Insider Threat And Cyber Investigations Lead

Airbnb Logo

Airbnb

πŸ’΅ $154k-$192k
πŸ“Remote - United States

Summary

Join Airbnb as their Insider Threat & Cyber Investigations Lead and conduct high-risk, complex investigations into insider threats. You will investigate cybersecurity incidents, financial misconduct, and intellectual property theft. This role requires deep technical expertise in digital forensics, cloud security, and log analysis. You will collaborate with various teams, including Legal, HR, and Compliance. The position is remote-eligible within the US, with occasional office work possible. A competitive salary and benefits package is offered.

Requirements

  • 10-12 years of experience in insider threat investigations, security, digital forensics, or related industries
  • Proven experience conducting high-risk, legally sensitive investigations involving corporate executives and critical business functions
  • Strong expertise in Windows, MacOS, and Chrome OS forensic tools
  • Experience in SQL-based forensic data correlation and behavioral anomaly analysis
  • Strong employment legal and commercial legal acumen, with experience handling workplace investigations and regulatory compliance
  • Expertise in digital forensic tools
  • Advanced knowledge of Windows Event Viewer, MacOS Console, Chrome OS system logs for forensic evidence retrieval
  • Strong expertise and skills in investigating cloud environments and Kubernetes
  • Experience with high-severity data deletion and asset retrieval in corporate environments
  • Ability to conduct investigative interviews and communicate findings clearly and effectively to legal, HR, and security teams

Responsibilities

  • Investigate identified insider threat cases escalated from the Information Security Engineering team, including: Financial misconduct, Engineering production abuse (e.g., code manipulation, unauthorized system modifications, data sabotage), Intellectual property theft & unauthorized data exfiltration, Legal escalations involving executive personnel
  • Conduct structured investigative interviews with subjects and relevant stakeholders to validate findings and gather additional intelligence
  • Collaborate/coordinate with engineering teams for the forensic collection of digital evidence from endpoints (Windows, macOS, Chrome OS), cloud storage, and mobile devices (iOS, Android)
  • Perform custom high-severity data deletions and secure asset retrieval in compliance with legal, regulatory, and corporate policies
  • Perform log analysis and coordinate/perform event queries across enterprise systems, including: Windows Event Viewer, MacOS Console, Chrome OS logs, Cloud platform logs (AWS, Azure, GCP), Enterprise applications and security logs
  • Analyze structured and unstructured data to correlate insider threat behaviors and support investigation findings
  • Utilize and collaborate with Information Security on queries (SQL, Security logs) to extract forensic evidence from company databases, endpoints, and cloud storage systems
  • Maintain a deep understanding of technical evidence, forensic artifacts, and the digital environments in which insider threat activities occur
  • Ensure investigations adhere to employment law, corporate policies, data privacy regulations, and commercial legal frameworks
  • Collaborate with Legal, HR, Privacy, and Compliance teams to assess corporate risk, legal exposure, and remediation strategies
  • Provide clear, structured briefings on high-profile cases to executive leadership and cross-functional security teams
  • Lead post-mortem reviews to refine investigative methodologies and implement lessons learned

Preferred Qualifications

  • Sans GIAC, GCFA, or GCFE (Advanced Digital Forensics)
  • CISSP
  • AWS/Google/Azure Security certifications
  • CompTIA Cloud+ Kubernetes Security or Fundamentals

Benefits

  • Bonus
  • Equity
  • Benefits
  • Employee Travel Credits

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs