← Back to jobs
Airbnb
Airbnb

Lead Insider Threat Investigator

otherfull-timeSydney, Australia
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

The Difference You Will Make:

The Insider Threat Lead Investigator is responsible for conducting high-risk, complex insider threat investigations involving cybersecurity, financial misconduct, intellectual property theft, unauthorized access, and data exfiltration. This role focuses on investigating identified threats produced by the Information Security Engineering team or from other internal reporting.

The investigator will conduct technical investigations, guide OSINT research, perform subject interviews, evidence collection, data deletion, and asset retrieval, while ensuring adherence to employment law, corporate policies, and regulatory requirements. This role requires deep technical expertise in digital forensics, cloud security, log analysis, and enterprise forensic tools while maintaining strong legal acumen to manage sensitive cases involving corporate risk, HR, and compliance considerations.

A Typical Day:

1. Technical Investigations

  • Utilize a functional understanding of information security principles, practices, and frameworks.
  • Investigate identified insider threat cases escalated from the Information Security Engineering team, including:
    • Financial misconduct
    • Engineering production abuse (e.g., code manipulation, unauthorized system modifications, data sabotage)
    • Intellectual property theft & unauthorized data exfiltration
    • Legal escalations involving executive personnel
  • Conduct structured investigative interviews with subjects and relevant stakeholders to validate findings and gather additional intelligence.
  • Manage incident response in coordination with Information Security, HR, Legal, and other relevant parties.
  • Perform custom high-severity data deletions and secure asset retrieval in compliance with legal, regulatory, and corporate policies.

2. Digital Forensics & Technical Analysis

  • Collaborate with security engineering teams for the forensic collection of digital evidence from endpoints (Windows, macOS, Chrome OS), cloud storage, and mobile devices (iOS, Android).
  • Perform log analysis and coordinate/perform event queries across enterprise systems, synthesizing the digital behaviour to correlate human events and factors to form and complete investigative strategies, including:
    • Windows Event Viewer, MacOS Console, Chrome OS logs
    • Cloud platform logs (AWS, Azure, GCP)
    • Enterprise applications and security logs
  • Maintain an understanding of technical evidence, forensic artifacts, and the digital environments in which insider threat activities occur.

3. Legal Acumen, Compliance, and Executive Reporting

  • Ensure investigations adhere to employment law, corporate policies, data privacy regulations, and commercial legal frameworks.
  • Collaborate with Legal, HR, Privacy, and Compliance teams to assess corporate risk, legal exposure, and remediation strategies.
  • Provide clear, structured briefings on high-profile cases to executive leadership and cross-functional security teams.
  • Lead post-mortem reviews to refine investigative methodologies and improve detection capabilities.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $14.99/mo. Cancel anytime.
Join waitlist
Apply now
Lead Insider Threat Investigator at Airbnb — Remote