How to apply for Technical Threat Investigator, Threat Intel Engineering

OpenAI

About OpenAI

OpenAI is a frontier AI research and product company with teams working on alignment, policy, and security. It posts specific high-impact opportunities, and the Threat Intelligence team protects OpenAI's technology, people, research, and infrastructure from adversaries who compromise systems or misuse models.

About the role

This is a deeply investigative role. You will independently run complex, end-to-end investigations into capable threat actors, covering their behavior, infrastructure, emerging techniques, and how AI is integrated into their workflows. Findings feed into detection, disruption, enforcement, and safety improvements, and into tooling that scales analysis.

A typical day

A typical day likely includes independent investigation into a threat actor or campaign, analysis of infrastructure and techniques, and coordination with detection, enforcement, or safety teams. You may also build or refine tooling to scale analysis and prepare findings for leadership. The posting does not describe a fixed daily routine, so ask about team cadence and on-call expectations in interviews.

Who OpenAI is looking for

  • Has run end-to-end threat investigations independently, from initial lead to written findings and handoff.
  • Understands adversary infrastructure, tracking, and emerging techniques, and can map how AI is used in cyber operations.
  • Can build lightweight tooling to scale and augment analysis, not just produce one-off reports.
  • Works well with detection, enforcement, safety, and research teams, and can present risk-aware insights to leadership.

Tips for this application

  • Frame your experience around independent, end-to-end investigations. Name the threat actors or campaigns you investigated, the methods you used, and the outcomes you drove.
  • Show how your findings turned into durable solutions such as detections, disruptions, or enforcement actions. OpenAI states this role translates investigative findings into scalable impact.
  • Demonstrate tooling you have built to scale threat analysis. Concrete examples of scripts, pipelines, or analysis tooling carry more weight than general claims.
  • Address AI in adversary workflows directly. Explain what you have observed or assessed about how threat actors integrate AI, since this is a core part of the role.
  • Read OpenAI's career review on working at a frontier AI lab and be ready to discuss your reasoning. The posting explicitly links to concerns about doing harm by working at a frontier AI company.

What to cover in your cover letter

['One or two specific investigations you led end-to-end, including the threat actor, your methods, and the impact.', 'How you turn investigative findings into detection, disruption, enforcement, or safety improvements.', 'Any tooling or automation you built to scale threat intelligence analysis.', 'Your understanding of AI misuse in cyber operations and how you would investigate it.']

Draft a cover letter

Research before applying

  • Read OpenAI's threat intelligence and security-related publications to understand how the team frames adversaries and model misuse.
  • Read the 80,000 Hours career review on working at an AI lab, which OpenAI links in the posting, and form a view on the tradeoffs.
  • Study OpenAI's usage policies and safety approach, since the role covers adversaries attempting to misuse models.
  • Review public reporting on AI-enabled cyber operations to prepare for questions about how AI fits into threat actor workflows.
OpenAI website

Likely interview topics

Based on the job description, expect questions about:

  • Walk through an end-to-end investigation you ran independently. What was the initial lead, and how did it conclude?
  • How do you track and attribute adversary infrastructure and emerging techniques?
  • How have you seen AI integrated into threat actor workflows, and how would you investigate that?
  • Describe tooling you built to scale threat analysis. What did it automate, and what was the impact?
  • How do you translate investigative findings into detection, disruption, or enforcement actions across teams?
Practise interview questions

Common mistakes to avoid

  • Presenting only high-level summaries of threat intelligence without showing hands-on investigative work and specific cases.
  • Treating the role as a standard SOC or detection engineering position. The posting describes a deeply investigative role with independent end-to-end work.
  • Ignoring the AI misuse angle. The role explicitly covers adversaries using AI in cyber operations, so omitting it leaves a gap.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.