About 10a Labs: 10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. Our adversarial red teaming, model evaluations, and intelligence collection enable engineering, safety, and security teams to stay ahead of evolving threats and deploy AI systems safely.
About the role:
10a Labs' Investigations Team is looking for a Senior Cyber Investigator to support critical safety incidents and conduct investigations across a range of cyber abuse areas. This role requires deep cybersecurity subject-matter expertise to detect and respond to malicious activity, assess threat actor behavior at the organizational level, and handle escalated cases requiring senior technical judgment.
Investigations may involve exposure to harmful or disturbing content, including malicious code, exploit development, and content designed to facilitate cyberattacks.
In this role, you will:
- Detect and investigate malicious uses and cyber abuse, including cases involving scaled data extraction, ransomware, and local and remote exploits
- Conduct org-level analysis of threat actor behavior, identifying patterns across cases to inform detection and mitigation strategies
- Handle escalated and technically complex cases, applying senior cybersecurity expertise to assess real-world harm potential
- Query internal data sources using SQL and Python and cross-reference open-source information (OSINT) to support investigations
- Document and share investigative findings and recommendations with internal stakeholders and client teams
- Support quality and consistency across the investigations team, providing guidance to junior investigators on ambiguous cases
- Respond to reactive escalations and on-call leads, including those not caught by existing safety systems
Required Qualifications:
- At least 5+ years of experience in cybersecurity, threat intelligence, Trust & Safety, national security, defense, intelligence, or law enforcement domains
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience
- Familiarity with LLM systems and how AI technology can be misused for cyber operations
- Deep subject-matter expertise in one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations
- Strong ability to assess the real-world harm potential of technical content, distinguishing genuine offensive uplift from benign or educational security research
- Strong SQL and Python proficiency for querying data and supporting detection workflows
- Proven experience conducting org-level threat actor analysis across large datasets
- Ability to rapidly context-switch across domains, modalities, and abuse areas in a fast-paced, ambiguous environment
- Ability to clear an insider-threat background check
Preferred Qualifications:
- Experience with threat intelligence frameworks such as MITRE ATT&CK
- Background in dark web monitoring, OSINT, or cross-platform threat analysis
- Experience scaling and automating detection and mitigation processes
- Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish
- Relevant certifications such as OSCP, GREM, or GCTI
Compensation & Benefits:
- Salary Range: $115K–$140K, depending on experience and location
- Work Environment: Fully remote, U.S.-based
- Health Benefits: Comprehensive health, dental, and vision coverage
- Time Off: Generous PTO and paid holiday schedule
- Retirement: 401(k) plan