Incident Response Manager - Abuse Operations
Core
Lead end-to-end fraud and abuse incident response, investigating high-risk accounts, mitigating active attacks, and driving cross-functional improvements to scale detection.
Role type
Senior IC Incident Response Manager (Fraud & Abuse)
Builds
Automated response workflows, incident runbooks, and agentic response solutions
Domain
Financial services, fraud detection, and security operations
Deliverable
production ML models | product features
Required skills
Incident response leadership, fraud investigation, threat intelligence, Python, SQL, log analysis, network security, digital forensics, risk mitigation, cross-functional alignment
Preferred skills
Fraud mitigation, adversarial mindset, big data processing (Databricks, Trino), data science frameworks (PySpark, Pandas, Sci-kit Learn), tactical threat hunting
Technologies
Python, SQL, Databricks, Trino, PySpark, Pandas, Sci-kit Learn
Responsibilities
Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure. Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response. Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence. Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention. Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting. Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.
Seniority
Senior, hands-on IC