Insider Risk Investigator - USDS

TikTok

Washington (District of Columbia)

Hybrid

USD 88,920 - 176,400

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401(k) with company match
Paid parental leave
Medical, dental, and vision benefits

Job summary

A leading technology company in Washington, DC is seeking an experienced Insider Risk Investigator to enhance organizational security by investigating potential insider threats. The candidate should possess a Bachelor's degree in a relevant field and over 5 years of cybersecurity investigation experience. This hybrid position requires working in-office three days a week, offering a competitive salary range of $88,920 to $176,400 annually along with comprehensive benefits.

Qualifications

  • 5+ years of experience in cybersecurity incident investigations focused on insider risk.
  • Proficient in scripting languages such as Python, Bash, or PowerShell.
  • Strong knowledge of operating systems including Windows, macOS, and Linux.

Responsibilities

  • Conduct investigations into suspected insider threats.
  • Utilize digital forensic techniques to collect evidence.
  • Generate detailed reports documenting investigative findings.

Skills

Technical investigation skills
Digital forensic expertise
Knowledge of cybersecurity tools

Education

Bachelor's degree in relevant field

Tools

EnCase
FTK
Cellebrite
X-Ways
Splunk

Job description

Overview

We are looking for an experienced Insider Risk Investigator with advanced expertise in Digital Forensics and Incident Response (DFIR). In this role, you will be responsible for identifying potential insider threats across the organization, conducting thorough investigations into unauthorized access or misuse of company assets and data, applying forensic methodologies to analyze incidents, and strengthening organizational security. The organization follows a hybrid work schedule that requires employees to work in the office 3 days a week, or as directed by their manager/department. This model is regularly reviewed and specific requirements may change.

Responsibilities
  • Conduct investigations into suspected insider threats including cases involving intellectual property theft, unauthorized access/use of sensitive systems or data, fraud/embezzlement activities, or violations of internal policies.
  • Utilize advanced digital forensic techniques to collect evidence from endpoints (Windows/macOS/Linux), mobile devices (iOS/Android), network logs, cloud-based services (AWS/Azure/GCP), file shares/repositories (e.g., SharePoint), databases, and other relevant sources.
  • Analyze system artifacts such as registry files, event logs, browser histories/cache data/memory dumps/timelines to accurately contextualize insider actions.
  • Use endpoint detection tools (EDR) or SIEM platforms to identify behavioral anomalies that may indicate malicious intent or policy violations.
  • Develop workflows for identifying high-risk behaviors such as exfiltration attempts via email/cloud storage/USB devices or lateral movement within internal networks.
  • Collaborate with cross-functional stakeholders including Legal teams (for compliance/litigation support), HR/Ethics teams on employee-related investigations, IT/Security teams on mitigation measures or technical controls post-investigation findings.
  • Generate detailed reports summarizing investigative findings with defensible documentation while maintaining chain-of-custody principles for potential legal proceedings.
  • Provide recommendations for improving proactive monitoring mechanisms/tools for early detection of insider risks across physical/digital environments.
  • Stay current on emerging threats related to insider risk programs as well as best practices in forensic analysis and security incident handling frameworks.
Qualifications

Minimum Qualifications

  • Bachelor's degree in Cybersecurity/Digital Forensics/Information Technology/Computer Science or equivalent professional experience in related fields.
  • 5+ years of experience conducting technical investigations into cybersecurity incidents with a strong emphasis on insider risk management cases.
  • Expertise in digital forensic tools such as EnCase, FTK, Cellebrite, X-Ways, AXIOM; familiarity with scripting languages like Python/Bash/PowerShell preferred.
  • Advanced knowledge of Windows/macOS/Linux operating systems at a forensic level—including file systems (NTFS/APFS/HFS+), memory analysis techniques/artifacts extraction methods/log parsing capabilities.
  • Experience working with EDR solutions (e.g., CrowdStrike Falcon, Carbon Black) or SIEM platforms such as Splunk/QRadar/ArcSight for anomaly detection during investigations.
  • Familiarity with cloud service providers like AWS/Azure/GCP—specifically their logging capabilities (e.g., CloudTrail/Azure Monitor)—and cloud-native investigation techniques.

Preferred Qualifications

  • Certifications in Digital Forensics and Incident Response domains: GCFE, GCFA, CCE, EnCE, CISSP, OSCP preferred but not required depending upon experience level validation!
  • Practical hands-on training certifications like SANS FOR508/MITRE ATT&CK fundamentals mastery ideal complements too
  • Extended skill flexibility needs
About USDS

USDS is a security-first division focused on governance of data protection policies and content assurance protocols to keep U.S. user data safe. The teams within USDS span across Trust & Safety, Security & Privacy, Engineering, User & Product Ops, Corporate Functions and more.

Data Security Statement

This role requires the ability to work with and support systems designed to protect sensitive data and information. As such, this role will be subject to strict national security-related screening.

Reasonable Accommodation

USDS is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/USDS-RA

Job Information

Compensation details: Washington, DC base salary range 88,920 – 176,400 USD annually. Compensation may vary based on qualifications, skills, competencies and location. Base pay may be accompanied by bonuses/incentives and restricted stock units. Benefits vary by location and include medical/dental/vision, 401(k) with company match, paid parental leave, disability coverage, life insurance, wellbeing benefits, paid holidays, paid sick days, and paid personal time. The company reserves the right to modify benefits at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Forensics & Insider Risk Integrator - USDS
Forensics & Insider Risk Integrator - USDS

TikTok • New York (NY)

On-site
USD 118,000 - 270,000
Health insurance
401(k) with company match
Paid time off
Lead Cyber Security Operations Center (CSOC) Analyst - USDS
Lead Cyber Security Operations Center (CSOC) Analyst - USDS

TikTok • Washington

On-site
USD 150,000 - 180,000
Medical insurance
401(k) plan
Paid parental leave
+1
Compliance Analyst - USDS
Compliance Analyst - USDS

TikTok • Washington

On-site
USD 68,000 - 132,000
Medical, dental, and vision insurance
401(k) with company match
Paid parental leave
+5
Head of Insider Risk - USDS
Head of Insider Risk - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 206,000 - 397,000
Solutions Architect, Security - USDS
Solutions Architect, Security - USDS

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 199,800 - 441,600
Medical, dental, and vision insurance
401(k) savings plan with company match
Paid parental leave
+3
Security Engineer - Insider Threat
Security Engineer - Insider Threat

HR Tech Job • Atlanta (GA)

On-site
USD 152,000 - 228,000
Bonus eligibility
Stock grants
Security Engineer (Insider Risk)
Security Engineer (Insider Risk)

Dragonfli Group • Washington

Hybrid
USD 120,000 - 160,000
Insurance - health, dental, and vision
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Security Solutions Architect: Scalable, Compliant Security
Security Solutions Architect: Scalable, Compliant Security

TikTok USDS Joint Venture • San Jose (CA)

On-site
Staff Insider Risk Engineer
Staff Insider Risk Engineer

United States Digital Space LLC • United States

Hybrid
USD 184,000 - 220,000
Medical, dental, vision insurance
401(k) retirement plan
Flexible spending & health savings
Protective Intelligence Analyst - USDS
Protective Intelligence Analyst - USDS

TikTok • Washington

Hybrid
USD 75,000 - 100,000
Hybrid work model
Professional development opportunities