Security Engineer, Detection & Response
Robinhood
Job Description
Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you鈥檙e ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world鈥檚 biggest financial problems. We鈥檙e looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn鈥檛 a place for complacency, it鈥檚 where ambitious people do the best work of their careers. We鈥檙e a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Security Operations (SecOps) team works to safeguard Robinhood and its customers by identifying, investigating, and responding to security threats. The team monitors production systems, endpoints, and cloud environments, and uses threat intelligence and structured testing to uncover risks before they affect customers. SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and response readiness. The team鈥檚 focus is clear: reduce risk, improve visibility, and protect customer trust every day! As a Security Engineer, Detection & Response, you will strengthen Robinhood鈥檚 ability to detect, investigate, and contain security incidents. You will design and improve detection logic, analyze security telemetry across cloud and endpoint systems, and contribute to measurable reductions in false positives and detection gaps. You will work directly with SOC analysts and security engineers to refine investigation workflows and document incident findings. This role is ideal for someone who enjoys hands-on detection engineering and improving how teams respond to real-world threats! This role is based in our Menlo Park, CA office, with in-person attendance expected at least 3 days per week. At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams. What you鈥檒l do Investigate security alerts across SIEM, EDR, and cloud security platforms, perform log analysis, and coordinate containment or remediation steps with engineering partners Develop, test, and tune detection rules using query languages to improve signal quality and reduce false positives Correlate data from multiple telemetry sources to identify attack patterns and determine appropriate
Read original postingRequired Skills
Robinhood