Lead Insider Threat Investigator

airbnb· Trust and Safety
Apply Now ↗
📍 Sydney, Australia

About this role

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more authentic way.

The Difference You Will Make:

The Insider Threat Lead Investigator is responsible for conducting high-risk, complex insider threat investigations involving cybersecurity, financial misconduct, intellectual property theft, unauthorized access, and data exfiltration. This role focuses on investigating identified threats produced by the Information Security Engineering team or from other internal reporting.

The investigator will conduct technical investigations, guide OSINT research, perform subject interviews, evidence collection, data deletion, and asset retrieval, while ensuring adherence to employment law, corporate policies, and regulatory requirements. This role requires deep technical expertise in digital forensics, cloud security, log analysis, and enterprise forensic tools while maintaining strong legal acumen to manage sensitive cases involving corporate risk, HR, and compliance considerations.

A Typical Day: 

1. Technical Investigations

  • Utilize a functional understanding of information security principles, practices, and frameworks. 
  • Investigate identified insider threat cases escalated from the Information Security Engineering team, including:
    • Financial misconduct
    • Engineering production abuse (e.g., code manipulation, unauthorized system modifications, data sabotage)
    • Intellectual property theft & unauthorized data exfiltration
    • Legal escalations involving executive personnel
  • Conduct structured investigative interviews with subjects and relevant stakeholders to validate findings and gather additional intelligence.
  • Manage incident response in coordination with Information Security, HR, Legal, and other relevant parties.
  • Perform custom high-severity data deletions and secure asset retrieval in compliance with legal, regulatory, and corporate policies.

2. Digital Forensics & Technical Analysis

  • Collaborate with security engineering teams for the forensic collection of digital evidence from endpoints (Windows, macOS, Chrome OS), cloud storage, and mobile devices (iOS, Android).
  • Perform log analysis and coordinate/perform event queries across enterprise systems, synthesizing the digital behaviour to correlate human events and factors to form and complete investigative strategies, including:
    • Windows Event Viewer, MacOS Console, Chrome OS logs
    • Cloud platform logs (AWS, Azure, GCP)
    • Enterprise applications and security logs 
  • Maintain an understanding of technical evidence, forensic artifacts, and the digital environments in which insider threat activities occur.

3. Legal Acumen, Compliance, and Executive Reporting

  • Ensure investigations adhere to employment law, corporate policies, data privacy regulations, and commercial legal frameworks.
  • Collaborate with Legal, HR, Privacy, and Compliance teams to assess corporate risk, legal exposure, and remediation strategies.
  • Provide clear, structured briefings on high-profile cases to executive leadership and cross-functional security teams.
  • Lead post-mortem reviews to refine investigative methodologies and implement lessons learned.

Your Expertise:

  • 10-12 years of experience in insider threat investigations, security, digital forensics, or related industries.
  • Proven experience conducting high-risk, legally sensitive investigations involving corporate executives and critical business functions.
  • Strong expertise in Windows, MacOS, and Chrome OS forensic tools.
  • Experience in SQL-based forensic data correlation and behavioral anomaly analysis.
  • Strong employment legal and commercial legal acumen, with experience handling workplace investigations and regulatory compliance.

Technical Proficiency:

  • Familiarity in digital forensic tools.
  • Advanced knowledge of Windows Event Viewer, MacOS Console, Chrome OS system logs for forensic evidence retrieval.
  • Comprehension and skills in investigating cloud environments and Kubernetes.
  • Experience with high-severity data deletion and asset retrieval in corporate environments.
  • Ability to conduct investigative interviews and communicate findings clearly and effectively to legal, HR, and security teams.

Preferred Certifications:

  • Sans GIAC, GCFA, or GCFE (Advanced Digital Forensics)
  • CISSP
  • AWS/Google/Azure Security certifications
  • CompTIA Cloud+
  • Kubernetes Security or Fundamentals

Our Commitment To Inclusion & Belonging:

Airbnb is committed to working with the broadest talent pool possible. We believe diverse ideas foster innovation and engagement, and allow us to attract creatively-led people, and to develop the best products, services and solutions. All qualified individuals are encouraged to apply.

 

Frequently Asked Questions

Is the salary disclosed for the Lead Insider Threat Investigator position at airbnb?
The salary for this Lead Insider Threat Investigator role at airbnb is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Lead Insider Threat Investigator position at airbnb located?
This Lead Insider Threat Investigator role at airbnb is based in Sydney, Australia. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Which team or department does the Lead Insider Threat Investigator at airbnb belong to?
This Lead Insider Threat Investigator position is part of the Trust and Safety department at airbnb. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Lead Insider Threat Investigator position at airbnb?
Click the "Apply Now" button on this page. You will be redirected to airbnb's official application portal hosted on greenhouse where you can submit your application directly.
When was the Lead Insider Threat Investigator job at airbnb posted?
This Lead Insider Threat Investigator position at airbnb was posted on Jun 4, 2026. Apply as soon as possible — early applications are often reviewed first.
Lead Insider Threat Investigator
airbnb
Apply for this role ↗

You'll be redirected to airbnb's official application page on Greenhouse.