Abuse Investigator
Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.
About the job
Responsibilities
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using detection and signal-enrichment methods.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify threats using the Fraud Taxonomy 3.0 framework.
- Lead incident root-cause analyses to identify system and strategy gaps and drive data-informed improvements for emerging fraud risks.
- Improve incident-response tooling and processes for clarity, accuracy, and efficiency.
- Collaborate with security, fraud, and data science teams to build agentic solutions for responding to abuse incidents at scale.
- Work with legal and policy teams to assess and mitigate risks.
- Lead projects, mentor teammates, and develop quality standards.
Requirements
- 3+ years of experience conducting incident response in security, product abuse, or trust domains.
- 3+ years of experience analyzing large datasets to solve problems and/or building behavioral models for fraud detection.
- Bachelor's or master's degree in Computer Science or a related field, or equivalent experience.
- Expert knowledge of Python and SQL; familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident-response investigations.
- Strong communication, problem-solving, and risk-reduction skills.
Preferred Qualifications
- Adversarial mindset and understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures.
- Experience with engineering, data-processing, and analysis tools such as Databricks and Trino.
- Familiarity with big-data and data-science frameworks such as PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence and threat hunting for sophisticated enterprise threat actors.
- Ability to use data and a user-centric approach to address complex product-integrity challenges.
Skills
Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Fraud Detection, Databricks, Trino, Pyspark, pandas, scikit-learn, Threat Intelligence, Threat Hunting, Data Analysis
Similar jobs
Security Engineering jobsInvestigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.
Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.