04 Oct
|
Aiwf Technologies
|
Bengaluru
04 Oct
Aiwf Technologies
Bengaluru
Fraud Investigator, Test Security
Talview | Managed Services | Test Security Research Programme
Location: Bangalore
Employment Type: Full-time
Experience: 35 years
Reports to: Programme Owner, Managed Services
Works with: Data Science, Product Engineering, Customer Success, Legal, and Proctoring Operations
About the Role
Talview runs a permanent Test Security Research Programme within Managed Services to identify examination malpractice through internal session data and research into external services offering exam leaks, exam assistance, and proxy test-taking.
As the programmes dedicated investigator, you will analyse session telemetry to identify suspicious patterns, conduct structured external threat research, and test qualified services against Talview-controlled assessments under approved rules of engagement.
Each investigation must result in an actionable product improvement request or an evidence-backed customer case, recorded in the Test Security Dashboard. Findings must be corroborated, auditable, and able to withstand scrutiny months after the investigation.
Key Responsibilities
Internal Telemetry Analysis
- Run recurring session-to-IP extracts and maintain baselines and exclusion lists for legitimate shared networks, including corporate NAT, universities, test centres, and CGNAT.
- Cluster sessions using IP addresses and environment fingerprints, identify distinct candidate identities within each cluster, and develop qualifying clusters into reviewable cases.
- Assess shared-IP clusters with different environments using temporal proximity, same-assessment overlap, and completion-time similarity. Advance only those that meet the agreed investigation threshold.
- Audit proctor-flag review decisions against session recordings, logs, and the agreed malpractice taxonomy.
- Analyse false positives and missed incidents by proctor, customer, and flag type, and use findings to improve proctor training.
- Raise structured investigation requests to Data Science for advanced forensic analysis, including event-stream signatures, log reconstruction, and biometric clustering, and incorporate the findings into each case.
External Threat Research
- Maintain an ongoing search programme across search engines, social and video platforms, freelancing marketplaces, forums, Telegram, and Discord, including regional-language channels.
- Maintain a version-controlled keyword set covering exam leaks, exam assistance, remote desktop support, proxy test-taking, and named customer assessments.
- Qualify leads and maintain a lead register.
- Begin with passive research, preserving each service’s pricing, claimed methods, guarantees, delivery mechanisms, and geographic coverage verbatim, with timestamps.
- Engage qualified agencies only under approved rules of engagement, using approved research personas, channels, and payment instruments.
- Plan and execute controlled tests against Talview-controlled assessments, securing Legal and Finance approvals and capturing detailed session telemetry.
- Document the methods observed and produce a detection-gap analysis as the primary deliverable.
- Publish a threat brief for each investigation and route countermeasure requirements to Product Engineering, with priority based on the assessed scope and impact of the threat.
Evidence, Escalation, and Reporting
- Assemble evidence packs that include triggered signals, corroboration from independent signal types, proctor observations, Data Science findings, and alternative explanations considered and ruled out.
- Apply the programme’s confidence framework and draft recommended actions for Programme Owner review.
- Brief Customer Success Managers within agreed SLAs and record the customer’s decision when closing each case.
- Maintain the Test Security Dashboard, ensuring every case has an owner, status, and next action, and that aggregate metrics can be traced to source sessions.
- Prepare weekly summaries and monthly customer test security reports.
- Contribute to monthly trend reports and quarterly leadership briefs.
Required Skills and Experience
Essential
- Investigation: 3–5 years of experience in fraud investigation, trust and safety, platform integrity, or anti-cheat, with demonstrated ability to take a case from an initial signal to a written finding that withstands challenge.
- Event data analysis: Hands-on experience with product analytics tools such as Mixpanel or Amplitude and telemetry or error-monitoring tools such as Sentry or Datadog to reconstruct user activity within a session.
- SQL: Solid query-writing skills using columnar databases or event stores such as ClickHouse, BigQuery, Snowflake, or Athena, including independently writing clustering queries.
- Python: Experience using pandas or equivalent tools to turn one-off investigations into repeatable analyses and recurring detection rules.
- OSINT: Experience sourcing and engaging actors on marketplaces, Telegram, and Discord, with disciplined use of research personas and evidence preservation.
- Technical understanding: Familiarity with NAT, CGNAT, device fingerprinting, virtual machines, virtual cameras, remote-access tools, and secure-browser restrictions. Ability to read and interpret logs independently.
- Written communication: Ability to prepare clear customer-facing reports and detailed internal evidence packs.
Desirable
- Experience in online proctoring, assessment delivery, or high-stakes examination integrity.
- Advanced Excel or Google Sheets skills.
- Dashboarding and data modelling experience using Power BI, Tableau, Looker Studio, or Metabase.
- Familiarity with GDPR, the DPDP Act, and constraints on handling biometric data.
- Experience working under documented rules of engagement in threat research, intelligence, or red-team environments.
- Exposure to fraud rings or marketplace abuse.
- Proficiency in a second language relevant to customer candidate populations.
- Certified Fraud Examiner (CFE) or equivalent certification.
📌 Fraud Investigator (Bengaluru)
🏢 Aiwf Technologies
📍 Bengaluru