Incident Response Manager - Abuse Operations

United States Digital Space LLC

Dublin

On-site

EUR 110,000 - 130,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking a Senior Incident Response Manager to lead fraud and abuse incident response across our financial infrastructure platform. You will act as incident commander, coordinating cross-functional workstreams with security, data science, legal, and policy teams, while driving proactive improvements and automation of response workflows.

This role requires 10+ years of experience in security or fraud incident response, deep Python/SQL expertise, and a track

Qualifications

  • 10+ years leading security or fraud incident response.
  • BS/MS in Computer Science or equivalent experience.
  • Expert knowledge of Python and SQL; familiarity with other languages.

Responsibilities

  • Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM).
  • Investigate high-risk activity and accounts; coordinate workstreams.
  • Develop incident response strategies and playbooks.
  • Partner with security, data science, legal, and policy teams.
  • Mentor teammates and drive cross-functional alignment.

Skills

Python
SQL
Communication
Incident response leadership
Threat intelligence

Education

BS/MS Computer Science

Tools

Databricks
Trino
PySpark
Pandas
Sci-kit Learn

Job description

Who we are About the company

the company is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use the company to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting the company and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What you’ll do

In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across the company by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed and precision while continuously elevating the company's fraud and abuse incident response function.

Responsibilities
  • Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
  • As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
  • Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
  • Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
  • Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.
Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements
  • 10+ years of experience leading security or fraud incident response;
  • B.S./M.S. in Computer Science or equivalent experience.
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
  • Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
Preferred qualifications
  • Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Abuse Investigator
Abuse Investigator

United States Digital Space LLC • Dublin

On-site
EUR 65,000 - 90,000
Security Incident Response Manager - Abuse Operations
Security Incident Response Manager - Abuse Operations

Stripe • Dublin

On-site
EUR 120,000 - 180,000
Abuse Investigator
Abuse Investigator

Stripe • Dublin

On-site
EUR 90,000 - 130,000
Abuse Investigator
Abuse Investigator

Jackalope Digital LLC • Dublin

Hybrid
EUR 90,000 - 130,000
Incident Response Manager - Abuse Operations
Incident Response Manager - Abuse Operations

Stripe • Dublin

On-site
EUR 150,000 - 190,000
S Security Incident Response Manager - Abuse Operations Stripe via Greenhouse Dublin 8611 security analytics View role
S Security Incident Response Manager - Abuse Operations Stripe via Greenhouse Dublin 8611 security analytics View role

Nubeero Limited • Dublin

On-site
EUR 120,000 - 160,000
S Abuse Investigator Stripe via Greenhouse Dublin 8611 security analytics View role
S Abuse Investigator Stripe via Greenhouse Dublin 8611 security analytics View role

Nubeero Limited • Dublin

On-site
EUR 90,000 - 120,000
Senior Fraud & Abuse Incident Leader (IRM)
Senior Fraud & Abuse Incident Leader (IRM)

Nubeero Limited • Dublin

On-site
EUR 120,000 - 160,000
Fraud & Abuse Incident Response Lead
Fraud & Abuse Incident Response Lead

United States Digital Space LLC • Dublin

On-site
EUR 110,000 - 130,000
Fraud Risk Analyst x2
Fraud Risk Analyst x2

Northern Trust Corp • Limerick

On-site
EUR 50,000 - 70,000