Remote Threat Intel Investigator & Automation Engineer

OpenAI

San Francisco (CA)

On-site

USD 230,000 - 385,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote work
Relocation assistance

Job summary

OpenAI is seeking a Technical Threat Investigator to protect OpenAI and ecosystem from sophisticated adversaries and model misuse. You will conduct end-to-end investigations, model attacker behavior, and drive improvements across detection, enforcement, and safety pipelines.

You will build lightweight automation, leverage diverse telemetry, and translate findings into high-signal outputs for stakeholders. Remote role with US/UK collaboration and SF HQ engagement.

Qualifications

  • Experience in threat intelligence, incident response, offensive security, or a closely related field.
  • Solid experience investigating sophisticated threat actors, including model misuse, platform abuse, or other adversarial activity in complex environments.
  • A strong understanding of adversary behavior, infrastructure, and tradecraft, and the ability to apply that understanding to proactive investigations.
  • Demonstrated ability to independently drive deep technical investigations from ambiguous signals through to clear, actionable findings.
  • Experience using AI to extend or accelerate investigative workflows.
  • Strong scripting ability and comfort building lightweight automation, investigative tooling, or workflows that improve scale and repeatability.
  • Strong ability to leverage telemetry from diverse systems and vendors to drive investigations, including directly querying, extracting, and stitching together data where needed.
  • Strong written and verbal communication skills, especially the ability to translate technical investigations into high-signal outputs for diverse stakeholders.
  • Comfort operating independently in ambiguous, fast-moving problem spaces with minimal oversight.

Responsibilities

  • Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI’s models, products, and broader ecosystem.
  • Think like an adversary — model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity.
  • Leverage internal telemetry, OSINT, vendor data, and in-house safety systems to produce high-confidence findings on adversarial use of our models in cyber operations, platform abuse, and threats targeting OpenAI.
  • Translate investigative findings into concrete improvements across detection, enforcement, intel, and safety pipelines.
  • Build tooling, scripts, automations, and agentic workflows that scale investigative throughput and reduce manual effort.
  • Prototype solutions in ambiguous and emerging problem spaces, including new product surfaces, novel attacker behaviors, and areas where existing coverage may be limited.
  • Partner closely with teams across Security, Safety Systems, Product Policy, and Integrity to operationalize findings and drive meaningful outcomes.
  • Produce clear, high-signal written outputs and recommendations that inform decision-making across technical and executive stakeholders.

Skills

Threat intelligence
Incident response
Offensive security
Adversary behavior
Scripting
Automation
Telemetry analysis
Written communication

Tools

Python
Shell scripting
OSINT
Telemetry data sources

Job description

OpenAI is seeking a Technical Threat Investigator to protect OpenAI and ecosystem from sophisticated adversaries and model misuse. You will conduct end-to-end investigations, model attacker behavior, and drive improvements across detection, enforcement, and safety pipelines.

You will build lightweight automation, leverage diverse telemetry, and translate findings into high-signal outputs for stakeholders. Remote role with US/UK collaboration and SF HQ engagement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Threat Intel Engineer — Investigative Security
Remote Threat Intel Engineer — Investigative Security

DaParrot Ltd • Northern (KY)

Hybrid
USD 180,000 - 240,000
Remote Threat Intelligence Investigator (AI Security)
Remote Threat Intelligence Investigator (AI Security)

Neura Market • Northern (KY)

Hybrid
USD 140,000 - 190,000
Relocation assistance
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

DaParrot Ltd • Northern (KY)

Hybrid
USD 180,000 - 240,000
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

Neura Market • Northern (KY)

Hybrid
USD 140,000 - 190,000
Relocation assistance
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

OpenAI • San Francisco (CA)

On-site
USD 230,000 - 385,000
Remote work
Relocation assistance
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

OpenAI • Los Angeles (CA)

On-site
USD 234,000 - 385,000
Remote Threat Intel Investigator | Equity
Remote Threat Intel Investigator | Equity

OpenAI • Los Angeles (CA)

On-site
USD 234,000 - 385,000
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

OpenAI • United States

On-site
USD 90,000 - 130,000
Remote Threat Intelligence Investigator - Abuse & Violent Activity
Remote Threat Intelligence Investigator - Abuse & Violent Activity

SupportFinity™ • San Francisco (CA)

On-site
USD 180,000 - 240,000
Remote Protective Intelligence Analyst
Remote Protective Intelligence Analyst

OpenAI • Washington

Hybrid
USD 120,000 - 180,000