploitation of Anthropic's AI systems, including model distillation, unauthorized access, account farming, reseller abuse, and fraud/scam operations. The manager will set strategy, hire and lead technical investigators, and build systems and processes for scaling these efforts. Key responsibilities include owning strategy, managing the team, directing complex investigations, driving the redesign of triage for detection pipelines, expanding coverage into fraud and scams, managing external engagement with government partners, and working with other teams to convert findings into mitigations. The role requires experience managing investigative teams, domain fluency in scaled abuse, proficiency in SQL and Python, experience tracking threat actors, and familiarity with large language models and their exploitation.

What you'd actually do

  1. Own strategy, priorities, and outcomes for the Model Exploitation & Fraud mission area; define what we detect, investigate, action, and share
  2. Hire, manage, and develop a team of technical threat investigators; set the quality bar for casework and intelligence reporting
  3. Direct, prioritize, and resource complex investigations into model distillation, unauthorized AI R&D usage, unauthorized access, coordinated account abuse, and fraud/scam networks, partnering with the senior investigators who lead the deepest technical casework and clearing blockers from their path
  4. Drive the redesign of triage for a very high-volume detection pipeline: partner with investigators and engineering to build abuse signals, clustering, and agentic investigation workflows that separate sophisticated actors from noise
  5. Expand the team's coverage into fraud and scams, building the detection and investigation playbooks from the ground up

Skills

Required

  • Led and managed investigative, fraud, platform integrity, or threat intelligence teams
  • Strong domain fluency in scaled abuse — fraud patterns, account abuse, unauthorized access, or platform exploitation economics
  • Proficient enough in SQL and Python to review data-heavy casework, pressure-test conclusions, and provide surge capacity
  • Experience overseeing investigations that track threat actors across surface, deep, and dark web environments, including reseller and access-broker communities
  • Working familiarity with large language models and a strong grasp of how models can be distilled, extracted, or exploited at scale
  • Built processes, detection systems, or programs from scratch
  • Communicate crisply with executives, engineers, and external partners alike

Nice to have

  • Experience at a major technology platform on trust and safety, fraud, or abuse investigations at scale
  • Background in financial crime investigation or fraud analytics
  • Experience working directly with U.S. government stakeholders on threat reporting
  • A track record of partnering with, growing, and retaining senior technical specialists, including defining clear scope between management and senior IC tracks
  • Fluency in Mandarin Chinese and/or Russian with nuanced regional and geopolitical context
  • Active Top Secret security clearance

What the JD emphasized

  • model distillation
  • unauthorized access
  • account farming
  • reseller abuse
  • fraud and scam operations
  • agentic investigation workflows

Other signals

  • model distillation
  • unauthorized access
  • account farming
  • reseller abuse
  • fraud and scam operations
  • agentic investigation workflows