Staff Insider Risk Engineer

BILL
$156,000 - $220,000Remote

About The Position

BILL is looking to hire a Staff Insider Risk Engineer to join the Security Operations Center to support the insider risk and digital forensics functions. Protecting the company's data, systems, and employees is mission-critical to maintaining the trust of our customers and partners. The Insider Risk role sits at the intersection of security operations, digital forensics, and cross-functional partnership with People, Legal, and Safety and Security teams, directly shaping how BILL identifies, investigates, and remediates insider threats. You’ll combine investigative tradecraft, behavioral analysis, technical telemetry, and AI-assisted workflows to rapidly assess risk and drive informed security decisions.

Requirements

  • 7+ years of experience in insider risk, security operations, investigations, digital forensics, incident response, compliance, data protection, or enterprise risk management
  • 2+ years of experience managing an insider risk program or conducting insider risk investigations
  • Experience with forensic tools and endpoint data loss prevention platforms
  • Experience with macOS, Windows, and cloud/container-based forensic analysis
  • Familiarity with cloud platforms (e.g. AWS) and collaboration platforms (e.g., Google Workspace) and the ability to extract and interpret log data to support investigations
  • Hands-on experience with security tools such as SIEM, UEBA, EDR, and email security solutions
  • Excellent written and oral communication skills, with the ability to produce clear, factual, and defensible investigation documentation for stakeholders
  • Sound judgment and discretion when handling sensitive, confidential, or privileged information
  • Ability to work in high-pressure and time-sensitive situations while maintaining accuracy and objectivity
  • Meticulous attention to detail and quality of work product
  • Utilize AI to accelerate investigations and automate repetitive tasks

Responsibilities

  • Conduct investigations into suspected insider threats, including data exfiltration, policy violations, and risky behavior
  • Triage and validate alerts from the insider risk management program, determining severity and appropriate escalation path in line with the tiered risk framework
  • Partner with the HR, Legal, and Privacy on remediation of confirmed insider incidents, including participation in employee interviews and documentation of findings
  • Maintain chain-of-custody documentation and adhere to established digital forensics standards to preserve evidentiary integrity for all investigations
  • Author clear, defensible investigation reports and file timelines that support HR and Legal decision-making on disciplinary or remediation actions
  • Contribute to and continuously improve insider risk playbooks and working groups
  • Support the design and tuning of detection use cases and monitoring baselines to improve identification of anomalous insider behavior
  • Track metrics for leadership, with the intention of highlighting trends and improvement opportunities
  • Support security operations efforts as capacity allows, given the close working relationship between insider risk and the broader security operations functions

Benefits

  • medical
  • dental
  • vision
  • life and disability insurance
  • 401(k) retirement plan
  • flexible spending & health savings account
  • paid holidays
  • paid time off
  • Employee Assistance Program (EAP)
  • 11+ Observed holidays and wellness days and flexible time off
  • Employee Stock Purchase Program with employee discounts
  • Wellness & Fitness initiatives
  • Employee recognition and referral programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service