Requirements
- •7+ years of experience in insider risk, detection engineering, security operations, incident response, digital forensics, data protection, threat hunting, or a related security field
- •2+ years leading an insider risk, investigations, or closely related security team
- •Demonstrated ability to lead a team while remaining hands-on in technical investigations and detection development
- •Experience managing the full investigation lifecycle, including scoping, evidence collection, timeline development, analysis, documentation, escalation, and lessons learned
- •Strong knowledge of digital forensics, evidence preservation, chain of custody, incident-response coordination, and case management
- •Experience partnering with Legal and People teams on sensitive workforce investigations
- •Sound understanding of the legal, privacy, confidentiality, and employee-relations considerations associated with workforce investigations
- •Experience working in software, financial services, or another industry that handles highly sensitive data
- •Strong written and verbal communication skills, sound judgment, and the ability to operate discreetly in high-trust situations
What You'll Do
- •Lead, develop, and mentor the Insider Trust team
- •Direct and conduct investigations involving sensitive data, systems, and workforce activity
- •Build and improve detections, monitoring, and escalation workflows for insider risk
- •Ensure investigations are timely, proportionate, well documented, and supported by defensible evidence
- •Partner with Legal, People, IT, and Security throughout the investigation and response lifecycle
- •Identify control gaps and translate investigative findings into lasting technical and process improvements
- •Establish metrics that demonstrate program effectiveness, investigative quality, and detection coverage
- •Communicate sensitive findings clearly to both executive and working-level stakeholders
Nice to Have
- •Experience working in a remote-first and globally distributed company
- •Experience investigating data movement across email, cloud storage, collaboration platforms, source-code repositories, build systems, artifact stores, browsers, AI tools, removable media, and unmanaged or partially managed devices
- •Hands-on experience with SIEM, DLP, or endpoint telemetry
- •Experience developing queries, analytics, or automation to identify and investigate suspicious behavior
- •Experience establishing investigation playbooks, escalation criteria, program metrics, and detection coverage
- •Experience leading projects, reviewing technical designs, and mentoring engineers or investigators
- •Working knowledge of blockchain technology, including hardware wallets and signing operations
