Senior Security Engineer - Detection and Response

Menlo Park, CA, or New York City, NY, or Seattle, WA

Robinhood

Trade 25+ crypto at the lowest cost on average in the EU. Sign up today and get a reward of up to 1 BTC.

View company page

Join a leading fintech company that’s democratizing finance for all.

Robinhood was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood is lowering barriers and providing greater access to financial information. Together, we are building products and services that help create a financial system everyone can participate in.

As we continue to build...

We’re seeking curious thinkers looking to co-author the next chapters of our story. Joining now means helping shape our vision, structures and systems; playing a key-role as we launch into our ambitious future.

About the team:

The preferred location for this position is in or around Robinhood's offices in Menlo Park, CA, New York, NY, or Seattle, WA with in-office work capabilities, as may be required by management.

The Detection and Response Team (D&R) at Robinhood exemplifies our Safety First value by building and operating services that protect our customers' security and privacy. D&R consists of the Detection Platform and Incident Response teams, who work together to detect and assess threats, collect and analyze data, and respond to events. Together, we ensure the effectiveness of our safeguards and the continuous protection of our customer's data.

We are searching for an inquisitive and innovative Security Engineer with a passion for building detection strategies, conducting threat-hunting exercises, automating the mundane, and leading responses to security incidents against the full breadth of Robinhood's technology stack.

We want to talk to you if you're interested in being part of an impactful and inclusive team built on teamwork that encourages your diverse ideas and perspectives.

What you'll do day-to-day:

  • Research attacker tactics, techniques, and procedures (TTPs) and craft detections to quickly identify and contain potential security threats
  • Work with our Threat Intel and Offensive Security teams to stay ahead of emerging threats and understand where our risks and gaps exist
  • Respond to security events, triage, perform investigations, incident analysis, and communicate clearly and efficiently to partners
  • Participate in an on-call rotation

About you:

  • Are innately curious and are skilled at finding hidden signals in a sea of data
  • Possess a breadth of knowledge and experience across the information security domain, such as endpoint security, cloud security, application security, or automation
  • 5+ years of experience in security operations, threat detection, incident response, or related domains

Bonus points:

  • Experience detecting or responding to threats in Kubernetes (K8s), AWS, and Linux environments
  • Proficiency in using Splunk, or similar tools to build sophisticated detections
  • Experience in threat hunting
  • Comfortable scripting in Python, Go, Bash, etc.

Technologies we use:

  • Amazon Web Services (AWS), Kubernetes
  • Splunk, Tines, Falco, Databricks, EDR, osquery

The expected salary range for this role is based on the location where the work will be performed and is aligned to one of 3 compensation zones. This role is also eligible to participate in a Robinhood bonus plan and Robinhood’s equity plan.

US Zone 1: $187000 - $220000
US Zone 2: $165000 - $194000
US Zone 3: $146000 - $172000

Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. You can view comp zones for our US office locations in the table below. For other locations not listed, compensation can be discussed with your recruiter during the interview process.

Office locations (by comp zone)
US Zone 1: Menlo Park, NYC, Seattle, Washington DC 
US Zone 2: Denver, Westlake (Dallas), Chicago 
US Zone 3: Lake Mary


We’re looking for more growth-minded and collaborative people to be a part of our journey in democratizing finance for all. If you’re ready to give 100% in helping us achieve our mission—we’d love to have you apply even if you feel unsure about whether you meet every single requirement in this posting. At Robinhood, we're looking for people invigorated by our mission, values, and drive to change the world, not just those who simply check off all the boxes.

Robinhood promotes diversity and provides equal opportunity for all applicants and employees. We are dedicated to building a company that represents a variety of backgrounds, perspectives, and skills. We believe that the more inclusive we are, the better our work (and work environment) will be for everyone. Additionally, Robinhood provides reasonable accommodations for candidates on request and respects applicants' privacy rights. To review Robinhood's Privacy Policy please visit Robinhood - US Applicant Privacy Policy. If you are an applicant located in the UK or EEA, please visit the Robinhood UK/EEA Applicant Privacy Policy.

Click here to learn more about Robinhood’s Benefits.

Tags: Application security Automation AWS Bash Cloud Databricks EDR Endpoint security Finance FinTech Incident response Kubernetes Linux Offensive security Privacy Python Scripting Splunk Threat detection TTPs

Perks/benefits: Equity Salary bonus Team events

Region: North America
Country: United States
Job stats:  15  3  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.