Lead Insider Trust & Fraud Investigator

1 hour, 55 minutes ago
Full-time
Lead
Cybersecurity
SoFi

SoFi

SoFi specializes in providing a comprehensive financial platform that empowers individuals to achieve their financial goals through services such as student loan refinancing, debt consolidation, home buying assistance, and investment opportunities, all...

Capital Markets
1K-5K
Founded 2011
$2900M raised

Description

  • Conduct end-to-end investigations into suspected insider risk activity, including data exfiltration, policy violations, fraud, IP theft, sabotage, and misuse of company resources.
  • Review and analyze telemetry from endpoint, identity and authentication, SaaS, application, and network logs.
  • Correlate events across multiple log sources to build defensible investigative timelines and attribution assessments.
  • Partner with stakeholders to deploy detections and improve internal controls, policies, and procedures to prevent malicious activity.
  • Exercise sound judgment when handling high-priority, high-risk, and sensitive cases.
  • Coordinate with external parties such as law enforcement, legal counsel, and regulatory bodies when needed.
  • Proactively engage internal and external stakeholders on priority, high-impact, and emerging typologies.
  • Deliver clear, concise, and objective briefings to technical and non-technical stakeholders.
  • Maintain case management records with complete documentation, evidence preservation, and chain of custody integrity.
  • Contribute to the development of playbooks, standards, and procedures.

Requirements

  • 8+ years of experience in an investigative role such as Insider Threat, Security Operations, Digital Forensics, Insider Response, or Corporate Investigations.
  • Experience reviewing and correlating endpoint, application, network, and other logs.
  • Familiarity with security tools such as SIEM, UEBA, DLP, and EDR.
  • Ability to interpret evidence and reconstruct events.
  • Familiarity with criminal law, rules, legislation, and internal policies.
  • Familiarity with evidence types and the rules governing admissibility.
  • Excellent written and verbal communication skills.
  • Understanding of insider risk typologies.
  • Experience working cross-functionally with HR, Legal, and executive stakeholders is preferred.
  • Experience or interest in cryptocurrency is a plus.

Benefits

  • Base pay range is provided for the role, with final offer determined by experience, skills, and location.
  • Comprehensive and competitive benefits package is available through SoFi Benefits.
  • Reasonable accommodations are available for candidates with physical or mental disabilities during the application and interview process.
  • Equal employment opportunity for all employees and applicants.
  • Consideration for qualified applicants with arrest and conviction records under the San Francisco Fair Chance Ordinance.
  • Remote work is not available from Hawaii or Alaska due to insurance coverage issues.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Data Protection Operations Lead

Airbnb 5K-10K Hotels, Restaurants & Leisure

Airbnb is hiring a Canada-remote Risk and Compliance Operations professional to shape privileged access management governance, controls, and reporting for Community Support and related teams.

Active Directory AWS Azure GCP OAuth OpenID Connect SAML SQL
3 hours, 40 minutes ago

Cyber Security Analyst

Centorrino Technologies 51-250 Internet Software & Services

Centorrino Technologies is seeking a Cyber Analyst in Melbourne and/or Perth to monitor and strengthen customer security operations and incident response, with NV1 security clearance required.

SIEM
23 hours, 25 minutes ago

Senior Data Protection Analyst (DLP)

One Park Financial 51-250 Diversified Financial Services

One Park Financial is hiring a Senior Data Protection Analyst in Miami to lead data egress and collaboration security efforts that protect sensitive customer and company information across communications and identity systems.

Python
1 day, 7 hours ago

Incident Response Analyst III

ZoomInfo 1K-5K Professional Services

ZoomInfo is hiring a Security Incident Response Analyst to join its US-remote Threat Detection and Response team, where the role focuses on protecting the company’s people, products, and data by detecting, investigating, and responding to security threats.

Cybersecurity SIEM
1 day, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers