Jobs in United States

Threat Investigator in San Francisco

52 active opportunities · Updated October 2026

Explore current threat investigator jobs in San Francisco. Filter by work mode, employment type, experience, department, date posted and distance.

O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Threat Intelligence team protects OpenAI’s technology, people, research, and infrastructure by proactively identifying and disrupting adversaries who seek to compromise our systems or misuse our models. We investigate sophisticated threats, build tooling to scale and augment analysis, and deliver intelligence that shapes security strategy and equips leadership with timely, risk-aware insights. We combine technical depth, investigative rigor, and strong cross-functional partnerships to uncover threats and drive impact across OpenAI’s security and research organizations. About the Role As a Technical Threat Investigator at OpenAI, you will help protect the company from sophisticated adversaries targeting OpenAI and the broader ecosystem, as well as those attempting to misuse our models in support of cyber operations. This is a deeply investigative role. You will independently conduct complex, end-to-end investigations into capable threat actors to understand their behavior, infrastructure, emerging techniques, and how AI is integrated into their workflows. You’ll use these insights to proactively identify malicious activity and drive detection, disruption, enforcement, and safety improvements across the company. You’ll translate your investigative findings into durable solutions that scale impact. You’ll build and own lightweight tooling, automate where it matters, and create AI-assisted workflows to make investigations faster, more repeatable, and more effective over time. In this role, you will: Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI’s models, products, and broader ecosystem. Think like an adversary — model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity. Leverage internal telemetry, OSINT, vendor data, a

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role OpenAI is seeking to build an investigative capability for Secure Manufacturing & Stealth programs. The risk surface for unreleased products, prototypes, confidential hardware, infrastructure, supply chain, manufacturing, and launch-readiness efforts spans employees, vendors, suppliers, logistics partners, physical movement of assets, procurement records, manufacturing workflows, access systems, device telemetry, and adversarial collection. This role is intended to build and run investigations across that specialized environment. In this role, you will: Lead complex SMS investigations to proactively identify and mitigate risks to unreleased products, prototypes, confidential hardware, secure manufacturing programs, and launch-readiness efforts. Investigate unauthorized disclosure, suspected leaks, insider risk, supplier compromise, vendor misconduct, theft, diversion, tampering, counterfeiting, surveillance, adversarial collection, and suspicious activity involving sensitive programs. Connect digital evidence, physical access activity, supply chain records, manufacturing data, vendor behavior, employee activity, collaboration metadata, procurement records, shipping data, and OSINT into clear findings and risk-reduction actions. Conduct proactive threat hunting to surface early indicators of compromise, collection, leakage, or insider activity affecting sensitive programs. Develop investigative playbooks, evidence-handling standards,

AWSGitRestAI
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Intelligence and Investigations team seeks to rapidly identify and mitigate abuse and strategic risks to ensure a safe online ecosystem. We are dedicated to identifying emerging abuse trends, analyzing risks, and working with our internal and external partners to implement effective mitigation strategies to protect against misuse. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits humanity. The Strategic Intelligence & Analysis (SIA) team provides safety intelligence for OpenAI’s products by monitoring, analyzing, and forecasting real-world abuse, geopolitical risks, and strategic threats. Our work informs safety mitigations, product decisions, and partnerships, ensuring OpenAI’s tools are deployed securely and responsibly across critical sectors. About the Role As an Agentic Risk Analyst, you will shape OpenAI’s operating picture for current agentic risk across products and platforms. You will bring a strategic, system-level perspective to current risks, connecting individual incidents, technical findings, abuse patterns, and external developments to relevant workstreams, mitigations, owners, dependencies, and residual gaps. You will analyze how risks emerge through autonomy, multi-step task execution, tool use, memory, retrieval, connectors, computer-use capabilities, and multi-agent workflows, with a particular focus on both adversarial misuse and unintended system behavior. By synthesizing signals from investigations, evaluations, red teaming, security reviews, product launches, external research, and real-world incidents, you will maintain a current view of material risks and evolving threat patterns. Your work will help turn complex and often ambiguous signals into coordinated decisions and measurable follow-through across product, safety, security, policy, and governance teams. You will work closely with investigators, engineers, product, policy, safety, and security teams, and measurement and forecasting

PythonSQLAWSRest
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Corporate Security team ensures the physical safety and security of the organization's assets, operations, and personnel. We are committed to maintaining a secure environment that enables our team to focus on advancing artificial intelligence in a responsible manner. About the Role As a Protective Intelligence & Threat Analyst, you will identify, assess, and communicate physical security threats affecting OpenAI, its personnel, executives, operations, and assets. You will leverage open-source intelligence, social media, investigative tools, and other information sources to assess violent or disruptive threats, geopolitical developments, and emerging risks relevant to the company. The role will support a broad range of Protective Intelligence activities, including persons of interest investigations, behavioral threat assessment, executive and individual risk assessments, event and travel security assessments, and time-sensitive intelligence support to Corporate Security and cross-functional partners. You will turn complex and often incomplete information into clear assessments and actionable recommendations that help inform security and protective decisions. We are seeking candidates with intelligence experience, particularly in protective intelligence, threat investigations, or behavioral threat assessment. Successful candidates will understand the intelligence cycle, OSINT investigative techniques, corporate physical security, risk management, and threat assessment, and will be comfortable operating independently in a fast-moving environment involving sensitive and occasionally high-profile matters. This role could be based in San Francisco, CA, or may be a remote role for the right candidate. We use a hybrid work model of 3 days in the office per week. Relocation offered for those outside of the Bay Area. In this role, you will: Identify and investigate potential physical threats to OpenAI, its executives, employees, facilities, operations,

PythonAWSRestAI
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team OpenAI’s Cyber team works to make frontier AI a decisive advantage for defenders. The Cyber Blue Team is an operator-led group focused on turning real defensive problems into better models, useful products, safe Codex workflows, and integrations with the security tools defenders already use. Our ambition is simple: Raise attacker cost. Lower defender toil. Prove it by defending OpenAI; scale it through the ecosystem. We are not setting out to build another SIEM or autonomous SOC. We want to build the AI reasoning and workflow layer that helps security teams investigate threats, create and validate detections, improve their controls, and respond with greater speed and confidence. About the Role We are looking for a Product Manager to help build a new generation of AI-powered cyber defense products. You will work closely with security practitioners, researchers, engineers, designers, internal security teams, customers, and technology partners to turn emerging model capabilities into products that solve meaningful defensive problems. This is an early-stage product role. The work will span product discovery, prototyping, evaluation, development, launch, and iteration. You will help the team identify where AI can create the most value for defenders and translate those opportunities into clear, usable, and trustworthy product experiences. Initial areas of focus may include: Detection engineering and detection-content development Threat hunting and investigation Security validation and control testing AI-agent and MCP runtime defense Integrations with security platforms and enterprise workflows Safe, governed assistance for incident response The specific roadmap will continue to evolve based on model progress, practitioner needs, internal learnings, and customer feedback. In This Role, You Will Work with security practitioners to understand high-value defensive workflows, recurring pain points, and opportunities for AI to materially improve outcomes. Help sh

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer you will join our OpenAI engineers and researchers in building, operating and securing transformational AI technologies. This role will focus on all aspects of Detection & Response but with a strong emphasis on detecting insider threats and influencing controls to safeguard OpenAI's most sensitive assets. In this role, you will: In this role, you will: Innovate on Detection and Response infrastructure to engineer and automate end-to-end detection and investigation workflows. Develop, measure, and tune detection rules to ensure effective and sustainable operations. Drive projects across OpenAI’s technology stack with a focus on insider threats, ranging from access abuse and intellectual property theft to novel risks emerging within AI infrastructure. Partner closely with cross-functional stakeholders, including HR, Legal, and peer investigative teams, providing technical expertise and evidence to support investigations. Collaborate on cutting-edge AI research, and use AI to improve OpenAI’s Security posture. You might thrive in this role if you: 5+ years experience working in a detection/response or insider-risk role.. We are seeking mid-level and senior candidates. You have broad familiarity with operating systems and platforms such as macOS, Windows, Linux, and Kubernetes, along with experience in cloud infrastructure. Knowledge of modern adversary tactics and attack paths, data exfiltration techniques, and h

PythonAWSKubernetesLinux
F
📍 San Francisco, California, United States· Full-time
✓ High-confidence listingCompany trend -85.5%

From $183.3K/yr

Quick readStrong listing-quality and freshness signals

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnershi

PythonKubernetesCI/CDRest
P
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -72.3%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. We are the first line of defense against fraud and abuse on the Plaid platform. Our mission is to ensure the safety and integrity of our platform for consumers and customers. As a Fraud and Abuse Operations Analyst , you will be responsible for responding to fraud and abuse events, investigating claims, and triaging incidents. We also partner with product and engineering teams to inform and improve fraud mitigation strategies. Responsibilities: Safeguard Plaid's Platform: Participate in the abuse on-call rotation, directly protecting our users and customers by responding to and resolving fraud and abuse events. Your timely actions will be instrumental in maintaining trust and security. Drive Investigations and Mitigate Risks: Investigate fraud and abuse claims from diverse sources, partnering with senior teammates on complex cases. Your findings will inform decisions and strategies, directly impacting Plaid's ability to prevent future incidents and minimize financial losses. Proactively perform threat modeling of abuse surfaces and continuously survey external fraud trends, adversary techniques, tooling, and emerging threat vectors Support Incident Response: Help triage and manage fraud and abuse ev

SQLAWSMachine LearningAI
O
📍 San Francisco, California, United States· Full-time· Remote
✓ High-confidence listingCompany trend -80.2%
Quick readStrong listing-quality and freshness signals

About the Team Our Safety Systems team is at the forefront of OpenAI's mission to build and deploy safe AGI, driving our commitment to AI safety and fostering a culture of trust and transparency. Within Safety Systems, the Model Policy team works to ensure that increasingly capable models behave safely and reliably in real-world environments. We investigate emerging model failures, define the behavior models should exhibit instead, and develop the data, evaluations, monitoring, and safeguards needed to improve and validate that behavior. Our work connects alignment research with the practical challenges of training and deploying frontier models. About the Role In this role, you will shape how OpenAI understands and addresses real-world risks that emerge from model misalignment as models become more autonomous and operate over longer horizons. You will investigate how misaligned behavior emerges across extended trajectories - including when models persist toward the wrong objective, take unsafe shortcuts, lose track of instructions, exploit weaknesses in their environment, or circumvent constraints - and translate these insights into behavioral policies, evaluations, monitoring, and safeguards. This role is ideal for someone who wants to turn alignment and safety concerns into concrete, empirically grounded improvements to frontier AI systems. Your Responsibilities: Identify vulnerabilities that emerge as models interact with tools, data, and external systems, and translate them into model- and system-level safeguards. Develop threat models and empirical frameworks for understanding harmful outcomes from misaligned behavior. Build frameworks for understanding harmful outcomes arising from model misalignment. Identify the underlying behaviors and system conditions that drive those outcomes. Turn findings into policy frameworks, evaluation criteria, online measurement and safeguards. Develop human data campaigns and gold sets to ground measurement and evaluation of eme

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Integrity team builds the systems OpenAI uses to understand, prevent, and respond to misuse across our products. We partner with Product, Policy, Safety Systems, User Operations, Security, Legal, Privacy, OpenAI for Government, and research teams to turn policy and threat models into product controls, review workflows, measurement systems, and enforcement paths. About the Role We are hiring a Product Manager to own Integrity's product strategy for sensitive deployments: contexts where model capability, customer or deployment setting, privacy constraints, and misuse potential make the operating bar unusually high. This includes government and other high stakes deployments, regulated or high-trust enterprise contexts, zero data retention and privacy-constrained environments, and agentic workflows where harm can unfold across many steps rather than a single prompt. The Sensitive Deployments PM will focus on high-consequence use cases relevant to government deployments and broader deployment-readiness questions for high-risk domains (e.g., healthcare), while building reusable Integrity capabilities for agentic detection and enforcements in these environments. This position is based in San Francisco, CA, with relocation assistance available. In this role, you will: Own the roadmap for sensitive deployment Integrity controls and readiness criteria. Define how we measure residual risk, decision quality, review quality, and mitigation effectiveness. Build agentic investigation and context-assembly workflows for complex, multi-step misuse patterns. Partner with Policy, Legal, Privacy, Safety Systems, User Ops, Government, and product teams to build shared capabilities. Create launch and deployment playbooks for sensitive customer, capability, and product contexts. You might thrive in this role if you: Have shipped complex product systems in AI, integrity, trust and safety, security, privacy, risk, government, regulated enterprise, or AI safety. Can turn am

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most sensitive assets– including our intellectual property, customer data, and the infrastructure that supports them– by building and operating the systems we use to detect suspicious activity and respond effectively when it matters. You’ll work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering closely with security teams and infrastructure owners to define the telemetry and response requirements we need and building tooling and automation where it delivers the most leverage. In this role, you will: Build and evolve Detection & Response capabilities across OpenAI’s infrastructure, products, and research environments, with an emphasis on high-signal detection and reliable operational response. Engineer detection pipelines and tooling: develop rule lifecycle management, measurement/quality loops (coverage, precision, latency), tuning processes, and safe rollout patterns. Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain. Partner with other Security teams and system/infrastructure owners across the company to ensure new systems ship with the right telemetry, threat models, and response playbooks from day one. Define D&R requirements and drive visibility across endpoin

AWSAzureGCPKubernetes
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Intelligence and Investigations team is dedicated to ensuring the safe, responsible deployment of AI by rapidly detecting and mitigating abuse. Our team leverages the latest testing methodologies to uncover vulnerabilities and emerging threats, helping safeguard OpenAI’s products and users. We work closely with cross-functional partners across product, policy, and engineering to drive a comprehensive defense strategy against evolving adversarial challenges. About the Role As a Red Team Specialist focused on cyber, you will help answer two practical questions: What cyber capabilities can our models provide to real-world attackers, and do our safeguards remain effective when those attackers use increasingly sophisticated techniques? The role combines scaled evaluation with expert-driven testing. You may bring deeper experience in cybersecurity and use that expertise to judge whether a model’s behavior meaningfully changes attacker capability. Alternatively, you may bring deeper experience in model evaluations, automation, or agentic harnesses and apply those skills to building rigorous cyber testing. We do not expect every candidate to be equally deep in both areas, but successful candidates will have a strong foundation in one and enough fluency in the other to work effectively across the boundary. Most of your work will focus on model cyber capabilities and safeguards; you will also spend a portion of your time testing novel abuse risks in agentic systems. This role is located in San Francisco, CA or Seattle, WA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Design and run rigorous evaluations of model cyber capabilities and safeguards, including policy adherence, correct refusal, over refusal, and resilience to jailbreaking and other adversarial techniques. Conduct hands-on testing to understand what models can enable when used by experienced security practiti

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Intelligence and Investigations team seeks to rapidly identify and mitigate abuse and strategic risks to ensure a safe online ecosystem. We are dedicated to identifying emerging abuse trends, analyzing risks, and working with our internal and external partners to implement effective mitigation strategies to protect against misuse. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits humanity. The Strategic Intelligence & Analysis (SIA) team provides safety intelligence for OpenAI’s products by monitoring, analyzing, and forecasting real-world abuse, geopolitical risks, and strategic threats. Our work informs safety mitigations, product decisions, and partnerships, ensuring OpenAI’s tools are deployed securely and responsibly across critical sectors. About the Role As a Quantitative Intelligence Analyst , you will focus on discovering novel and emerging risks in complex human–AI systems before they are well-defined, measurable, or widely understood. You will use deep subject matter expertise and quantitative tooling to surface weak, early, and unconventional risk signals. You will build analytic models that explain how harms could emerge and translate ambiguous patterns into structured, data-driven insight. Your work will help identify potential gaps in policy or coverage and operationalize previously unmeasured problems into signals that can support detection, mitigation, and planning downstream. You will develop analytical frameworks that map how new risks form, evolve, and propagate as products change, policies shift, and external events unfold. Your analyses will directly inform strategic risk prioritization and planning across the company, with regular visibility through strategic risk products. This role is based in office (hybrid, 3 days/week). Relocation support is available In this role, you will: Discover and define new quantitative risk signals where no established metrics exist, using subject matter exp

PythonSQLAWSRest
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the team The Intelligence and Investigations team seeks to rapidly identify and mitigate abuse and strategic risks to ensure a safe online ecosystem in close collaboration with our internal and external partners. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits humanity. This role focuses specifically on AI Safety: understanding and mitigating risks created or amplified by increasingly capable AI systems. It is not a cybersecurity, information security, or corporate security role. The Strategic Intelligence & Analysis (SIA) team provides safety intelligence for OpenAI’s products by monitoring, analyzing, and forecasting real-world abuse, geopolitical risks, and strategic threats. Our work informs AI safety mitigations, product decisions, and partnerships, ensuring OpenAI’s tools are deployed responsibly across critical sectors. About the role We are looking for a Frontier AI Risks Lead to help us understand potential harms and misuse of AI in a time of rapid, sustained change. We seek to understand how developments in AI could intersect with misuse and abuse, accelerating existing harm areas and creating novel risks. We seek to scan available signals and use strategic foresight methodologies to enable proactive detection and mitigation of frontier AI risks. This is an AI safety role focused on frontier and systemic risks, including model misalignment, recursive self-improvement (RSI), multi-agent interaction, loss of control, runaway agents, and related emerging failure modes. In this role, you will help provide a strategic-level perspective on a range of frontier AI safety areas, producing actionable understanding of issues relevant to OpenAI’s platforms, systems, and broader mission. Utilizing mixed quantitative and qualitative methodologies, you will spot early warning signs, pull threads on potentially concerning behavior, and turn weak signals into clear, prioritized risk calls. You will focus on upstream ecosystem sc

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Intelligence and Investigations team seeks to rapidly detect and disrupt abuse in AI technologies to ensure their safe use. We are dedicated to identifying emerging abuse trends, analyzing risks, and working with our internal partners to implement effective mitigation strategies to protect against misuse. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits all of humanity. About the Role As an Intelligence Systems Engineer, you’ll be focused on advancing our Intelligence & Investigations efforts at OpenAI, ensuring the safe and responsible use of AI across our products and services. We are seeking a self-starter to prototype, develop, and maintain new tools and processes that integrate OpenAI’s models and infrastructure to enable internal teams to make sense of large, open-domain datasets, fight abuse, and inform high-stakes decisions. You will be a crucial technical bridge between our data scientists and subject matter experts and technical teams like Platform Integrity, Safety Systems, and Research by leading the development of innovative tools and processes that bolster goals in scaled collections, investigations, and analysis. The ideal candidate has strong analytical and data skills, with a background in both prototyping and building scalable systems that can swiftly detect emerging threats, process vast amounts of information, and deliver insights to stakeholders. We value professionals with outstanding communication skills, a commitment to continuous learning, and who are dedicated to promoting the responsible use of AI. This role is based in San Francisco, CA. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Prototype, build, and maintain at-scale intelligence systems that detect, triage, and monitor targeted signals from both open-source and internal data Analyze requirements and deliver end-to-end solutions that address

PythonSQLAWSRest
🔔

Get new threat investigator jobs in San Francisco, United States by email

Daily job updates · Unsubscribe anytime