Higgsfield logo

Data Analyst, Antifraud

Moves you to
Kazakhstan
Support
Relocation support
Posted
Sep 30, 2026
Is this job info correct?

Why work at Higgsfield AI?

Higgsfield AI is the fastest-scaling generative AI company in history, hitting $1B in annual revenue run rate, 30M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.

We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.

What This Role Means at Higgsfield

Most subscription businesses lose a password. We lose GPU-seconds.

When someone runs two hundred accounts off one card to harvest a per-account promotional grant, the cost lands on our compute bill the same hour, and it does not stop until somebody finds them. We have found operators doing exactly that — hundreds of accounts, synchronised signups, machine- generated emails, round-the-clock automation — and we have also found that most of our worst- margin accounts are not abusers at all, just heavy users on an unlimited plan. Telling those two apart, account by account, with evidence that survives being challenged, is this job.

You are the person who finds them, proves it, and puts a number on it.

You make sure:

  • Every enforcement action we take is backed by evidence a stranger could follow

  • We know what abuse cost us last month, on the same basis as last month

  • The detection system is measured against real cases, not against its own past decisions

  • When a ring changes shape, somebody notices this week — and that somebody is you

What You Will Do

Investigation & casework

  • Run ring investigations end to end: from a flagged account or a cost anomaly to a named cluster, its members, its signature, its lifetime economics and a recommended action.

  • Build the linkage yourself — shared payment instruments, IP and ASN concentration, email-stem families, registration bursts, behavioural and automation fingerprints — and know which links are evidence and which are coincidence.

  • Separate abuse from unprofitable-but-legitimate every single time. On an unlimited plan, negative gross margin is normal. Cost is a gate, never a trigger.

  • Triage the review queue the detection system produces, and feed what you learn back into it. Your adjudications are the only unbiased labels the scientist has.

Evidence & defensibility

  • Produce evidence packages that hold up outside the company — to an external auditor, to a payment network, to a customer disputing a ban, to Legal enforcing our Terms. Our abuse work has already been used in all four contexts.

  • Write per-account, not per-ring, when the action is per-account. A ban list without a reason column is not evidence.

  • Know what our Terms of Use actually entitle us to do, and flag when the evidence supports the finding but not the action.

Quantification & reporting

  • Own the abuse loss number: what it cost, on what basis, net of the revenue we reversed and the legitimate customers we caught by mistake. Same definition every month, written down.

  • Distinguish COGS burned, revenue at risk, revenue reversed and cash refunded — they are four different numbers and people will conflate them.

  • Build the recurring reporting that tells us whether the problem is growing, and the ad-hoc answer to "why did compute spike last Tuesday" that is due the same day.

Monitoring & adaptation

  • Watch the detectors themselves. A rule that stops firing is a detection event, not a quiet week.

  • Check the instrument before explaining the movement: a missing upstream table, a silently dropped join, a vendor signal that went away. This has bitten us and it will again.

  • Spot new abuse patterns before they are in anybody's model — usually in a cost anomaly, a strange cohort, or a support ticket that does not fit.

How we work

  • SQL and Python on raw payment, usage and identity data in BigQuery, without anyone preparing it for you. We use AI heavily — resourcefulness beats syntax.

  • Close partnership with the Antifraud data scientist (you validate what they build), Payments (chargebacks and processor signals), Support (the humans who meet your false positives) and Finance (the loss number goes in the accounts).

Who We're Looking For

  • 2+ years doing investigative or risk analytics — fraud, abuse, trust and safety, AML, chargebacks, gaming or marketplace integrity. What matters is that you have chased real bad actors, not modelled them in the abstract.

  • Strong SQL, without help. Self-joins, window functions, cohort replay, and joining payments to usage to identity across messy keys. This is the single most-used skill in the role.

  • Python at working level for analysis — pandas, notebooks, a bit of graph work.

  • Investigative instinct: you follow the thread, you notice the thing that does not fit, and you can say when a pattern is a coincidence.

  • Evidentiary discipline: you can write up a finding so that somebody who distrusts you can check it, and you know the difference between "this looks like abuse" and "this is provable."

  • Unit-economics literacy: gross margin per account, what compute costs, and why a negative-margin customer may be entirely legitimate.

  • The judgment to escalate rather than act when the evidence is thin, and to say so in writing.

  • Clear written and spoken English, B2+.

Backgrounds that often do well:

  • Fraud / risk analysts from fintech, payments, marketplaces, gaming, crypto or betting

  • Trust & safety investigators and platform-integrity analysts

  • Chargeback, dispute or AML analysts who write their own queries

  • Strong product or BI analysts who got handed the abuse problem and kept it

What This Role Is Not

This role is not a fit if you:

  • Want to build models full time — that is the Antifraud data scientist, and it is open

  • Want to do content moderation or NSFW classification

  • Would put an account on a ban list without being able to say why in one sentence

  • Treat every negative-margin account as an abuser

  • Need a labelled dataset or a clean table before you can start

  • Are uncomfortable that your work gets real people's accounts restricted, sometimes wrongly

  • Want predictable 9–5 workdays

Hiring Process

  • First interview (30 min)

  • Business case (60 min)

  • Take-home with real-shaped data (7 days, ~10–12 hours of work)

  • Team interview (60 min)

  • Paid on-site trial (1 month)

The Deal

  • Competitive salary in USD

  • Equity: participation in the company's stock option program

  • On-site role in Almaty, Kazakhstan

  • Relocation support (flight + temporary housing)

  • Flat structure, high autonomy, fast career growth

Similar jobs

Apply for this job