Fraud Intelligence Lead
Listed on 2026-09-18
-
IT/Tech
Data Analyst, Cybersecurity, Data Science Manager
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use.
Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.
Our Fraud Intelligence team's mission is to turn fraud signals into insight that our EPD teams transform into improvements across Protect, IDV, Signal, and Guaranteed Payments. We believe transaction patterns, device signals, identity linkages, and behavioral data are dramatically under leveraged tools in fraud prevention, and we ground our products in what adversaries are actually doing right now.
As the Fraud Intelligence Lead, you will build and run a small, high-leverage team of Fraud Intelligence Analysts (and eventually a Staff Researcher) responsible for live casework across Protect, IDV, and Payments/ACH. You'll operate as a player-coach, hiring and coaching your team while staying close enough to the work to personally pick up casework and SEV response when needed.
ResponsibilitiesTeam Building & People Leadership
Set the casework quality bar: define what rigorous investigation, triage, and reporting look like for the team
Coach analysts on investigation technique, pattern synthesis, and translating findings into product/model input
Operating Model & Cross-PA Partnership
Own coverage allocation across the Protect/IDV and Payments/ACH pods, including flexing assignments as volume shifts
Manage matrixed staffing and time allocation clearly between the Fraud PA and Payments PA
Represent the Fraud Intelligence team in product and model roadmap discussions, translating casework patterns into strategic priorities
Reporting & Escalation
Report team health, casework trends, and emerging risks to the Head of Fraud
Own escalation paths for SEVs and incidents requiring legal, law enforcement, or regulatory involvement
Live Fraud Investigation & Reconstruction
Lead investigations into complex fraud cases across identities, accounts, devices, and transaction surfaces
Provide support to day-to-day fraud operations including SEVs and alert triage
Reconstruct attacker sequences and hypothesize actor intent and tooling
Distill patterns from noisy signals into clear narratives and actionable insights
Bridge investigation outcomes to product and model improvements
Product & Model Partnership
Collaborate with Data Science, ML/AI, and Product teams to improve labeling, feature sets, evaluation frameworks, and model decay monitoring
Surface data quality limitations and systematically formalize missing features
Translate exploratory research into reusable feature pipelines, model inputs, or rule augmentations
Participate in product discovery, roadmap planning, and post-launch evaluation to ensure fraud-awareness by design
Ecosystem Monitoring & Knowledge Leadership
Continuously survey external fraud trends, adversary techniques, tooling, and emerging threat vectors
Proactively perform threat modeling of abuse surfaces and initiate research proposals when patterns emerge
5+ years of applied fraud experience in a high-velocity environment (fintech, consumer payments, banking, SaaS, marketplace risk, or security research)
Investigator mindset: pattern synthesis, hypothesis testing, and skilled triage between signal and noise
End-to-end investigation experience reconstructing attacker intent and behavior in multi-step attack sequences across accounts, devices, and identities
Post-containment incident response experience with a deep emphasis on post-mortems and root cause analysis
Dark and grey-web navigation and investigation experience; ability to assess source credibility and translate external intelligence into actionable insights
Strong communication: ability to explain complex, ambiguous behavior to technical and non-technical audiences
Tool fluency with data environments and investigative tool chains (BI tools, anomaly detection, case trackers)
SQL for deep data querying and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).