Investigator
Investigates and responds to complex fraud and product-abuse incidents, analyzes high-risk accounts and threat patterns, and improves detection and response at scale. Requires 3+ years of incident response and data analysis experience, strong Python and SQL skills, and expertise in security investigations.
About the job
Responsibilities
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using detection and signal-enrichment data.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify threats using Fraud Taxonomy 3.0 (FT3).
- Lead incident root-cause analyses to identify system and strategy gaps and drive improvements for emerging fraud risks.
- Improve incident-response tooling and processes for clarity, accuracy, and efficiency.
- Collaborate with security, fraud, and data science teams to build agentic solutions for abuse-incident response at scale.
- Work with legal and policy teams to assess and mitigate risks.
- Lead projects, mentor teammates, and champion quality standards.
Requirements
- 3+ years of incident-response experience in security, product abuse, or trust domains.
- 3+ years of experience analyzing large datasets to solve problems and/or building behavioral fraud-detection models.
- Bachelor's or master's degree in computer science or a related field, or equivalent experience.
- Expert knowledge of Python and SQL, with familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident-response investigations.
- Clear communication, strong problem-solving, and the ability to think creatively and holistically about risk reduction.
Nice-to-haves
- Adversarial mindset and understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures (TTPs).
- Experience with engineering, data-processing, and analysis tools such as Databricks and Trino.
- Familiarity with big-data and data-science frameworks such as PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence and hunting sophisticated threat actors in enterprise environments.
- User-centric approach to complex product-integrity challenges.
Skills
Python, SQL, Incident Response, Fraud Detection, Log Analysis, Network Security, Digital Forensics, Databricks, Trino, Pyspark, pandas, scikit-learn, Threat Intelligence, Data Analysis, Ft3
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.