Skip to content

Open nowPosted 2 days ago

Data Analyst, Antifraud

Higgsfield AI79 open roles

Where
Almaty, Kazakhstan
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowData Analyst, AntifraudHiggsfield AI · Almaty, Kazakhstan
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Higgsfield AI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Higgsfield AI postings stay open a median of 29 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 2 days ago

Higgsfield AI median: 29 days open

The posting

WHY WORK AT HIGGSFIELD AI?

Higgsfield AI is the fastest-scaling generative AI company in history, hitting $1B in annual revenue run rate, 30M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.

We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.

WHAT THIS ROLE MEANS AT HIGGSFIELD

Most subscription businesses lose a password. We lose GPU-seconds.

When someone runs two hundred accounts off one card to harvest a per-account promotional grant, the cost lands on our compute bill the same hour, and it does not stop until somebody finds them. We have found operators doing exactly that — hundreds of accounts, synchronised signups, machine- generated emails, round-the-clock automation — and we have also found that most of our worst- margin accounts are not abusers at all, just heavy users on an unlimited plan. Telling those two apart, account by account, with evidence that survives being challenged, is this job.

You are the person who finds them, proves it, and puts a number on it.

You make sure:

- Every enforcement action we take is backed by evidence a stranger could follow

- We know what abuse cost us last month, on the same basis as last month

- The detection system is measured against real cases, not against its own past decisions

- When a ring changes shape, somebody notices this week — and that somebody is you

WHAT YOU WILL DO

Investigation & casework

- Run ring investigations end to end: from a flagged account or a cost anomaly to a named cluster, its members, its signature, its lifetime economics and a recommended action.

- Build the linkage yourself — shared payment instruments, IP and ASN concentration, email-stem families, registration bursts, behavioural and automation fingerprints — and know which links are evidence and which are coincidence.

- Separate abuse from unprofitable-but-legitimate every single time. On an unlimited plan, negative gross margin is normal. Cost is a gate, never a trigger.

- Triage the review queue the detection system produces, and feed what you learn back into it. Your adjudications are the only unbiased labels the scientist has.

Evidence & defensibility

- Produce evidence packages that hold up outside the company — to an external auditor, to a payment network, to a customer disputing a ban, to Legal enforcing our Terms. Our abuse work has already been used in all four contexts.

- Write per-account, not per-ring, when the action is per-account. A ban list without a reason column is not evidence.

- Know what our Terms of Use actually entitle us to do, and flag when the evidence supports the finding but not the action.

Quantification & reporting

- Own the abuse loss number: what it cost, on what basis, net of the revenue we reversed and the legitimate customers we caught by mistake. Same definition every month, written down.

- Distinguish COGS burned, revenue at risk, revenue reversed and cash refunded — they are four different numbers and people will conflate them.

- Build the recurring reporting that tells us whether the problem is growing, and the ad-hoc answer to "why did compute spike last Tuesday" that is due the same day.

Monitoring & adaptation

- Watch the detectors themselves. A rule that stops firing is a detection event, not a quiet week.

- Check the instrument before explaining the movement: a missing upstream table, a silently dropped join, a vendor signal that went away. This has bitten us and it will again.

- Spot new abuse patterns before they are in anybody's model — usually in a cost anomaly, a strange cohort, or a support ticket that does not fit.

How we work

- SQL and Python on raw payment, usage and identity data in BigQuery, without anyone preparing it for you. We use AI heavily — resourcefulness beats syntax.

- Close partnership with the Antifraud data scientist (you validate what they build), Payments (chargebacks and processor signals), Support (the humans who meet your false positives) and Finance (the loss number goes in the accounts).

WHO WE'RE LOOKING FOR

- 2+ years doing investigative or risk analytics — fraud, abuse, trust and safety, AML, chargebacks, gaming or marketplace integrity. What matters is that you have chased real bad actors, not modelled them in the abstract.

- Strong SQL, without help. Self-joins, window functions, cohort replay, and joining payments to usage to identity across messy keys. This is the single most-used skill in the role.

- Python at working level for analysis — pandas, notebooks, a bit of graph work.

- Investigative instinct: you follow the thread, you notice the thing that does not fit, and you can say when a pattern is a coincidence.

- Evidentiary discipline: you can write up a finding so that somebody who distrusts you can check it, and you know the difference between "this looks like abuse" and "this is provable."

- Unit-economics literacy: gross margin per account, what compute costs, and why a negative-margin customer may be entirely legitimate.

- The judgment to escalate rather than act when the evidence is thin, and to say so in writing.

- Clear written and spoken English, B2+.

Backgrounds that often do well:

- Fraud / risk analysts from fintech, payments, marketplaces, gaming, crypto or betting

- Trust & safety investigators and platform-integrity analysts

- Chargeback, dispute or AML analysts who write their own queries

- Strong product or BI analysts who got handed the abuse problem and kept it

WHAT THIS ROLE IS NOT

This role is not a fit if you:

- Want to build models full time — that is the Antifraud data scientist, and it is open

- Want to do content moderation or NSFW classification

- Would put an account on a ban list without being able to say why in one sentence

- Treat every negative-margin account as an abuser

- Need a labelled dataset or a clean table before you can start

- Are uncomfortable that your work gets real people's accounts restricted, sometimes wrongly

- Want predictable 9–5 workdays

HIRING PROCESS

- First interview (30 min)

- Business case (60 min)

- Take-home with real-shaped data (7 days, ~10–12 hours of work)

- Team interview (60 min)

- Paid on-site trial (1 month)

THE DEAL

- Competitive salary in USD

- Equity: participation in the company's stock option program

- On-site role in Almaty, Kazakhstan

- Relocation support (flight + temporary housing)

- Flat structure, high autonomy, fast career growth

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Higgsfield AI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Higgsfield AI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Higgsfield AI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.