robinhood
Security Engineer, Detection & Response
At a Glance
- Location
- Menlo Park, California, United States
- Experience
- 2–4 years
- Posted
- 2026-03-16T11:11:26-04:00
Key Requirements
Required Skills
Domain Knowledge
- Engineering
Benefits & Perks
including 100% paid health insurance for employees with 90% coverage for dep
Requirements
2–4 years of experience in security operations, detection engineering, or incident response
Experience analyzing logs and tuning alerts within SIEMs, EDR platforms, and cloud security tools
Experience writing detections using query languages (e.g., SQL-like, KQL, or similar)
Familiarity with threat hunting and investigation techniques across cloud and endpoint environments
Ability to analyze security telemetry, identify patterns of malicious activity, and recommend practical improvements
Here’s what we expect from them:
Compensation & Benefits
Challenging, high-impact work to grow your career.
Performance-driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching.
Best-in-class benefits to fuel your work, including 100% paid health insurance for employees with 90% coverage for dependents.
Lifestyle wallet — a highly flexible benefits spending account for wellness, learning, and more.
Employer-paid life & disability insurance, fertility benefits, and mental health benefits.
Time off to recharge including company holidays, paid time off, sick time, parental leave, and more!
Responsibilities
Investigate security alerts across SIEM, EDR, and cloud security platforms, perform log analysis, and coordinate containment or remediation steps with engineering partners
Develop, test, and tune detection rules using query languages to improve signal quality and reduce false positives
Correlate data from multiple telemetry sources to identify attack patterns and determine appropriate response actions
Monitor emerging threats and update detection logic based on investigation findings and threat intelligence reporting
Contribute to automation efforts by building or refining SOAR playbooks and scripts that improve investigation speed and consistency
Team
We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.
The Security Operations (SecOps) team works to safeguard Robinhood and its customers by identifying, investigating, and responding to security threats. The team monitors production systems, endpoints, and cloud environments, and uses threat intelligence and structured testing to uncover risks before they affect customers. SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and response readiness. The team’s focus is clear: reduce risk, improve visibility, and protect customer trust every day!
As a Security Engineer, Detection & Response, you will strengthen Robinhood’s ability to detect, investigate, and contain security incidents. You will design and improve detection logic, analyze security telemetry across cloud and endpoint systems, and contribute to measurable reductions in false positives and detection gaps. You will work directly with SOC analysts and security engineers to refine investigation workflows and document incident findings. This role is ideal for someone who enjoys hands-on detection engineering and improving how teams respond to real-world threats!
This role is based in our Menlo Park, CA office, with in-person attendance expected at least 3 days per week.
At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.