Risk Investigator - Third Party/ATO Fraud

1 hour, 53 minutes ago
Full-time
Senior
Cybersecurity
Mercury

Mercury

Mercury provides online business banking solutions tailored for startups and small businesses, offering streamlined financial workflows and quick application processes to enhance operational efficiency.

Banks
251-1K
Founded 2017
$152M raised

Description

  • Lead complex investigations into suspected account takeover incidents and determine risk, containment, and recovery actions.
  • Own end-to-end response for high-impact, executive-visible cases across Fraud, Support, Product, Engineering, Compliance, Legal, and Leadership.
  • Communicate directly with customers during sensitive account security incidents with timely, empathetic guidance.
  • Develop and improve ATO investigation policies, playbooks, and operational workflows.
  • Partner with Product, Engineering, and Risk teams to identify detection gaps and improve authentication controls and fraud detection.
  • Escalate emerging account takeover trends and attacker behaviors into actionable operational and product improvements.
  • Provide subject matter expertise during critical incidents and guide strategy for the most complex cases.
  • Identify opportunities to automate investigative tasks and improve tooling, efficiency, and customer experience.
  • Maintain clear, defensible investigative documentation for internal, regulatory, and cross-functional use.
  • Mentor teammates, share best practices, and contribute to onboarding and training materials.

Requirements

  • 3+ years of direct experience investigating and responding to account takeover fraud incidents in a bank, fintech, payments company, or other financial services organization.
  • Deep expertise in account takeover methodologies, attacker tactics, authentication systems, identity verification, and account recovery processes.
  • Experience identifying common fraud typologies such as wire fraud, ACH fraud, check fraud, mule accounts, and identity theft.
  • Ability to lead complex, ambiguous investigations while balancing customer experience, fraud risk, and operational efficiency.
  • Exceptional customer-facing communication skills for high-impact or executive-visible incidents.
  • Excellent judgment in time-sensitive decisions affecting customer access, account security, and financial risk.
  • Ability to influence and collaborate with Product, Engineering, Compliance, Customer Support, and Leadership.
  • Ability to communicate complex investigative findings clearly and concisely, verbally and in writing.
  • Track record of improving operational processes, tooling, or automation.
  • Highly organized with exceptional attention to detail while managing multiple critical investigations.
  • Experience mentoring teammates and helping build a strong investigative culture (preferred).
  • Strong product mindset and curiosity about evolving fraud threats and customer security.
  • Motivation to protect customers and improve detection, investigation, and response to account takeover threats.

Benefits

  • Base salary of $121,700-$152,100 for NYC, Los Angeles, Seattle, or the San Francisco Bay Area; $109,500-$136,900 elsewhere in the US.
  • Equity in the form of stock options.
  • Total rewards package including benefits.
  • Competitive compensation within the SaaS and fintech industry.
  • Reasonable accommodations during the recruitment process for applicants with disabilities or special needs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Screening Analyst

Qonto 1K-5K Banks

Qonto is hiring a Screening Analyst to support its Financial Crime team in protecting customers and ensuring compliant operations across European markets.

Swift
53 minutes ago

Senior Detection & Response Analyst

Toyota Tsusho Systems 51-250 IT Services

Toyota Tsusho Systems US, Inc. is hiring a Senior Detection and Response Analyst to support its Regional Security Operations program by providing 24x7 security monitoring, incident handling, and threat response.

Active Directory Cybersecurity DNS HTTP Sentinel Splunk
1 hour, 23 minutes ago

Detection and Response Engineer

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a Detection and Response Engineer to support client SIEM monitoring, threat hunting, and purple team activities within its Defensive Services team.

Ansible AWS Azure Cybersecurity GCP GitHub GitLab HIPAA SIEM Splunk Terraform
1 hour, 38 minutes ago

SOC Analyst

ClearCapital.com, 1-10 Real Estate

Clear Capital is hiring a SOC Analyst to protect its on-premises and cloud environments through security monitoring, incident response, threat hunting, and vulnerability advisory work.

Active Directory DNS Linux macOS OAuth SAML SIEM
2 hours, 8 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers