Jobs in United States

Threat Investigator in United States

175 active opportunities · Updated October 2026

Explore current threat investigator jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.

R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $155K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Threat Investigator on the Safety Investigations team, you will help lead Roblox’s deep-dive investigative capability for the most severe, complex, and externally significant safety matters. You will conduct actor-centric and network-centric investigations, proactively identify sophisticated threat actors and abuse patterns, and develop high-quality investigative work product that supports internal decision-making and, where appropriate, external law-enforcement engagement. The ideal candidate will have an exceptional investigations background, strong analytical tradecraft, and a demonstrated ability to connect fragmented internal and external signals into clear, defensible investigative findings. They will be an innovative self-starter, a collaborative partner across functions, and someone motivated by Roblox’s mission of connecting a billion people with optimism and civility. Through your work, you will become an expert in Roblox’s internal and external safety practices, advance our investigative capabilities and playbooks, and work across a variety of systems and data sources to surface, analyze, and ultimately disrupt high-risk actors, networks, and behaviors. Please note: T

PythonSQLAWSGit
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Threat Intelligence team protects OpenAI’s technology, people, research, and infrastructure by proactively identifying and disrupting adversaries who seek to compromise our systems or misuse our models. We investigate sophisticated threats, build tooling to scale and augment analysis, and deliver intelligence that shapes security strategy and equips leadership with timely, risk-aware insights. We combine technical depth, investigative rigor, and strong cross-functional partnerships to uncover threats and drive impact across OpenAI’s security and research organizations. About the Role As a Technical Threat Investigator at OpenAI, you will help protect the company from sophisticated adversaries targeting OpenAI and the broader ecosystem, as well as those attempting to misuse our models in support of cyber operations. This is a deeply investigative role. You will independently conduct complex, end-to-end investigations into capable threat actors to understand their behavior, infrastructure, emerging techniques, and how AI is integrated into their workflows. You’ll use these insights to proactively identify malicious activity and drive detection, disruption, enforcement, and safety improvements across the company. You’ll translate your investigative findings into durable solutions that scale impact. You’ll build and own lightweight tooling, automate where it matters, and create AI-assisted workflows to make investigations faster, more repeatable, and more effective over time. In this role, you will: Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI’s models, products, and broader ecosystem. Think like an adversary — model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity. Leverage internal telemetry, OSINT, vendor data, a

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role OpenAI is seeking to build an investigative capability for Secure Manufacturing & Stealth programs. The risk surface for unreleased products, prototypes, confidential hardware, infrastructure, supply chain, manufacturing, and launch-readiness efforts spans employees, vendors, suppliers, logistics partners, physical movement of assets, procurement records, manufacturing workflows, access systems, device telemetry, and adversarial collection. This role is intended to build and run investigations across that specialized environment. In this role, you will: Lead complex SMS investigations to proactively identify and mitigate risks to unreleased products, prototypes, confidential hardware, secure manufacturing programs, and launch-readiness efforts. Investigate unauthorized disclosure, suspected leaks, insider risk, supplier compromise, vendor misconduct, theft, diversion, tampering, counterfeiting, surveillance, adversarial collection, and suspicious activity involving sensitive programs. Connect digital evidence, physical access activity, supply chain records, manufacturing data, vendor behavior, employee activity, collaboration metadata, procurement records, shipping data, and OSINT into clear findings and risk-reduction actions. Conduct proactive threat hunting to surface early indicators of compromise, collection, leakage, or insider activity affecting sensitive programs. Develop investigative playbooks, evidence-handling standards,

AWSGitRestAI
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the Team The Intelligence and Investigations team seeks to rapidly identify and mitigate abuse and strategic risks to ensure a safe online ecosystem. We are dedicated to identifying emerging abuse trends, analyzing risks, and working with our internal and external partners to implement effective mitigation strategies to protect against misuse. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits humanity. The Strategic Intelligence & Analysis (SIA) team provides safety intelligence for OpenAI’s products by monitoring, analyzing, and forecasting real-world abuse, geopolitical risks, and strategic threats. Our work informs safety mitigations, product decisions, and partnerships, ensuring OpenAI’s tools are deployed securely and responsibly across critical sectors. About the Role As an Agentic Risk Analyst, you will shape OpenAI’s operating picture for current agentic risk across products and platforms. You will bring a strategic, system-level perspective to current risks, connecting individual incidents, technical findings, abuse patterns, and external developments to relevant workstreams, mitigations, owners, dependencies, and residual gaps. You will analyze how risks emerge through autonomy, multi-step task execution, tool use, memory, retrieval, connectors, computer-use capabilities, and multi-agent workflows, with a particular focus on both adversarial misuse and unintended system behavior. By synthesizing signals from investigations, evaluations, red teaming, security reviews, product launches, external research, and real-world incidents, you will maintain a current view of material risks and evolving threat patterns. Your work will help turn complex and often ambiguous signals into coordinated decisions and measurable follow-through across product, safety, security, policy, and governance teams. You will work closely with investigators, engineers, product, policy, safety, and security teams, and measurement and forecasting

PythonSQLAWSRest
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the Team The Corporate Security team ensures the physical safety and security of the organization's assets, operations, and personnel. We are committed to maintaining a secure environment that enables our team to focus on advancing artificial intelligence in a responsible manner. About the Role As a Protective Intelligence & Threat Analyst, you will identify, assess, and communicate physical security threats affecting OpenAI, its personnel, executives, operations, and assets. You will leverage open-source intelligence, social media, investigative tools, and other information sources to assess violent or disruptive threats, geopolitical developments, and emerging risks relevant to the company. The role will support a broad range of Protective Intelligence activities, including persons of interest investigations, behavioral threat assessment, executive and individual risk assessments, event and travel security assessments, and time-sensitive intelligence support to Corporate Security and cross-functional partners. You will turn complex and often incomplete information into clear assessments and actionable recommendations that help inform security and protective decisions. We are seeking candidates with intelligence experience, particularly in protective intelligence, threat investigations, or behavioral threat assessment. Successful candidates will understand the intelligence cycle, OSINT investigative techniques, corporate physical security, risk management, and threat assessment, and will be comfortable operating independently in a fast-moving environment involving sensitive and occasionally high-profile matters. This role could be based in San Francisco, CA, or may be a remote role for the right candidate. We use a hybrid work model of 3 days in the office per week. Relocation offered for those outside of the Bay Area. In this role, you will: Identify and investigate potential physical threats to OpenAI, its executives, employees, facilities, operations,

PythonAWSRestAI
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the Team OpenAI’s Cyber team works to make frontier AI a decisive advantage for defenders. The Cyber Blue Team is an operator-led group focused on turning real defensive problems into better models, useful products, safe Codex workflows, and integrations with the security tools defenders already use. Our ambition is simple: Raise attacker cost. Lower defender toil. Prove it by defending OpenAI; scale it through the ecosystem. We are not setting out to build another SIEM or autonomous SOC. We want to build the AI reasoning and workflow layer that helps security teams investigate threats, create and validate detections, improve their controls, and respond with greater speed and confidence. About the Role We are looking for a Product Manager to help build a new generation of AI-powered cyber defense products. You will work closely with security practitioners, researchers, engineers, designers, internal security teams, customers, and technology partners to turn emerging model capabilities into products that solve meaningful defensive problems. This is an early-stage product role. The work will span product discovery, prototyping, evaluation, development, launch, and iteration. You will help the team identify where AI can create the most value for defenders and translate those opportunities into clear, usable, and trustworthy product experiences. Initial areas of focus may include: Detection engineering and detection-content development Threat hunting and investigation Security validation and control testing AI-agent and MCP runtime defense Integrations with security platforms and enterprise workflows Safe, governed assistance for incident response The specific roadmap will continue to evolve based on model progress, practitioner needs, internal learnings, and customer feedback. In This Role, You Will Work with security practitioners to understand high-value defensive workflows, recurring pain points, and opportunities for AI to materially improve outcomes. Help sh

AWSRestAIGo
D
📍 New York, New York, United States· Full-time
✓ High-confidence listingCompany trend -85.2%

From $156K/yr

Quick readStrong listing-quality and freshness signals

The Team: As a Security Engineer 2 on the Cyber Threat Intelligence team, you will help Datadog stay ahead of evolving threats by identifying, analyzing, and operationalizing intelligence on threat actors, campaigns, and emerging threats. Working within Security Engineering, you will partner closely with security teams to translate intelligence into actionable security improvements across the company. You will serve as a subject matter expert on how the cyber threat landscape intersects with Datadog and contribute to intelligence-led decision making during both steady-state operations and active security incidents. This role provides opportunities to influence detection, response, and security strategy through technical analysis, collaboration, and intelligence-driven initiatives. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Develop and maintain tooling that automates the collection, processing, analysis, and dissemination of threat intelligence. Assess emerging vulnerabilities, threat activity, and security events to help stakeholders understand potential impact to Datadog. Conduct threat hunting and infrastructure analysis to identify adversary activity relevant to Datadog and improve defensive controls. Partner with security teams to operationalize intelligence into detections, investigations, and response workflows. Coordinate with information-sharing communities to gather, evaluate, and disseminate actionable intelligence. Produce technical briefings, threat reports, and intelligence products for security and engineering stakeholders. Who You Are: Experienced in writing and presenting operational and technical intelligence for threat detection, response, and security stakeholders. Skilled in partnering with detection and response te

LinuxAIGoRust
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -82%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer you will join our OpenAI engineers and researchers in building, operating and securing transformational AI technologies. This role will focus on all aspects of Detection & Response but with a strong emphasis on detecting insider threats and influencing controls to safeguard OpenAI's most sensitive assets. In this role, you will: In this role, you will: Innovate on Detection and Response infrastructure to engineer and automate end-to-end detection and investigation workflows. Develop, measure, and tune detection rules to ensure effective and sustainable operations. Drive projects across OpenAI’s technology stack with a focus on insider threats, ranging from access abuse and intellectual property theft to novel risks emerging within AI infrastructure. Partner closely with cross-functional stakeholders, including HR, Legal, and peer investigative teams, providing technical expertise and evidence to support investigations. Collaborate on cutting-edge AI research, and use AI to improve OpenAI’s Security posture. You might thrive in this role if you: 5+ years experience working in a detection/response or insider-risk role.. We are seeking mid-level and senior candidates. You have broad familiarity with operating systems and platforms such as macOS, Windows, Linux, and Kubernetes, along with experience in cloud infrastructure. Knowledge of modern adversary tactics and attack paths, data exfiltration techniques, and h

PythonAWSKubernetesLinux
C-
📍 New York, New York, United States· Full-time
✓ High-confidence listing

$145K – $170K/yr

Quick readStrong listing-quality and freshness signals

CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier—physically and digitally. With more than 43 million Members and a growing network of partners across the world, CLEAR's secure identity platform is transforming the way people live, work, and travel. Whether it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences. CLEAR is seeking a Senior Security Operations Analyst III to join our SOC team to help strengthen our ability to detect, investigate, and respond to evolving security threats. In this role, you’ll lead complex investigations, improve CLEAR’s threat detection and response capabilities, and serve as a trusted security partner while helping develop the analysts and program around you. What you'll do: Lead complex investigations of security events across corporate networks, endpoints, data centers, cloud environments, and other critical systems, driving incidents from initial analysis through escalation and remediation Develop, tune, and optimize threat detection logic across SIEM, EDR, and other security platforms, proactively identifying coverage gaps, reducing false positives, and improving the fidelity of security alerts Partner with Engineering, Infrastructure, and other teams to investigate threats, identify root causes, communicate risk, and drive timely remediation and improvements to CLEAR’s security posture Apply threat intelligence, data, automation, and AI-enabled tools to identify emerging attack patterns, accelerate investigations, improve detection workflows, and strengthen decision-making while applying sound security judgment Serve as a subject matter expert and escalation point for other analysts, mentoring junior team members, sharing knowledge, and helping establish scalable processes, playbooks, and standards for threat detection and analysis Continuously evaluate CLEAR’s detection coverage against the evolving t

GitRestAIGo
F
📍 United States· Full-time
✓ High-confidence listingCompany trend -85.5%

From $183.3K/yr

Quick readStrong listing-quality and freshness signals

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnershi

PythonKubernetesCI/CDRest
F
📍 San Francisco, California, United States· Full-time
✓ High-confidence listingCompany trend -85.5%

From $183.3K/yr

Quick readStrong listing-quality and freshness signals

About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. What you'll do There is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so nobody is paged at 3am local. The adversaries are real. The business is growing fast and the threat surface is growing with it. Defining the necessary telemetry is part of the job. Detection engineering Build and tune detections across endpoint, identity, SaaS, and cloud , treating them as software: version-controlled, peer-reviewed, and shipped through the same CI/CD practices the rest of engineering uses. Track detection quality as measured quantities : coverage against MITRE ATT&CK, precision, time-to-detect. We don’t build-and-forget here. Response & automation Own incident response: triage, contain, remediate, and write the retrospective that turns the incident into a systemic fix. Build automation that removes toil from investigations, and partner closely with the US-based team so context carries across time zones instead of getting lost at handoff. Telemetry & partnershi

PythonKubernetesCI/CDRest
M
📍 New York, new york, United States· Full-time
✓ Quality checkedCompany trend -67.9%

About Us: AI needs a new infrastructure layer. We're building it at Modal. Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now. Our customers include category-defining companies like Lovable , Ramp , Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale. We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September. Our team includes creators of popular open-source projects (e.g., Seaborn , Luig i ), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience. The Role: We're looking for a Detection & Response Engineer to build the systems that help us identify, investigate, and respond to threats across our platform. This is an engineering role focused on automation. You'll build detections, investigation tooling, and response capabilities that scale with our infrastructure, using AI where it meaningfully improves signal, investigation speed, and operational effectiveness. You'll work closely with infrastructure, platform, and security engineers to ensure every incident makes the platform more resilient. What You'll Work On: Detection Engineering Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents Improve visibility across cloud infrastruc

SQLKubernetesGitLinux
P
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -72.3%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. We are the first line of defense against fraud and abuse on the Plaid platform. Our mission is to ensure the safety and integrity of our platform for consumers and customers. As a Fraud and Abuse Operations Analyst , you will be responsible for responding to fraud and abuse events, investigating claims, and triaging incidents. We also partner with product and engineering teams to inform and improve fraud mitigation strategies. Responsibilities: Safeguard Plaid's Platform: Participate in the abuse on-call rotation, directly protecting our users and customers by responding to and resolving fraud and abuse events. Your timely actions will be instrumental in maintaining trust and security. Drive Investigations and Mitigate Risks: Investigate fraud and abuse claims from diverse sources, partnering with senior teammates on complex cases. Your findings will inform decisions and strategies, directly impacting Plaid's ability to prevent future incidents and minimize financial losses. Proactively perform threat modeling of abuse surfaces and continuously survey external fraud trends, adversary techniques, tooling, and emerging threat vectors Support Incident Response: Help triage and manage fraud and abuse ev

SQLAWSMachine LearningAI
R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $295.3K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. About the role: As a Principal Security Engineer on the Detection and Response (D&R) team at Roblox, you'll play a key role designing and developing effective custom security data pipeline systems, detection strategies and automations for response workflows to defend our critical assets from threat actors. You will also lead real-time incident response, actively investigate events and analyze threat actor techniques to prioritize emerging threats to ensure Roblox is equipped to mitigate and react to critical challenges. You will play a vital part to ensure the safety of our community and enterprise by proactively fostering a high-performing, inclusive security culture. This is a hybrid in-office role. You Will: Be a D&R authority! You will deliver robust detection & response capabilities: build new threat detection systems (keeping false positives low) while also automating processes with scripts, playbooks and orchestration tooling. Implement ETL pipelines : Design and develop customized data processing pipelines. Conduct security operations : Actively monitor security events and participate in on-call rotations to lead real-time incident response to contain and mitigate potent

JavaReactAWSCI/CD
A
📍 United States· Full-time
✓ High-confidence listingCompany trend -98.8%

From $196K/yr

Quick readStrong listing-quality and freshness signals

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way. The Community You Will Join: The Threat Detection and Response team (TDR) at Airbnb is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the incident lifecycle. This is the front-line team that detects, investigates, and responds to internal & external security threats and malicious activity. This is a key role to help define and execute our vision for threat detection and incident response capabilities and process while mentoring other team members. As a senior engineer on the team, you will have direct impact building, optimizing, and growing securing capabilities as you help deliver world-class threat detection and incident response. The Difference You Will Make: You will be a key member of our growing Threat Detection & Response (TDR) team. You will get an opportunity to define and execute on novel approaches to detecting, containing and mitigating threats and incidents. You will partner with cross-functional partners across the company to improve the overall security of Airbnb driven by learnings and root cause analysis of investigations and incidents resulting in removal of entire classes of problems. A Typical Day: Perform investigations of security incidents using your knowledge of digital forensics and data analytics. Use your coding, data analytics and investigation skills to hunt, detect and respond to threats. Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale. Hunt for threats in our corporate and prod

PythonSQLAWSGit
🔔

Get new threat investigator jobs in United States by email

Daily job updates · Unsubscribe anytime