Remote job
Insider Threat Investigator
Job details
About this role
Role overview
An embedded investigator position with a global risk consultancy, focused on uncovering and mitigating insider threats for a client in San Francisco. The role blends deep-dive investigation (roughly 70%) with project management for closing vulnerability gaps (roughly 30%), and supports a broader threat management program. It is a full-time remote role scheduled Monday through Friday, 9:00 a.m. to 5:00 p.m. Pacific Time, with up to 10% travel and occasional non-traditional hours for urgent cases.
Responsibilities
- Lead complex insider risk investigations spanning digital and human channels, coordinating cross-functional response as incident commander when needed. - Use open-source intelligence, social media platforms, law enforcement databases, and deep/dark web tools to identify and assess threats. - Produce concise, actionable threat analysis products for executives, security operations teams, and cross-functional partners. - Conduct sensitive interviews with victims, witnesses, and persons of interest, both virtually and in person. - Manage cases end-to-end in case management software, documenting evidence, status, and after-action findings. - Partner with Legal, Employee Relations, Talent, Cybersecurity, Technology, and business leaders, plus external law enforcement and intelligence vendors, to mitigate risk. - Refine insider risk policies, procedures, and documentation in alignment with data privacy and legal requirements.
Requirements
- Bachelor's degree in criminal justice, cybersecurity, intelligence studies, or a closely related field. - 8+ years of hands-on insider threat investigation experience in cybersecurity, law enforcement, counterintelligence, or comparable private-sector work. - 4+ years supporting insider risk mitigation and remediation, including coordinating projects to close identified vulnerabilities. - Demonstrated experience interviewing insider risk actors, witnesses, and impacted individuals. - Strong command of corporate investigation standards, employment law considerations, and confidentiality practices. - Ability to independently manage sensitive cases, interpret evidence, and communicate findings to corporate stakeholders. - Willingness to work non-traditional hours and respond to emergent or time-sensitive situations. - Excellent written and oral communication skills, with strong cross-functional collaboration and adaptability.
Nice to have
- ASIS Professional Certified Investigator (PCI) credential. - CERT Insider Threat Program Manager (ITPM) certificate. - Background in data analysis, planning, policy drafting, or training and exercise design. - Additional language skills.
Benefits and work setup
- Remote-first position; Pacific Time Zone candidates preferred. - HSA medical plan with 100% of employee-only premium covered; PPO option with partial coverage; HSA employer contribution and Medical FSA. - Employer-paid life, short-term disability, long-term disability, and AD&D insurance. - 401(k) with employer match, plus 11 paid holidays and paid vacation, sick, and parental leave. - Annual health and wellness benefit, pet insurance, national employee discount program, and an Employee Assistance Program. - Identity protection service, plus access to a risk intelligence dashboard and mobile app for 24/7 threat information. - Dedicated security and intelligence training programs, coaching, and mentoring opportunities. - Listed pay range of $150,000 USD.