Incident Response Manager - Abuse Operations
Leads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.
About the job
Responsibilities
- Lead fraud and abuse incident response end-to-end, coordinating workstreams, investigating high-risk activity and accounts, and making actionable mitigation recommendations under pressure.
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using FT3-mapped detection and signal enrichment.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify findings using Fraud Taxonomy 3.0.
- Develop, document, and execute incident response strategies, runbooks, and capabilities to improve fraud and abuse detection and prevention.
- Partner with security, data science, legal, and policy teams to build automated or agentic response solutions, refine KPIs, and deliver incident reporting.
- Mentor teammates, lead incident response engineering projects, and improve quality standards across the team.
Requirements
- 10+ years of experience leading security or fraud incident response.
- B.S. or M.S. in Computer Science, or equivalent experience.
- Expert knowledge of Python and SQL; familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident response investigations.
- Ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills, with experience driving cross-functional alignment independently.
Preferred Qualifications
- Expertise in fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- Understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures.
- Experience with engineering, data processing, and analysis tools such as Databricks and Trino.
- Familiarity with big-data processing and data-science frameworks, including PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence or hunting sophisticated threat actors in an enterprise environment.
- Ability to use data and a user-centric approach to address complex product-integrity challenges.
Skills
Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Threat Intelligence, Databricks, Trino, Pyspark, pandas, scikit-learn
Similar jobs
Security Engineering jobsLeads live fraud and abuse incident response, investigates high-risk accounts, and helps merchants remediate security threats. Requires 10+ years of security or fraud incident-response experience, expert Python and SQL skills, and expertise in forensics, threat intelligence, and network security.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.