Abuse Investigator
Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.
About the job
Responsibilities
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using detection and signal-enrichment techniques.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify threats using Fraud Taxonomy 3.0 (FT3).
- Lead incident root-cause analyses to identify gaps in systems and strategies and drive improvements for emerging fraud risks.
- Streamline incident-response tooling and processes for clarity, accuracy, and efficiency.
- Collaborate with security, fraud, and data science teams to build agentic solutions for responding to abuse incidents at scale.
- Work with legal and policy teams to assess and mitigate risks.
- Lead projects, mentor teammates, and develop quality standards.
Requirements
- 3+ years of experience conducting incident response in security, product abuse, or trust domains.
- 3+ years of experience analyzing large datasets to solve problems and/or building behavioral fraud-detection models.
- Bachelor's or master's degree in Computer Science or a related field, or equivalent experience.
- Expert knowledge of Python and SQL, with familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident-response investigations.
- Strong communication, problem-solving, and risk-reduction skills.
Nice-to-haves
- Adversarial mindset and understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures (TTPs).
- Experience with engineering, data-processing, and analysis tools such as Databricks and Trino.
- Familiarity with big-data processing and data-science frameworks such as PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence and hunting sophisticated threat actors in enterprise environments.
- Experience addressing complex product-integrity challenges through data-driven, user-centric approaches.
Skills
Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Fraud Detection, Databricks, Trino, Pyspark, pandas, scikit-learn, Threat Intelligence, Data Analysis
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.