Senior Corporate Security Investigator & Detection Lead

actblue

United States

Remote

USD 174,000 - 211,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible schedule
Unlimited time off
Health, dental, vision insurance
Disability insurance
Life insurance
401K with match
Home-office setup allowance
Remote‑friendly culture
Snack deliveries

Job summary

ActBlue is seeking a Senior Corporate Security Specialist II to safeguard our platform and data in a remote, salaried role. You will build and tune detections in our SIEM, lead sensitive matter reviews, and coordinate with the Security team and external vendors to drive risk‑based security improvements.

You will bring 5–7 years of security experience, hands‑on forensic expertise across endpoints, identity, email, cloud, and SaaS, and proficiency with Terraform and Python for logging and

Qualifications

  • 5 to 7 years of security experience, including hands‑on experience leading complex corporate‑security and workplace investigations
  • Hands‑on experience conducting forensic investigations across endpoint, identity, email, cloud, and SaaS data sources
  • Practical fluency with detection engineering as code, including authoring, testing, and tuning detections in a version‑controlled pipeline
  • Working experience with forensically sound evidence collection and preservation — including chain‑of‑custody discipline, hashing, custodian‑based collection, and eDiscovery / legal‑hold workflows
  • Sound judgment about what evidence to collect, how to preserve it, and what to share with whom
  • A track record of producing review findings and recommendations that have held up to scrutiny
  • Comfort working with internal or external counsel, and directing forensic vendors on assigned engagements
  • Understanding of the legal context in which corporate‑security matters arise, including the limits and obligations that apply to management‑side reviews
  • Strong written and verbal communication, including the ability to explain technical findings to non‑technical audiences
  • Experience working alongside a managed SOC or MSSP, including escalation management
  • Experience with infrastructure‑as‑code workflows in Terraform and Python for logging, alerting, and security automation
  • Experience securing Google Workspace, Okta, GitHub, and Atlassian environments
  • Experience supporting PCI evidence collection and response

Responsibilities

  • Author, tune, and maintain detections as code in our SIEM/SOAR pipeline — version‑controlled, peer‑reviewed, tested, and deployed through the detection pipeline
  • Identify detection and tooling gaps and propose architecture improvements
  • Serve on the on‑call rotation and coordinate day‑to‑day escalations with our third‑party managed SOC, maintaining the detection feedback loop
  • Operate email security, endpoint security, and DLP controls; investigate and resolve high‑sensitivity signals and tune controls based on what investigations surface
  • Run tabletop exercises, deliver workforce security training, and produce threat intelligence that shapes team priorities
  • Restrict, suspend, or revoke an employee's system access when a review identifies active risk, pending completion of that review
  • Define security requirements and detection coverage for identity and audit collection across corporate systems
  • Conduct investigations and sensitive matter reviews with forensically sound evidence handling, chain‑of‑custody discipline, and confidentiality by default
  • Lead complex reviews independently — employee conduct, insider risk, access misuse, data exfiltration — co‑leading or escalating the most sensitive matters
  • Conduct forensic analysis across endpoint, identity, email, cloud, and SaaS sources
  • Produce findings, evidence summaries, technical analyses, and timelines for key stakeholders
  • Preserve evidence for legal holds and formal proceedings
  • Interpret findings in context and recommend resolutions, rather than providing raw technical output alone
  • Apply and improve Corporate Security methodology, evidence standards, and reporting standards
  • Manage the SOC relationship and coordinate forensic vendors and external specialists, treating both as extensions of the team's capacity
  • Exercise independent judgment over review methodology and evidence handling within established standards
  • Maintain the chain‑of‑custody, evidence‑handling, and confidentiality controls used by Corporate Security

Skills

Investigation leadership
Forensic investigations
Detections as code
Endpoint security
Identity/audit data
SOC/MSSP coordination
Terraform & Python
Google Workspace Okta GitHub
Legal holds workflows
Confidentiality & discretion

Tools

Terraform
Python
Google Workspace
Okta
GitHub
Atlassian

Job description

ActBlue is seeking a Senior Corporate Security Specialist II to safeguard our platform and data in a remote, salaried role. You will build and tune detections in our SIEM, lead sensitive matter reviews, and coordinate with the Security team and external vendors to drive risk‑based security improvements.

You will bring 5–7 years of security experience, hands‑on forensic expertise across endpoints, identity, email, cloud, and SaaS, and proficiency with Terraform and Python for logging and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Corporate Security Lead & Incident Investigator
Senior Corporate Security Lead & Incident Investigator

Actblue • Somerville (MA)

On-site
USD 120,000 - 170,000
Senior Corporate Security Specialist
Senior Corporate Security Specialist

Actblue • Somerville (MA)

On-site
USD 120,000 - 170,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

Attentive • Wilmington (DE)

On-site
USD 140,000 - 207,000
Health & wellness
Equity
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

United States Digital Space LLC • United States

On-site
USD 140,000 - 207,000
Equity
Health & wellness
Senior SIEM & Incident Response Specialist
Senior SIEM & Incident Response Specialist

Trustwave • United States

Hybrid
USD 90,000 - 140,000
Medical, dental, and vision insurance
401(k) with employer matching
Paid time off
+4
Senior Corporate Security Engineer - Remote
Senior Corporate Security Engineer - Remote

Atlan Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Competitive compensation
AI native culture
Health & wellness benefits
+3
Senior Security Engineer: SIEM & Incident Lead (Equity)
Senior Security Engineer: SIEM & Incident Lead (Equity)

K2 Space Corporation • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Medical/dental/vision
Paid time off
Equity
Senior Security Analyst & Incident Commander
Senior Security Analyst & Incident Commander

23andMe, Inc. • Palo Alto (CA)

On-site
USD 110,000 - 140,000
On-call bonus
Senior Threat Detection Lead - SOAR & SIEM Expert
Senior Threat Detection Lead - SOAR & SIEM Expert

ADP • Roseland (NJ)

On-site
USD 150,000 - 210,000
Senior Security Operations: Detection & Response (Remote)
Senior Security Operations: Detection & Response (Remote)

Point • San Francisco (CA)

On-site
USD 151,000 - 167,000
Health benefits
Unlimited PTO
Remote & onsite options
+3