Staff Insider Risk Engineer

United States Digital Space LLC

United States

Hybrid

USD 184,000 - 220,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401(k) retirement plan
Flexible spending & health savings

Job summary

BILL is seeking a Staff Insider Risk Engineer to join the Security Operations Center. The role supports insider risk detection, digital forensics, and cross‑functional collaboration with People, Legal, and Safety teams to identify, investigate, and remediate insider threats.

You will leverage investigative tradecraft, behavioral analysis, and AI‑assisted workflows to assess risk and drive informed security decisions, while refining detection logic and alert fidelity for scalable protection.

Qualifications

  • 7+ years of experience in insider risk, security operations, investigations, digital forensics, incident response, compliance, data protection, or enterprise risk management.
  • 2+ years of experience managing an insider risk program or conducting insider risk investigations.
  • Experience with forensic tools and endpoint data loss prevention platforms.
  • Experience with macOS, Windows, and cloud/container‑based forensic analysis.
  • Familiarity with cloud platforms (e.g. AWS) and collaboration platforms (e.g., Google Workspace) and the ability to extract and interpret log data to support investigations.
  • Hands‑on experience with security tools such as SIEM, UEBA, EDR, and email security solutions.
  • Excellent written and oral communication skills, with the ability to produce clear, factual, and defensible investigation documentation for stakeholders.
  • Sound judgment and discretion when handling sensitive, confidential, or privileged information.
  • Ability to work in high‑pressure and time‑sensitive situations while maintaining accuracy and objectivity.
  • Meticulous attention to detail and quality of work product.
  • Utilize AI to accelerate investigations and automate repetitive tasks.

Responsibilities

  • Conduct investigations into suspected insider threats, including data exfiltration, policy violations, and risky behavior.
  • Triage and validate alerts from the insider risk management program, determining severity and appropriate escalation path in line with the tiered risk framework.
  • Partner with the HR, Legal, and Privacy on remediation of confirmed insider incidents, including participation in employee interviews and documentation of findings.
  • Maintain chain‑of‑custody documentation and adhere to established digital forensics standards to preserve evidentiary integrity for all investigations.
  • Author clear, defensible investigation reports and file timelines that support HR and Legal decision‑making on disciplinary or remediation actions.
  • Contribute to and continuously improve insider risk playbooks and working groups.
  • Support the design and tuning of detection use cases and monitoring baselines to improve identification of anomalous insider behavior.
  • Track metrics for leadership, with the intention of highlighting trends and improvement opportunities.
  • Support security operations efforts as capacity allows, given the close working relationship between insider risk and the broader security operations functions.

Skills

Insider risk
Security operations
Digital forensics
Incident response
Data protection
Enterprise risk management
Compliance

Tools

SIEM
UEBA
EDR
Cloud analytics
Forensic tools

Job description

Innovate with purpose

At BILL, we believe in empowering the businesses that drive our economy. By replacing outdated financial processes with innovative tools, we help businesses—from startups to established brands—make smarter decisions and gain control of their operations. And we don’t stop there: we’re creating the future of financial automation so businesses can spend more time on what matters.

Working here means you become part of a vision-driven team that’s ready to tackle challenges and build cutting‑edge solutions. We value purpose, drive, and curiosity—and we thrive in a fast‑paced, ever‑changing environment. Whether in one of our offices in San Jose, CA, Draper, UT, or in a remote‑eligible role, BILLders collaborate to deliver real impact for businesses that need more time in their busy weeks.

BILL builds high performing teams and we seek to hire the best talent for every role. We're committed to building a workplace that fosters inclusion and diverse perspectives, valuing each person’s unique skills and experiences. We’d love to hear from you—you might be just what we’re looking for, whether in this role or another.

Let’s give businesses more time for what matters.

Make your impact within a rapidly growing Fintech Company

BILL is looking to hire a Staff Insider Risk Engineer to join the Security Operations Center to support the insider risk and digital forensics functions. Protecting the company's data, systems, and employees is mission‑critical to maintaining the trust of our customers and partners.

The Insider Risk role sits at the intersection of security operations, digital forensics, and cross‑functional partnership with People, Legal, and Safety and Security teams, directly shaping how BILL identifies, investigates, and remediates insider threats. You’ll combine investigative tradecraft, behavioral analysis, technical telemetry, and AI‑assisted workflows to rapidly assess risk and drive informed security decisions.

Detection Engineering & Alert Fidelity Optimization:

Design, build, and continuously refine insider threat detection logic, use cases, and analytics to improve signal quality. Leverage AI to accelerate investigations, validate findings, and improve decision‑making. Identify opportunities to automate repetitive work and improve investigative workflows.

Alert Triage and Investigation:

Triage and investigate insider threat alerts, applying structured methodologies to assess risk and using forensics to complete thorough analyses. Translate investigation outcomes into control improvements.

Detection Strategy & Use Case Development:

Develop and implement a scalable detection strategy aligned to key insider threat risks (i.e., data exfiltration, employee exit risk, misuse). Identify gaps and prioritize new detection use cases to expand coverage and effectiveness

Cross-Functional Partnership:

Partner with InfoSec, IT, Legal, and HR teams to ensure detections are risk‑aligned, context‑aware, and operationally actionable. Incorporate business context and investigation requirements into detection design to improve alert fidelity and response effectiveness.

Security Operations Collaboration:

Provide support during high‑risk security incidents where forensics and related skills are required.

Responsibilities
  • Conduct investigations into suspected insider threats, including data exfiltration, policy violations, and risky behavior
  • Triage and validate alerts from the insider risk management program, determining severity and appropriate escalation path in line with the tiered risk framework
  • Partner with the HR, Legal, and Privacy on remediation of confirmed insider incidents, including participation in employee interviews and documentation of findings
  • Maintain chain‑of‑custody documentation and adhere to established digital forensics standards to preserve evidentiary integrity for all investigations
  • Author clear, defensible investigation reports and file timelines that support HR and Legal decision‑making on disciplinary or remediation actions
  • Contribute to and continuously improve insider risk playbooks and working groups
  • Support the design and tuning of detection use cases and monitoring baselines to improve identification of anomalous insider behavior
  • Track metrics for leadership, with the intention of highlighting trends and improvement opportunities
  • Support security operations efforts as capacity allows, given the close working relationship between insider risk and the broader security operations functions
We’d love to chat if you have:
  • 7+ years of experience in insider risk, security operations, investigations, digital forensics, incident response, compliance, data protection, or enterprise risk management
  • 2+ years of experience managing an insider risk program or conducting insider risk investigations
  • Experience with forensic tools and endpoint data loss prevention platforms
  • Experience with macOS, Windows, and cloud/container‑based forensic analysis
  • Familiarity with cloud platforms (e.g. AWS) and collaboration platforms (e.g., Google Workspace) and the ability to extract and interpret log data to support investigations
  • Hands‑on experience with security tools such as SIEM, UEBA, EDR, and email security solutions
  • Excellent written and oral communication skills, with the ability to produce clear, factual, and defensible investigation documentation for stakeholders
  • Sound judgment and discretion when handling sensitive, confidential, or privileged information
  • Ability to work in high‑pressure and time‑sensitive situations while maintaining accuracy and objectivity
  • Meticulous attention to detail and quality of work product
  • Utilize AI to accelerate investigations and automate repetitive tasks
Visa Sponsorship:

Please note that this position is not eligible for visa sponsorship. Applicants must have authorization to work in the United States without requiring visa sponsorship now or in the future.

Our ranges for each role and job level are based on a variety of factors including candidate experience, expertise, and geographic location and may vary from the amounts listed below. The role is also eligible for a competitive benefits package that includes: medical, dental, vision, life and disability insurance, 401(k) retirement plan, flexible spending & health savings account, paid holidays, paid time off, and other company benefits. The estimated salary ranges noted below roles in the specific geographic zones

Zone 1: San Francisco Bay Area CA (includes HQ), New York City, Seattle, Los Angeles County

$183,500—$220,000 USD

Zone 2: CA (Non San Francisco Bay Area and Los Angeles County), Austin TX, Massachusetts

$165,200—$198,000 USD

Zone 3: Utah (includes Utah office), Dallas TX, Houston TX, Florida, North Carolina, Illinois, Colorado, Arizona, Georgia, Oregon, Pennsylvania

$156,000—$187,000 USD

What’s in
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Insider Risk Engineer
Staff Insider Risk Engineer

BILL • United States

Hybrid
USD 183,500 - 220,000
100% paid health, dental, vision plans
HSA & FSA accounts
Life Insurance & Disability coverage
+2
Staff Insider Risk Engineer
Staff Insider Risk Engineer

BILL • California (MO)

Hybrid
USD 183,000 - 220,000
Medical, dental, vision insurance
401(k) with company match
HSA & FSA accounts
+3
Risk Data Analyst, Staff
Risk Data Analyst, Staff

BILL • United States

On-site
USD 143,000 - 191,000
Senior Staff Software Engineer - Payments Risk
Senior Staff Software Engineer - Payments Risk

BILL • California (MO)

On-site
USD 186,000 - 259,000
Health insurance
HSA and FSA accounts
Life insurance
+2
Risk Data Analyst, Staff
Risk Data Analyst, Staff

BILL • California (MO)

Hybrid
USD 159,000 - 191,000
Health, dental, & vision insurance
HSA/FSA accounts
Life insurance
+5
Director Risk Portfolio Management
Director Risk Portfolio Management

BILL • California (MO)

Hybrid
USD 190,000 - 239,000
Employee Stock Purchase Program
100% paid health, dental, and vision plans
Flexible time off
+1
Senior Manager, Fraud Strategy Data Scientist
Senior Manager, Fraud Strategy Data Scientist

BILL • United States

Hybrid
USD 190,400 - 238,050
Health, dental, vision coverage
HSA & FSA accounts
Life Insurance & disability coverage
+3
Fraud Strategy Data Scientist
Fraud Strategy Data Scientist

BILL • San Jose (CA)

Hybrid
USD 113,000 - 135,000
Health insurance
401(k) retirement plan
Paid holidays
+3
Insider Threat Engineer
Insider Threat Engineer

Webhosting • Austin (TX)

On-site
USD 150,000 - 230,000
Senior Underwriter Analyst
Senior Underwriter Analyst

United States Digital Space LLC • United States

Hybrid
USD 77,000 - 92,000
Health, dental, vision
HSA/FSA
Life Insurance
+6