Threat Investigator

10a Labs

United States

On-site

USD 70,000 - 100,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

An AI security company in the United States is seeking a Threat Investigator to join their Investigations Team. The role involves detecting and responding to malicious activities, drafting investigative reports, and utilizing SQL and Python for data analysis. Candidates should have at least 3 years of experience in technical investigations, strong proficiency in SQL and Python, and be willing to work flexible hours, including on-call responsibilities. This position requires dealing with sensitive content, ensuring a proactive approach to cyber threats.

Qualifications

  • Minimum of 3 years of investigative experience in related fields.
  • Ability to work on sensitive topics, including child safety.
  • Strong technical skills in investigations and detection processes.

Responsibilities

  • Detect and reacquire bad actors on the platform.
  • Investigate policy-violating activity using SQL and Python.
  • Document and share findings with internal stakeholders.
  • Triage and mitigate active cyber threats.

Skills

SQL proficiency
Python proficiency
Technical investigations
Ability to context-switch

Tools

SIEM experience
Forensic log analysis

Job description

Join to apply for the Threat Investigator role at 10a Labs.

About 10a Labs

10a Labs is an applied research and AI security company trusted by AI unicorns, Fortune 10 companies, and U.S. tech leaders. We combine proprietary technology, deep expertise, and multilingual threat intelligence to detect abuse at scale. We also deliver state‑of‑the‑art red teaming across high‑impact security and safety challenges. 10a Labs’ Investigations Team is expanding. We are looking to hire more support to respond to critical safety incidents and conduct investigations across a range of abuse areas, including but not limited to Violence, Hate, Mental Health, CBRNE, Child Safety and more.

About the Role

As a Threat Investigator, you will support our Investigations Team and be responsible for detecting and/or responding to malicious uses and abuse, investigating the activity, drafting reports based on your findings, and making recommendations. This requires technical expertise investigating threat actors, harmful behaviours, and/or other activities; as well as strong ability to use SQL and Python to query, transform, and understand data. You will respond to escalations and reactive leads, including those that are not caught by our existing safety systems.

Investigations involve sensitive and distressing content, including sexual, violent, or otherwise‑disturbing material.

This role includes serving in an on‑call capacity that will involve resolving urgent escalations outside normal work hours, occasionally including evenings and weekends. The typical on‑call rotation is 7 consecutive days per month, though this may shift based on operational needs and you should remain flexible.

In This Role, You Will
  • Proactively detect and reacquire bad actors on our platform.
  • Investigate potentially policy‑violating activity by querying internal data sources (using SQL and Python) and cross‑referencing open source information.
  • Document and share investigative findings with internal stakeholders.
  • Triage and mitigate active cyber threats, monitor and detect cyber threats, and administer security controls.
Requirements
  • U.S.-based, with the ability to work West Coast hours (9am‑5pm PT).
  • Ability to be on‑call to resolve urgent escalations outside normal work hours, including occasional evenings and weekends.
  • Strong SQL and Python proficiency.
  • Strong and applicable technical investigations and detection pipelines.
  • At least 3+ years of related investigative experience working on related topics; willingness to work on child safety subject matter.
  • Ability to rapidly context‑switch across domains, modalities, and abuse areas.
  • Experience with forensic log analysis, SIEM experience, and pocket capture analysis.
  • Excited to work in a fast‑paced, ambiguous, and purposeful space with high impact across users and beyond.
Desired Qualities (Not Required)
  • Expertise with LLM, Agentic AI, and associated risks including prompt injection.
  • Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish.
  • Experience scaling and automating processes, especially with language models.
  • Familiarity using language models to scale.
  • Familiarity with one of the following topics/areas: AI safety, prompt injection, child safety, digital mental health, spam and fraud abuse, radicalization/persuasion/grooming; hateful activities and groups.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Investigator US
Threat Investigator US

10a Labs • Washington

On-site
USD 70,000 - 100,000
Senior Cyber Investigator
Senior Cyber Investigator

10a Labs • Washington

Remote
USD 115,000 - 140,000
Generous PTO
401(k) plan
Junior Cyber Investigator
Junior Cyber Investigator

10a Labs • Washington

On-site
USD 80,000 - 105,000
Generous PTO and paid holiday schedule
401(k) plan
Threat Intelligence Engineer
Threat Intelligence Engineer

Anthropic • Washington, San Francisco (CA)

Hybrid
USD 320,000 - 405,000
Remote Threat Intelligence Investigator - Abuse & Violent Activity
Remote Threat Intelligence Investigator - Abuse & Violent Activity

SupportFinity™ • San Francisco (CA)

On-site
USD 180,000 - 240,000
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

DaParrot Ltd • Northern (KY)

Hybrid
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Visa Hunt • San Francisco (CA)

On-site
USD 180,000 - 240,000
Technical Cyber Threat Investigator
Technical Cyber Threat Investigator

Anthropic • San Francisco (CA)

Hybrid
USD 230,000 - 290,000
Competitive compensation
Generous vacation and parental leave
Flexible working hours
Technical Threat Investigator, Threat Intel Engineering
Technical Threat Investigator, Threat Intel Engineering

OpenAI • San Francisco (CA)

On-site
USD 230,000 - 385,000
Remote work
Relocation assistance
Abuse Investigator
Abuse Investigator

Socket.dev • Seattle (WA), New York (NY)

On-site
USD 180,000 - 240,000