Airbnb Logo

Airbnb

Insider Threat & Cyber Investigations Lead

Job Posted 8 Days Ago Reposted 8 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
154K-192K Annually
Senior level
Remote
Hiring Remotely in United States
154K-192K Annually
Senior level
The role involves leading insider threat investigations, conducting technical analysis, ensuring legal compliance, and collaborating with various teams. Responsibilities include managing sensitive corporate cases, performing digital forensics, and executing preventative strategies.
The summary above was generated by AI

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way.

The Insider Threat & Cyber Investigations Lead is responsible for conducting high-risk, complex insider threat investigations involving cybersecurity, financial misconduct, intellectual property theft, unauthorized modifications, engineering production abuse, and data exfiltration. This role focuses on investigating identified threats produced by the Information Security Engineering team or from other internal reporting.

The investigator will conduct technical investigations, guide OSINT research, perform subject interviews, evidence collection, data deletion, and asset retrieval, while ensuring adherence to employment law, corporate policies, and regulatory requirements. This role requires deep technical expertise in digital forensics, cloud security, log analysis, and enterprise forensic tools while maintaining strong legal acumen to manage sensitive cases involving corporate risk, HR, and compliance considerations.

A Typical Day:1. Technical Investigations
  • Investigate identified insider threat cases escalated from the Information Security Engineering team, including:
    • Financial misconduct
    • Engineering production abuse (e.g., code manipulation, unauthorized system modifications, data sabotage)
    • Intellectual property theft & unauthorized data exfiltration
    • Legal escalations involving executive personnel
  • Conduct structured investigative interviews with subjects and relevant stakeholders to validate findings and gather additional intelligence.
  • Collaborate/coordinate with engineering teams for the forensic collection of digital evidence from endpoints (Windows, macOS, Chrome OS), cloud storage, and mobile devices (iOS, Android).
  • Perform custom high-severity data deletions and secure asset retrieval in compliance with legal, regulatory, and corporate policies.
2. Digital Forensics & Technical Analysis
  • Perform log analysis and coordinate/perform event queries across enterprise systems, including:
    • Windows Event Viewer, MacOS Console, Chrome OS logs
    • Cloud platform logs (AWS, Azure, GCP)
    • Enterprise applications and security logs
  • Analyze structured and unstructured data to correlate insider threat behaviors and support investigation findings.
  • Utilize and collaborate with Information Security on queries (SQL, Security logs) to extract forensic evidence from company databases, endpoints, and cloud storage systems.
  • Maintain a deep understanding of technical evidence, forensic artifacts, and the digital environments in which insider threat activities occur.
3. Legal Acumen, Compliance, and Executive Reporting
  • Ensure investigations adhere to employment law, corporate policies, data privacy regulations, and commercial legal frameworks.
  • Collaborate with Legal, HR, Privacy, and Compliance teams to assess corporate risk, legal exposure, and remediation strategies.
  • Provide clear, structured briefings on high-profile cases to executive leadership and cross-functional security teams.
  • Lead post-mortem reviews to refine investigative methodologies and implement lessons learned.
Your Expertise:
  • 10-12 years of experience in insider threat investigations, security, digital forensics, or related industries.
  • Proven experience conducting high-risk, legally sensitive investigations involving corporate executives and critical business functions.
  • Strong expertise in Windows, MacOS, and Chrome OS forensic tools.
  • Experience in SQL-based forensic data correlation and behavioral anomaly analysis.
  • Strong employment legal and commercial legal acumen, with experience handling workplace investigations and regulatory compliance.
Technical Proficiency:
  • Expertise in digital forensic tools.
  • Advanced knowledge of Windows Event Viewer, MacOS Console, Chrome OS system logs for forensic evidence retrieval.
  • Strong expertise and skills in investigating cloud environments and Kubernetes.
  • Experience with high-severity data deletion and asset retrieval in corporate environments.
  • Ability to conduct investigative interviews and communicate findings clearly and effectively to legal, HR, and security teams.
Preferred Certifications:
  • Sans GIAC, GCFA, or GCFE (Advanced Digital Forensics)
  • CISSP
  • AWS/Google/Azure Security certificaitions
  • CompTIA Cloud+Kubernetes Security or Fundamentals
Location: Remote- USA

This position is US - Remote Eligible. The role may include occasional work at an Airbnb office or attendance at offsites, as agreed to with your manager. While the position is Remote Eligible, you must live in a state where Airbnb, Inc. has a registered entity. Click here for the up-to-date list of excluded states. This list is continuously evolving, so please check back with us if the state you live in is on the exclusion list . If your position is employed by another Airbnb entity, your recruiter will inform you what states you are eligible to work from.

Our Commitment To Inclusion & Belonging:

Airbnb is committed to working with the broadest talent pool possible. We believe diverse ideas foster innovation and engagement, and allow us to attract creatively-led people, and to develop the best products, services and solutions. All qualified individuals are encouraged to apply.

We strive to also provide a disability inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation in order to submit an application, please contact us at: reasonableaccommodations@airbnb.com. Please include your full name, the role you’re applying for and the accommodation necessary to assist you with the recruiting process. 

We ask that you only reach out to us if you are a candidate whose disability prevents you from being able to complete our online application.

How We'll Take Care of You:

Our job titles may span more than one career level. The actual base pay is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role may also be eligible for bonus, equity, benefits, and Employee Travel Credits.  

Pay Range
$154,000$192,000 USD

Top Skills

AWS
Azure
Chrome Os
Digital Forensic Tools
GCP
Kubernetes
Macos Console
SQL
Windows Event Viewer

Airbnb Seattle, Washington, USA Office

720 Olive Way, Seattle, Washington, United States, 98101

Similar Jobs

3 Hours Ago
Remote
United States of America
123K-150K Annually
Mid level
123K-150K Annually
Mid level
Artificial Intelligence • Computer Vision • HR Tech • Machine Learning • Software
The Application Security Engineer will enhance security processes, conduct assessments, automate vulnerability detection, lead SDLC practices, and train on secure development practices.
Top Skills: Automation ToolsCi/Cd PipelineNist GuidelinesOwaspStatic And Dynamic Application Security Tools
3 Hours Ago
Remote
USA
254K-299K Annually
Mid level
254K-299K Annually
Mid level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Manage the information security program for Americas entities, improve security processes, and ensure compliance with regulations while collaborating with various teams.
Top Skills: LookerSnowflakeSQL
3 Hours Ago
Remote
2 Locations
110K-135K Annually
Mid level
110K-135K Annually
Mid level
Insurance • Legal Tech • Social Impact
The System Administrator manages IT systems at Atticus, focusing on GCP, Google Workspace, user permissions, cybersecurity, and device management, while providing end-user support.
Top Skills: GCPGoogle WorkspacemacOSMdmSalesforceTwilio

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account