Safeguards Enforcement Analyst, Account Takeover & Credential Abuse
Anthropic · Safeguards (Trust & Safety)
- Pay
- $245,000–$285,000/yr
- Where
- San Francisco, CA | New York City, NY | Washington, DC
- Posted
- Jul 14
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
As a Safeguards Enforcement Analyst on the account abuse team, you'll build and execute enforcement workflows that keep our products safe, with a focus on detecting and mitigating potential harm. Your initial focus will be account compromise: Anthropic's enforcement systems have to distinguish customers whose accounts have been compromised from actors abusing the platform — and today those two populations can look identical in the data.
What you'd do
- Investigate credential-compromise incidents across first-party and third-party platforms, tracing actor behavior across accounts and surfaces
- Design and operate remediation workflows for compromised accounts: revocation, customer notification, and standards for restoring access
- Partner with Engineering and Data Science teams to improve how we separate compromised-customer traffic from willful abuse
- Enforce usage policies with a focus on detecting and mitigating potentially harmful use of AI systems
- Work with threat intelligence on emerging credential-abuse patterns and the actors behind them
- Support the Safeguards policy design team by providing detailed feedback on policy gaps based on real enforcement scenarios
- Keep up to date with emerging AI policy enforcement best practices, and use these to inform our decision-making and workflows
- Write the policy framework for compromise scenarios, including cases where Anthropic can't independently verify a customer's security posture
- Act as the enforcement SME when account compromise intersects with active abuse investigations
What they want
- Experience in trust and safety, fraud investigation, security operations, or a related field
- Subject matter expertise in one or more of: account takeover, credential abuse, session security, or incident response
- Experience designing or operating enforcement, remediation, or customer-recovery flows — not just detection
- Comfort using data (SQL or similar tools) to trace actor behavior across accounts and to measure what's working
- A thoughtful perspective on the tension between protecting the platform and restoring access for legitimate compromised customers
- Strong written communication skills, with experience producing clear briefs about messy incidents for technical and non-technical stakeholders
- Excellent judgment and the ability to collaborate with team members while navigating rapidly evolving priorities and workstreams