Sr. Technical Investigator, Trust Investigations Account Security

LinkedIn

$136K — $221K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in a technical field or equivalent experience
  • 5+ years with scripting or data analysis tools (SQL, Python)
  • 5+ years in proactive threat investigations related to account security
  • 3+ years with investigation techniques and evidence handling
  • Familiarity with authentication and session security concepts

Responsibilities

  • Lead root-cause investigations into high-impact account security campaigns
  • Serve as incident commander during major account-compromise incidents
  • Generate proactive investigative leads on coordinated threat activity
  • Develop detection rules and pipelines for account takeover patterns
  • Mentor junior investigators on technical and tooling capabilities
  • Collaborate with product and engineering teams to inform risk posture
  • Represent team's work in cross-functional forums

Benefits

  • Generous health and wellness programs
  • Time away for employees at all levels
  • Commitment to fair and equitable compensation practices
  • Annual performance bonus potential
  • Stock options and other incentive compensation plans
Full Job Description
At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team. This role will be based in Mountain View, CA. Trust Investigations is seeking a Senior Technical Investigator to support our work protecting member accounts. In this role, you'll develop and apply approaches to detect, understand and mitigate coordinated, persistent, and high-harm attacks against account access and authentication, helping ensure a safe and trustworthy experience for LinkedIn members. Our teams work closely with product, engineering, and data science partners dedicated to advancing our visibility, controls and measurement across login, authentication, and account recovery. In this role you will run investigations and contribute to building our technology as we operate an AI-first trust environment: you'll lead complex investigations and incidents, using case insights to develop and maintain our detection rules, pipelines, and runbooks that help LinkedIn stop account takeover (ATO) and account rental activity at scale. Our investigations drive product vulnerability assessments and risk recommendations, so you'll work with our intelligence teams, engineers focused on challenges and controls, and product-risk teams to ensure findings inform how the company builds and protects its login, MFA, and account recovery experiences going forward. Key Responsibilities Investigation & Incident Leadership - Lead root-cause investigations into complex, coordinated, or high-impact account security campaigns, including account rental/seat-sharing networks, from initial leads through resolution. - Serve as incident commander for major account-compromise incidents, coordinating response and ensuring timely, accurate resolution and member remediation. - Generate proactive investigative leads and track emerging coordinated threat activity relevant to account authenticity, security and trust. Detection Engineering & Technical Tradecraft - Author detection rules and data pipelines tuned specifically to ATO patterns and typologies like session hijacking, MFA bypass, and device/network fingerprint anomalies. - Innovate on investigative tradecraft, staying current on tools, techniques, and adversary tactics used across the account takeover and credential-abuse landscape broadly. - Partner with Engineering and Data Science to build and refine analysis, threat-hunting, and mitigations for account abuse. - Develop technical playbooks that help the broader team scale its investigative work across account takeover, recovery, and rental abuse. Cross-Functional Partnership & Vulnerability Reporting - Partner with internal investigators and product-risk teams to ensure investigative findings and intel inform product planning and risk posture. - Collaborate with Product, Engineering, Data Science, Legal, and Policy partners to align investigative priorities with the teams' roadmap and the broader trust strategy. - Represent the technical substance of your team's work in cross-functional forums and externally to peers in the sector. Quality & Mentorship - Mentor other investigators on technical, investigative, and tooling capabilities, fostering a culture of rigor and continuous learning. Qualifications Basic Qualifications - Bachelor's Degree in a related technical discipline, or equivalent practical experience. - 5+ years of experience with scripting or data analysis tools (SQL, Python, or similar), with the ability to synthesize complex data into actionable insights. - 5+ years of experience in proactive threat investigations of account, content, or behavioral abuse in trust & safety, social media, online platforms, or fintech - including meaningful direct experience with account takeover, credential compromise, or authentication abuse. - 3+ years of experience with investigation techniques/tools and evidence handling, including working across diverse structured and unstructured data sets. Preferred Qualifications - Master's Degree in Cyber Security, Criminal Justice, Computer Science, or a related technical discipline. - Direct experience building or maintaining detection rules, alerting logic, or data pipelines (not just consuming them). - Strong technical acumen and the ability to translate data and investigative outcomes into actionable insights for engineering, AI, and senior leadership partners. - Experience leading proactive threat hunting against large-scale, coordinated account takeover or credential-abuse operations. - Familiarity with authentication and session security concepts (MFA/2FA, passkeys, device/session fingerprinting, cookie and token security) and how they're exploited or defended. - Experience with frameworks such as MITRE ATT&CK or the cyber kill chain, and the ability to adapt them to account takeover and authentication-abuse typologies. - Demonstrated ability to navigate cross-functional dependencies and drive collaboration across engineering, product, data science, and legal teams. - Excellent written and verbal communication skills, with the ability to influence across all levels of an organization. - Experience mentoring or developing other investigators. - Experience working in global teams spanning multiple locations and time zones. Suggested Skills - Trust & Safety / Account Security Investigations - Detection Engineering (rules, jobs, pipelines) - Account Takeover & Credential Abuse Investigations - Authentication & Session Security - Platform Abuse Prevention You will Benefit from our Culture: We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels. LinkedIn is committed to fair and equitable compensation practices. The pay range for this role is $136,000 to $221,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor. The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits.

Similar Jobs

More Jobs at LinkedIn

More Information Technology Jobs

Find similar Sr. Technical Investigator, Trust Investigations Account Security jobs: