Forward Deployed Security Engineer
Leads live fraud and abuse incident response, investigates high-risk accounts, and helps merchants remediate security threats. Requires 10+ years of security or fraud incident-response experience, expert Python and SQL skills, and expertise in forensics, threat intelligence, and network security.
About the job
Responsibilities
- Respond to live fraud and abuse incidents as a forward-deployed security engineer, investigating high-risk activity, neutralizing active attacks, and mitigating security risks.
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using Fraud Taxonomy 3.0 detection and signal enrichment.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify findings using Fraud Taxonomy 3.0.
- Develop, document, and execute incident-response strategies, runbooks, and capabilities to improve fraud and abuse detection and prevention.
- Partner directly with impacted merchants and customers to investigate root causes, remediate vulnerabilities, and secure accounts.
- Serve as an operational and technical liaison for legal teams, policy partners, and threat-intelligence communities.
- Build relationships with external threat-intelligence communities, peer working groups, and law-enforcement agencies.
- Build automated response workflows, leverage threat intelligence, and recommend risk mitigations.
Requirements
- 10+ years of experience leading security or fraud incident response.
- B.S. or M.S. in Computer Science, or equivalent experience.
- Expert knowledge of Python and SQL; familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident-response investigations.
- Ability to drive cross-functional alignment with minimal oversight.
- Previous work with law enforcement.
- Engagement in threat-intelligence sharing communities.
Nice-to-haves
- Broad expertise in fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- Understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures.
- Experience with Databricks, Trino, or similar engineering, data-processing, and analysis tools.
- Familiarity with PySpark, Pandas, scikit-learn, or similar open-source data-processing and data-science frameworks.
- Experience with tactical threat intelligence or hunting sophisticated threat actors in an enterprise environment.
- Experience speaking or participating in external conferences or similar industry engagements.
Skills
Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Threat Intelligence, Databricks, Trino, Pyspark, pandas, scikit-learn, Fraud Detection, Risk Management, Law Enforcement
Similar jobs
Security Engineering jobsLeads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads product security strategy and assessments for MongoDB’s server products, partnering with engineers on threat modeling, secure architecture, vulnerability research, and remediation. The role requires 7+ years of security experience and strong C++ expertise with low-level codebases.