Security Engineer, Insider Risk
Security Engineer · Mid · Full Time
Opens Airwallex's application page
Role
What you'll do.
Security Engineer focused on insider risk and fraud detection at Airwallex, a $11B fintech leader managing $200B+ in payments. This role requires 3+ years of detection engineering expertise with hands-on experience in SIEM, EDR, DLP, and behavioral analytics, specifically in designing advanced detection rules, conducting digital forensics, and collaborating cross-functionally to protect against sophisticated insider threats and fraud in a cloud-native financial infrastructure environment.
Responsibilities
- Detection Rule Development and Optimization: Design, develop, and maintain advanced detection signatures and analytics across SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), DLP (Data Loss Prevention), and payment monitoring platforms. Create high-efficacy detection logic that identifies both technical threats and nuanced abuse scenarios, with continuous tuning and refinement based on emerging insider and fraud threat patterns.
- Insider Threat and Fraud Investigation: Conduct deep-dive analysis into user, system, and financial data to uncover complex fraud tactics, potential abuse by insiders, and privileged user misuse. Develop and maintain comprehensive detection logic for insider and fraud scenarios, identifying sophisticated attack vectors including account misuse, privilege escalation attempts, and social engineering tactics that could compromise the $200B+ payments ecosystem.
- Incident Response and Digital Forensics Support: Support relevant incident response and digital forensics efforts by collecting, analyzing, and correlating forensic evidence. Link forensic findings to potential business impact, coordinate investigation efforts with relevant teams, and document findings to establish clear audit trails. Contribute technical expertise to accelerate incident resolution and improve detection capabilities based on forensic learnings.
- Cross-Functional Collaboration and Risk Mitigation: Collaborate with fraud analysts, KYC (Know Your Customer) operations, compliance teams, and broader security engineering functions to improve high-risk workflows including onboarding, KYC processes, authentication mechanisms, and funds movement protocols. Identify and mitigate emerging risks such as account misuse, privilege escalation, and social engineering within the organization by sharing threat intelligence and detection insights.
- Threat Modeling and Best Practices Leadership: Mentor peers on advanced detection strategies, fraud taxonomy development, and the complete fraud and insider threat lifecycle. Share domain best practices in threat modeling and detection engineering with the engineering team, actively supporting others' development in fraud and insider risk domains. Foster technical depth and establish center-of-excellence practices for insider threat and fraud detection capabilities.
- Behavioral Analytics and Anomaly Detection Implementation: Develop and operationalize detection logic utilizing behavioral analytics, anomaly detection algorithms, and rule-based logic to surface insider and fraud risk. Contribute insight into evolving fraud trends and trusted insider behaviors, strengthening Airwallex's proactive security stance through continuous learning, agile solution development, and adaptation to new attack methodologies in the fintech landscape.
- Workflow and Control Enhancement: Lead the creation and enhancement of DLP controls with expertise in correlating exfiltration techniques to insider scenarios. Contribute to the development of monitoring strategies that align with modern cloud-native architectures and identity and access management frameworks. Improve control effectiveness through data-driven recommendations and close collaboration with engineering and operations teams.
- Regulatory and Compliance Alignment: Ensure detection strategies and incident response protocols align with regulatory requirements, compliance best practices, and incident disclosure obligations specific to financial institutions. Maintain awareness of evolving regulatory standards and incorporate compliance considerations into threat modeling and detection logic development.
- Technical Problem-Solving and Root Cause Analysis: Demonstrate relentless pursuit of root causes for security incidents and false positives. Navigate ambiguity effectively by seeking out new data sources and synthesizing signals across disparate platforms and logs. Develop technical proofs of concept to validate threat hypotheses and improve detection accuracy, ensuring that detection engineering efforts directly impact insider risk and fraud prevention effectiveness.
Qualifications
What we look for.
Technical
SIEM Platform Expertise
Advanced hands-on experience designing, building, and operating Security Information and Event Management (SIEM) platforms. Proficiency in creating complex correlation rules, managing alert tuning, and orchestrating data ingestion from multiple sources to detect insider threats and fraud patterns across enterprise infrastructure.
EDR and Endpoint Detection
Strong expertise with Endpoint Detection and Response (EDR) tools for identifying suspicious endpoint behavior, lateral movement, and data exfiltration attempts. Experience configuring behavioral detection rules, managing alert response workflows, and correlating endpoint telemetry with network and user behavior data to identify insider threats.
DLP Control Design and Implementation
Expert-level experience designing, implementing, and tuning Data Loss Prevention (DLP) controls. Demonstrated ability to map exfiltration techniques to specific insider scenarios, configure content policies, monitor data movement patterns, and correlate DLP alerts with other security telemetry to identify sophisticated data theft attempts.
Behavioral Analytics and Anomaly Detection
Proficiency in deploying and tuning user behavior analytics (UBA) and anomaly detection systems. Experience building detection models that identify deviations from baseline user behavior, privilege escalation patterns, account misuse indicators, and other behavioral anomalies indicative of insider threats or compromised accounts.
Cloud-Native Architecture Security
Working knowledge of modern cloud-native architectures (Kubernetes, microservices, serverless) and cloud platforms (AWS, Azure, GCP) with understanding of how cloud identity, access management, and monitoring differ from on-premises environments. Ability to design detection rules for cloud-specific attack vectors and insider risk scenarios.
Digital Forensics and Incident Response
Hands-on experience conducting digital forensics investigations, collecting forensic evidence, preserving chain of custody, and analyzing artifacts to support incident response efforts. Ability to correlate forensic findings with security telemetry, timeline reconstruction, and attribution of malicious activities to specific actors or scenarios.
Payment Systems and Transaction Monitoring
Experience with fraud detection platforms and transaction monitoring systems used in payment processing environments. Understanding of payment risk indicators, transaction anomalies, and anti-money laundering (AML) principles relevant to detecting fraudulent fund movements and insider abuse of payment systems.
SQL and Data Analysis
Strong SQL proficiency for querying security logs, event databases, and fraud detection systems. Ability to perform complex data analysis, create custom reports, and extract security-relevant signals from large datasets to support threat investigation and detection rule development.
Scripting and Automation
Proficiency in scripting languages such as Python or PowerShell for automating threat detection workflows, parsing security logs, developing custom analysis tools, and orchestrating response actions. Experience creating reproducible analysis frameworks and automating manual detection processes.
Threat Modeling and Attack Framework Knowledge
Strong understanding of threat modeling methodologies, MITRE ATT&CK framework for insider threats and fraud scenarios, and attack flow analysis. Ability to map attacker tactics and techniques to detection opportunities and translate business risks into technical detection requirements.
Education
Bachelor's Degree in Computer Science or Information Security
Formal education in Computer Science, Information Security, Cybersecurity, or closely related technical field. Degree should provide foundational knowledge in system architecture, cryptography, networking, and security principles necessary for detection engineering roles.
Industry Certifications
Relevant security certifications such as GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), OSCP (Offensive Security Certified Professional), CISSP (Certified Information Systems Security Professional), or similar credentials that demonstrate commitment to security engineering excellence and continuous professional development.
Experience
3+ Years Detection and Security Engineering Experience
Minimum 3+ years of hands-on, practical experience in security engineering or detection engineering roles with direct responsibility for designing and maintaining detection systems. Experience should demonstrate progressive expertise in building robust detection architectures and responding to sophisticated threats.
Insider Threat and Fraud Detection Specialization
Proven track record with strong focus on insider threat detection and fraud risk prevention in complex technology or financial environments. Demonstrated experience identifying behavioral patterns indicative of insider threats, designing detections for account misuse scenarios, and developing comprehensive fraud detection strategies.
Fintech, Payment, or Regulated Environment Experience
Preferential background in fintech, payment processing, or regulated industries (banking, financial services) handling substantial fraud and insider risk volumes. Experience navigating compliance requirements, working with regulatory frameworks, and implementing controls in high-stakes financial environments where security failures have significant business impact.
Digital Forensics and Transaction Analysis Experience
Strong hands-on background in digital forensics investigation, transaction analysis, and financial crime investigation. Ability to link forensic evidence to business impact, conduct detailed transaction reviews to identify fraud patterns, and present findings to both technical and non-technical stakeholders.
Skills
Required
SIEM Operations and Rule Development
Advanced proficiency in SIEM platforms with ability to develop, tune, and maintain complex detection rules and correlation logic for identifying insider threats and fraud.
Endpoint Detection and Response (EDR)
Expert-level knowledge of EDR tools for detecting suspicious endpoint behavior, lateral movement, and data exfiltration patterns associated with insider threats.
Data Loss Prevention (DLP) Engineering
Deep expertise in designing and implementing DLP controls, correlating exfiltration techniques with insider scenarios, and tuning content policies for maximum fraud and insider threat detection.
Behavioral Analytics and Anomaly Detection
Proficiency in deploying user behavior analytics platforms and developing anomaly detection algorithms that identify deviations from baseline behavior indicative of compromise or insider abuse.
Digital Forensics
Hands-on experience conducting forensic investigations, collecting evidence, preserving chain of custody, and reconstructing timelines to support insider threat and fraud investigations.
SQL and Data Query
Strong SQL capabilities for extracting, analyzing, and correlating data from security logs, event databases, and fraud detection systems to identify threats and validate detection hypotheses.
Python or PowerShell Scripting
Proficiency in scripting languages for automating threat detection workflows, parsing security logs, and creating custom analysis tools to scale detection efforts.
Cloud Security Architecture
Working knowledge of cloud-native security principles, cloud platform architecture, and cloud identity and access management as they relate to insider threat and fraud detection.
Incident Response Coordination
Ability to support incident response efforts, coordinate across teams, preserve forensic evidence, and communicate findings effectively to technical and non-technical stakeholders.
Threat Modeling and MITRE ATT&CK
Strong understanding of threat modeling methodologies and MITRE ATT&CK framework applied to insider threat and fraud scenarios for identifying detection gaps and opportunities.
Preferred
Payment Systems Security
Nice to haveExperience with fraud detection and transaction monitoring systems used in payment processing environments, including understanding of payment risk indicators and fund movement anomalies.
Anti-Money Laundering (AML) Principles
Nice to haveFamiliarity with AML frameworks, suspicious activity reporting, and compliance requirements applicable to financial institutions handling cross-border payments and financial transactions.
Kubernetes and Microservices Security
Nice to haveSecurity expertise specific to containerized and microservices-based architectures, including identity, access control, and monitoring in modern cloud-native environments.
Advanced Persistent Threat (APT) Forensics
Nice to haveExperience investigating advanced threats, attributing attacks to specific threat actors, and understanding sophisticated tradecraft relevant to insider threat and targeted fraud scenarios.
Machine Learning for Security
Nice to haveBackground in developing or deploying machine learning models for anomaly detection, fraud prediction, or behavioral analytics to enhance detection capability beyond rule-based approaches.
Compliance and Regulatory Frameworks
Nice to haveDeep understanding of financial regulatory requirements (SOX, PCI-DSS, GDPR), incident disclosure obligations, and compliance best practices relevant to financial institutions.
User Behavior Analytics (UBA) Platforms
Nice to haveSpecific experience configuring and tuning user behavior analytics platforms such as Splunk UBA, Exabeam, or similar solutions for detecting insider threats and compromised account activity.
SOAR Platform Integration
Nice to haveExperience with Security Orchestration, Automation and Response (SOAR) platforms for automating incident response workflows, enriching alerts with threat intelligence, and scaling detection operations.
Fraud Investigation Tools
Nice to haveHands-on experience with fraud investigation platforms, transaction analysis tools, and case management systems used in financial crime investigations and fraud prevention.
Security Team Leadership and Mentorship
Nice to haveDemonstrated ability to mentor junior team members, establish best practices, develop detection strategies, and foster a culture of technical excellence within security teams.
Compensation
Pay and benefits.
Base·USD 140,000 – 185,000
Equity·Stock options
Full posting
Original listing.
About Airwallex
Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale.
Proudly founded in Melbourne, we have a team of over 2,300 of the brightest and most innovative people in tech across 27 offices around the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you’re ready to do the most ambitious work of your career, join us.
Attributes We Value
We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you’re motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor.
You're humble and collaborative; turn zero‑to‑one ideas into real products, and you “get stuff done” end-to-end. You use AI to work smarter and solve problems faster. Here, you’ll tackle complex, high‑visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let’s build what’s next.
About the team
The Airwallex Information Security Team is a high calibre and highly proactive team that works across our infrastructure, applications, corporate IT and broader engineering functions.
What you’ll do
As a Security Engineer focused on insider and fraud threats within the Information Security Engineering team, you will be pivotal in protecting Airwallex’s $200b+ payments ecosystem, our customers, and our global workforce. Your mandate centers on identifying, investigating, and challenging threats from both internal and external actors. You will be challenged to:
Design, develop, and maintain advanced detection rules and automated response mechanisms to surface insider and fraud risk, using a mix of behavioral analytics, anomaly detection, and rule-based logic.
Deep-dive into user, system, and financial data to uncover complex fraud tactics and potential abuse by insiders or privileged users.
Contribute insight into evolving fraud trends and trusted insider behaviors, strengthening Airwallex’s proactive security stance through continuous learning and agile solutioning.
Mentor peers on advanced detection strategies, fraud taxonomy development, and the broader fraud/insider threat lifecycle, fostering technical depth on the team.
Responsibilities
Lead the creation and tuning of high-efficacy detection signatures and analytics across SIEM, EDR, DLP, and payment monitoring platforms, focusing on both technical threats and nuanced abuse scenarios.
Support relevant incident response and digital forensics efforts.
Identify and mitigate the risk of issues such as account misuse, privilege escalation, and social engineering within the organization.
Collaborate with fraud analysts, KYC operations, compliance, and the broader security team to improve high-risk workflows (onboarding, KYC,authentication, funds movement).
Create, maintain, and operationalize detection logic for insider and fraud scenarios.
Share domain best practices in threat modeling and detection with the engineering team, actively supporting others’ development in fraud and insider risk domains.
Who you are
You have a proven passion for detecting and responding to sophisticated fraud and insider threats in a Fintech or technology-driven environment. You are outcome-driven, relentless in your pursuit of root causes, and thrive when blending technical acumen with creative threat modeling. You are:
Intellectually curious, especially about insider threat frameworks, fraud prevention, psychology of trust abuse, and organizational risk.
Adept at navigating ambiguity, seeking out new data sources, and synthesizing signals across disparate platforms and logs.
Proactive in identifying abuse patterns, hypothesizing how attackers (internal and external) might operate within a complex ecosystem, and testing theories through technical proof.
Articulate when presenting complex scenarios to stakeholders, and skilled at collaborating across business, security, compliance, and engineering functions.
Minimum Qualifications
Bachelor’s degree in Computer Science, Information Security, or relevant field.
3+ years of hands-on experience in security engineering or detection engineering, with a strong focus on insider threat or fraud risk (ideally in financial or high-growth technology settings).
Direct experience building, tuning, and operating detection and monitoring solutions (e.g. SIEM, EDR, DLP, user behavior analytics, and fraud detection platforms).
Expertise designing and implementing DLP controls and correlating exfiltration techniques with insider scenarios.
Working knowledge of modern cloud-native architectures and how they impact identity, access, and monitoring.
Experience with coordinating incident response and digital forensics.
Preferred Qualifications
Experience within Fintech, payment, or regulated environments handling substantial fraud or insider risk volumes.
Strong background in digital forensics, transaction analysis, and linking forensic evidence to potential business impact.
Understanding of regulatory requirements, compliance best practices, and incident disclosure obligations for financial institutions.
Applicant Safety Policy: Fraud and Third-Party Recruiters
To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page.
Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary.
Equal opportunity
Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don’t regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.
Redirects to Airwallex's application page.
Other roles
More at Airwallex.
Software Engineer - Intern 2027
Intern
IT Support Engineer
Junior
IT Support Engineer
Mid
Corporate Security Engineer
Mid
Senior Data Scientist, Analytics (Lending)
Senior