Lead Insider Threat Investigator

Airbnb Airbnb · Consumer · Sydney, Australia · Trust and Safety

Lead Investigator for Insider Threat, focusing on complex investigations involving cybersecurity, financial misconduct, IP theft, and data exfiltration. Responsibilities include technical investigations, OSINT, interviews, evidence collection, and ensuring adherence to legal and regulatory requirements. Requires deep expertise in digital forensics, cloud security, log analysis, and enterprise forensic tools, along with strong legal acumen.

What you'd actually do

  1. Conducting high-risk, complex insider threat investigations involving cybersecurity, financial misconduct, intellectual property theft, unauthorized access, and data exfiltration.
  2. Conduct technical investigations, guide OSINT research, perform subject interviews, evidence collection, data deletion, and asset retrieval, while ensuring adherence to employment law, corporate policies, and regulatory requirements.
  3. Utilize a functional understanding of information security principles, practices, and frameworks.
  4. Investigate identified insider threat cases escalated from the Information Security Engineering team, including: Conduct structured investigative interviews with subjects and relevant stakeholders to validate findings and gather additional intelligence.
  5. Ensure investigations adhere to employment law, corporate policies, data privacy regulations, and commercial legal frameworks.

Skills

Required

  • Insider threat investigations
  • Digital forensics
  • Cloud security
  • Log analysis
  • Enterprise forensic tools
  • Legal acumen
  • Cybersecurity
  • Financial misconduct investigation
  • Intellectual property theft investigation
  • Data exfiltration investigation
  • OSINT research
  • Subject interviews
  • Evidence collection
  • Data deletion
  • Asset retrieval
  • Employment law
  • Corporate policies
  • Regulatory compliance
  • Windows forensics
  • macOS forensics
  • Chrome OS forensics
  • SQL-based forensic data correlation
  • Behavioral anomaly analysis
  • Kubernetes investigation
  • Communication skills

Nice to have

  • GIAC certifications (GCFA, GCFE)
  • CISSP
  • AWS Security certification
  • Google Security certification
  • Azure Security certification
  • CompTIA Cloud+
  • Kubernetes Security certification
  • Kubernetes Fundamentals certification

What the JD emphasized

  • high-risk, complex insider threat investigations
  • cybersecurity
  • financial misconduct
  • intellectual property theft
  • unauthorized access
  • data exfiltration
  • technical investigations
  • OSINT research
  • subject interviews
  • evidence collection
  • data deletion
  • asset retrieval
  • employment law
  • corporate policies
  • regulatory requirements
  • deep technical expertise
  • digital forensics
  • cloud security
  • log analysis
  • enterprise forensic tools
  • strong legal acumen
  • corporate risk
  • HR
  • compliance considerations
  • structured investigative interviews
  • incident response
  • Information Security
  • HR
  • Legal
  • custom high-severity data deletions
  • secure asset retrieval
  • legal
  • regulatory
  • corporate policies
  • forensic collection of digital evidence
  • endpoints
  • cloud storage
  • mobile devices
  • log analysis
  • event queries
  • enterprise systems
  • digital behaviour
  • correlate human events and factors
  • investigative strategies
  • technical evidence
  • forensic artifacts
  • digital environments
  • insider threat activities
  • employment law
  • corporate policies
  • data privacy regulations
  • commercial legal frameworks
  • Legal
  • HR
  • Privacy
  • Compliance teams
  • corporate risk
  • legal exposure
  • remediation strategies
  • high-profile cases
  • executive leadership
  • cross-functional security teams
  • post-mortem reviews
  • investigative methodologies
  • lessons learned
  • 10-12 years of experience
  • insider threat investigations
  • security
  • digital forensics
  • related industries
  • Proven experience
  • high-risk, legally sensitive investigations
  • corporate executives
  • critical business functions
  • Strong expertise
  • Windows, MacOS, and Chrome OS forensic tools
  • Experience in SQL-based forensic data correlation
  • behavioral anomaly analysis
  • Strong employment legal and commercial legal acumen
  • experience handling workplace investigations
  • regulatory compliance
  • digital forensic tools
  • Advanced knowledge
  • Windows Event Viewer
  • MacOS Console
  • Chrome OS system logs
  • forensic evidence retrieval
  • investigating cloud environments
  • Kubernetes
  • high-severity data deletion
  • asset retrieval
  • corporate environments
  • investigative interviews
  • communicate findings clearly and effectively
  • legal
  • HR
  • security teams