Skip to main content
BILL

Staff Insider Risk Engineer

RemoteUnited States only
Published
Role
Fullstack
Experience
Senior
$183.5k–$220k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

BILL is seeking a Staff Insider Risk Engineer to join the Security Operations Center, supporting insider risk and digital forensics functions to protect the company's data, systems, and employees.

Core skills

Insider RiskSecurity OperationsDigital Forensics

Required skills

InvestigationsIncident ResponseComplianceData ProtectionEnterprise Risk ManagementmacOSWindowsCloud Forensic AnalysisContainer Forensic AnalysisAWSGoogle WorkspaceSIEMUEBAEDREmail Security SolutionsData Loss Prevention PlatformsAI-assisted workflowsChain-of-custody documentationInvestigation reportsPlaybooksThreat detection logicMetricsTriageEscalationstakeholder communication

What you'll do

  • Conduct investigations into suspected insider threats, including data exfiltration, policy violations, and risky behavior
  • Triage and validate alerts from the insider risk management program, determining severity and appropriate escalation path in line with the tiered risk framework
  • Partner with the HR, Legal, and Privacy on remediation of confirmed insider incidents, including participation in employee interviews and documentation of findings
  • Maintain chain-of-custody documentation and adhere to established digital forensics standards to preserve evidentiary integrity for all investigations
  • Author clear, defensible investigation reports and file timelines that support HR and Legal decision-making on disciplinary or remediation actions
  • Contribute to and continuously improve insider risk playbooks and working groups
  • Support the design and tuning of detection use cases and monitoring baselines to improve identification of anomalous insider behavior
  • Track metrics for leadership, with the intention of highlighting trends and improvement opportunities
  • Support security operations efforts as capacity allows, given the close working relationship between insider risk and the broader security operations functions
  • Design, build, and continuously refine insider threat detection logic, use cases, and analytics to improve signal quality
  • Leverage AI to accelerate investigations, validate findings, and improve decision-making
  • Identify opportunities to automate repetitive work and improve investigative workflows
  • Triage and investigate insider threat alerts using structured methodologies and forensic techniques
  • Translate investigation outcomes into control improvements
  • Develop and implement a scalable detection strategy aligned to key insider threat risks (e.g., data exfiltration, employee exit, misuse)
  • Identify gaps and prioritize new detection use cases to expand coverage and effectiveness
  • Partner with InfoSec, IT, Legal, and HR teams to ensure detections are risk-aligned, context-aware, and operationally actionable
  • Incorporate business context and investigation requirements into detection design to improve alert fidelity and response effectiveness
  • Provide support during high-risk security incidents where forensics and related skills are required

What they require

  • 7+ years of experience in insider risk, security operations, investigations, digital forensics, incident response, compliance, data protection, or enterprise risk management
  • 2+ years of experience managing an insider risk program or conducting insider risk investigations
  • Experience with forensic tools and endpoint data loss prevention platforms
  • Experience with macOS, Windows, and cloud/container-based forensic analysis
  • Familiarity with cloud platforms (e.g., AWS) and collaboration platforms (e.g., Google Workspace) and the ability to extract and interpret log data to support investigations
  • Hands-on experience with security tools such as SIEM, UEBA, EDR, and email security solutions
  • Excellent written and oral communication skills, with the ability to produce clear, factual, and defensible investigation documentation for stakeholders
  • Sound judgement and discretion when handling sensitive, confidential, or privileged information
  • Ability to work in high-pressure and time-sensitive situations while maintaining accuracy and objectivity
  • Meticulous attention to detail and quality of work product
  • Utilize AI to accelerate investigations and automate repetitive tasks
  • Authorization to work in the United States without requiring visa or sponsorship

Benefits

  • 100% paid employee health, dental, and vision plans (choose HMO, PPO, or HDHP)
  • HSA & FSA accounts
  • Life Insurance, Long & Short-term disability coverage
  • Employee Assistance Program (EAP)
  • 11+ Observed holidays and wellness days and flexible time off
  • Employee Stock Purchase Program with employee discounts
  • Wellness & Fitness initiatives
  • Employee recognition and referral programs
  • Flexible spending & health savings account
  • Paid holidays
  • Paid time off

BILL replaces outdated financial processes with financial automation tools to help businesses make smarter decisions and gain control of their operations.

FintechEnterprise

Details

Visa sponsorshipNo
$183.5k–$220k/yr