À propos de ce poste Staff Insider Risk Engineer chez BILL
Innovate with purpose
At BILL, we believe in empowering the businesses that drive our economy. By replacing outdated financial processes with innovative tools, we help businesses—from startups to established brands—make smarter decisions and gain control of their operations. And we don’t stop there: we’re creating the future of financial automation so businesses can spend more time on what matters.
Working here means you become part of a vision-driven team that’s ready to tackle challenges and build cutting-edge solutions. We value purpose, drive, and curiosity—and we thrive in a fast-paced, ever-changing environment. Whether in one of our offices in San Jose, CA, Draper, UT, or in a remote-eligible role, BILLders collaborate to deliver real impact for businesses that need more time in their busy weeks.
BILL builds high performing teams and we seek to hire the best talent for every role. We're committed to building a workplace that fosters inclusion and diverse perspectives, valuing each person’s unique skills and experiences. We’d love to hear from you—you might be just what we’re looking for, whether in this role or another.
✨ Let’s give businesses more time for what matters.
Make your impact within a rapidly growing Fintech Company
BILL is looking to hire a Staff Insider Risk Engineer to join the Security Operations Center to support the insider risk and digital forensics functions. Protecting the company's data, systems, and employees is mission-critical to maintaining the trust of our customers and partners.
The Insider Risk role sits at the intersection of security operations, digital forensics, and cross-functional partnership with People, Legal, and Safety and Security teams, directly shaping how BILL identifies, investigates, and remediates insider threats. You’ll combine investigative tradecraft, behavioral analysis, technical telemetry, and AI-assisted workflows to rapidly assess risk and drive informed security decisions.
Detection Engineering & Alert Fidelity Optimization: Design, build, and continuously refine insider threat detection logic, use cases, and analytics to improve signal quality. Leverage AI to accelerate investigations, validate findings, and improve decision-making. Identify opportunities to automate repetitive work and improve investigative workflows.
Alert Triage and Investigation: Triage and investigate insider threat alerts, applying structured methodologies to assess risk and using forensics to complete thorough analyses. Translate investigation outcomes into control improvements.
Detection Strategy & Use Case Development: Develop and implement a scalable detection strategy aligned to key insider threat risks (i.e., data exfiltration, employee exit risk, misuse). Identify gaps and prioritize new detection use cases to expand coverage and effectiveness
Cross-Functional Partnership: Partner with InfoSec, IT, Legal, and HR teams to ensure detections are risk-aligned, context-aware, and operationally actionable. Incorporate business context and investigation requirements into detection design to improve alert fidelity and response effectiveness.
Security Operations Collaboration: Provide support during high-risk security incidents where forensics and related skills are required.
Responsibilities
- Conduct investigations into suspected insider threats, including data exfiltration, policy violations, and risky behavior
- Triage and validate alerts from the insider risk management program, determining severity and appropriate escalation path in line with the tiered risk framework
- Partner with the HR, Legal, and Privacy on remediation of confirmed insider incidents, including participation in employee interviews and documentation of findings
- Maintain chain-of-custody documentation and adhere to established digital forensics standards to preserve evidentiary integrity for all investigations
- Author clear, defensible investigation reports and file timelines that support HR and Legal decision-making on disciplinary or remediation actions
- Contribute to and continuously improve insider risk playbooks and working groups
- Support the design and tuning of detection use cases and monitoring baselines to improve identification of anomalous insider behavior
- Track metrics for leadership, with the intention of highlighting trends and improvement opportunities
- Support security operations efforts as capacity allows, given the close working relationship between insider risk and the broader security operations functions
We’d love to chat if you have:
- 7+ years of experience in insider risk, security operations, investigations, digital forensics, incident response, compliance, data protection, or enterprise risk management
- 2+ years of experience managing an insider risk program or conducting insider risk investigations
- Experience with forensic tools and endpoint data loss prevention platforms
- Experience with macOS, Windows, and cloud/container-based forensic analysis
- Familiarity with cloud platforms (e.g. AWS) and collaboration platforms (e.g., Google Workspace) and the ability to extract and interpret log data to support investigations
- Hands-on experience with security tools such as SIEM, UEBA, EDR, and email security solutions
- Excellent written and oral communication skills, with the ability to produce clear, factual, and defensible investigation documentation for stakeholders
- Sound judgment and discretion when handling sensitive, confidential, or privileged information
- Ability to work in high-pressure and time-sensitive situations while maintaining accuracy and objectivity
- Meticulous attention to detail and quality of work product
- Utilize AI to accelerate investigations and automate repetitive tasks
Visa Sponsorship: Please note that this position is not eligible for visa sponsorship. Applicants must have authorization to work in the United States without requiring visa sponsorship now or in the future.
Our ranges for each role and job level are based on a variety of factors including candidate experience, expertise, and geographic location and may vary from the amounts listed below. The role is also eligible for a competitive benefits package that includes: medical, dental, vision, life and disability insurance, 401(k) retirement plan, flexible spending & health savings account, paid holidays, paid time off, and other company benefits. The estimated salary ranges noted below roles in the specific geographic zones
What’s in it for you?
Redefining how businesses automate their work is a fast-paced, exciting, and fun environment. But we also have benefits and perks to ensure the magic isn’t only experienced by our customers, but by our employees as well.
Here is a preview of some of the amazing benefits here at BILL:
- 100% paid employee health, dental, and vision plans (choose HMO, PPO, or HDHP)
- HSA & FSA accounts
- Life Insurance, Long & Short-term disability coverage
- Employee Assistance Program (EAP)
- 11+ Observed holidays and wellness days and flexible time off
- Employee Stock Purchase Program with employee discounts
- Wellness & Fitness initiatives
- Employee recognition and referral programs
- And much more
Don’t believe us? Check out our culture, benefits, and teams on our career site, LinkedIn Life, or YouTube pages.
BILL is an Equal Opportunity Employer. We believe our best ideas come from the unique stories, perspectives, and experiences of our team members. We welcome people of all backgrounds, abilities, and identities to bring their authentic selves and contribute to our culture.
We are committed to a transparent, inclusive hiring process that reflects our values. If you need accommodations at any stage, please contact interviewaccommodations@hq.bill.com. To ensure a fair evaluation, our Candidate Integrity Policy prohibits the use of unapproved external assistance, including generative AI, during live interviews or assessments. Doing so will result in a review and potential disqualification.
Our Applicant Privacy Notice describes how BILL treats the personal information it receives from applicants.