Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
Communication @ 7
Fraud @ 4
LLM
Python @ 6
Reporting @ 4
SQL @ 6
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Anthropic is seeking a Threat Intel Manager to build and lead its Model Exploitation & Fraud team within Threat Intelligence. The team detects, investigates, and disrupts large-scale exploitation of Anthropic's AI systems, including model distillation, unauthorized access, account farming, reseller abuse, and fraud and scam operations.
The role owns the mission area's strategy, team leadership, investigative programs, systems, processes, and external partnerships. It involves regular engagement with the U.S. government and requires understanding external black-market ecosystems and their interaction with Anthropic's systems. The role may involve exposure to explicit sexual, violent, or psychologically disturbing content and may require responding to escalations during weekends and holidays.
Responsibilities
- Own strategy, priorities, and outcomes for the Model Exploitation & Fraud mission area, defining what the team detects, investigates, actions, and shares.
- Hire, manage, and develop a team of technical threat investigators, setting quality standards for casework and intelligence reporting.
- Define responsibilities between management and senior individual contributors, with management owning strategy, people leadership, and program ownership while senior experts retain ownership of the deepest technical investigations and tradecraft.
- Independently lead complex investigations.
- Direct, prioritize, and resource investigations into model distillation, unauthorized AI research and development usage, unauthorized access, coordinated account abuse, and fraud and scam networks.
- Redesign triage for a high-volume detection pipeline by partnering with investigators and engineering to build abuse signals, clustering, and agentic investigation workflows.
- Expand coverage into fraud and scams and build detection and investigation playbooks.
- Own external engagement, including intelligence sharing with U.S. government partners and industry peers.
- Anticipate how resellers, proxies, and third-party platforms change the abuse surface and adjust coverage accordingly.
- Work with policy, enforcement, and engineering to convert findings into bans, product mitigations, and safety-by-design improvements.
- Define and report team metrics and brief Safeguards and company leadership on the threat landscape.
Requirements
- Experience leading and managing investigative, fraud, platform integrity, or threat intelligence teams, ideally teams consisting of senior specialized individual contributors.
- Strong domain fluency in scaled abuse, including fraud patterns, account abuse, unauthorized access, or platform exploitation economics.
- Proficiency in SQL and Python sufficient to review data-heavy casework, pressure-test conclusions, and provide surge capacity.
- Experience overseeing investigations tracking threat actors across surface, deep, and dark web environments, including reseller and access-broker communities.
- Working familiarity with large language models and a strong understanding of how models can be distilled, extracted, or exploited at scale.
- Experience building processes, detection systems, or programs from scratch.
- Strong communication skills with executives, engineers, and external partners.
- Bachelor's degree or an equivalent combination of education, training, and experience.
- Relevant education, training, or professional experience in a field related to the role.
Preferred Qualifications
- Experience at a major technology platform in trust and safety, fraud, or abuse investigations at scale.
- Background in financial crime investigation or fraud analytics.
- Experience working directly with U.S. government stakeholders on threat reporting.
- Experience partnering with, growing, and retaining senior technical specialists and defining scope between management and senior individual contributor tracks.
- Fluency in Mandarin Chinese and/or Russian with nuanced regional and geopolitical context.
- Active Top Secret security clearance.
Benefits
Anthropic offers competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and an office space for collaboration. Anthropic sponsors visas where possible and retains an immigration lawyer to assist with visa applications.