Security Engineer, Detection & Response
Company: Robinhood
Location: Menlo Park
Posted on: April 1, 2026
|
|
|
Job Description:
Join us in building the future of finance. Our mission is to
democratize finance for all. An estimated $124 trillion of assets
will be inherited by younger generations in the next two decades.
The largest transfer of wealth in human history. If you’re ready to
be at the epicenter of this historic cultural and financial shift,
keep reading. About the team role We are building an elite team,
applying frontier technologies to the world’s biggest financial
problems. We’re looking for bold thinkers. Sharp problem-solvers.
Builders who are wired to make an impact. Robinhood isn’t a place
for complacency, it’s where ambitious people do the best work of
their careers. We’re a high-performing, fast-moving team with
ethics at the center of everything we do. Expectations are high,
and so are the rewards. The Security Operations (SecOps) team works
to safeguard Robinhood and its customers by identifying,
investigating, and responding to security threats. The team
monitors production systems, endpoints, and cloud environments, and
uses threat intelligence and structured testing to uncover risks
before they affect customers. SecOps partners closely with
engineering and infrastructure teams to strengthen detection
coverage and response readiness. The team’s focus is clear: reduce
risk, improve visibility, and protect customer trust every day! As
a Security Engineer, Detection & Response, you will strengthen
Robinhood’s ability to detect, investigate, and contain security
incidents. You will design and improve detection logic, analyze
security telemetry across cloud and endpoint systems, and
contribute to measurable reductions in false positives and
detection gaps. You will work directly with SOC analysts and
security engineers to refine investigation workflows and document
incident findings. This role is ideal for someone who enjoys
hands-on detection engineering and improving how teams respond to
real-world threats! This role is based in our Menlo Park, CA
office, with in-person attendance expected at least 3 days per
week. At Robinhood, we believe in the power of in-person work to
accelerate progress, spark innovation, and strengthen community.
Our office experience is intentional, energizing, and designed to
fully support high-performing teams. What you’ll do Investigate
security alerts across SIEM, EDR, and cloud security platforms,
perform log analysis, and coordinate containment or remediation
steps with engineering partners Develop, test, and tune detection
rules using query languages to improve signal quality and reduce
false positives Correlate data from multiple telemetry sources to
identify attack patterns and determine appropriate response actions
Monitor emerging threats and update detection logic based on
investigation findings and threat intelligence reporting Contribute
to automation efforts by building or refining SOAR playbooks and
scripts that improve investigation speed and consistency Document
incidents and contribute to post-incident reviews with clear
findings and recommended improvements to detection and response
processes What you bring 2–4 years of experience in security
operations, detection engineering, or incident response Experience
analyzing logs and tuning alerts within SIEMs, EDR platforms, and
cloud security tools Experience writing detections using query
languages (e.g., SQL-like, KQL, or similar) Familiarity with threat
hunting and investigation techniques across cloud and endpoint
environments Ability to analyze security telemetry, identify
patterns of malicious activity, and recommend practical
improvements Clear written and verbal communication skills when
documenting incidents and collaborating with technical teams Nice
to have: Our ambitious roadmap requires a great culture shaped by
exceptional leaders. Here’s what we expect from them: Experience
developing and deploying SOAR playbooks to automate detection and
response workflows Familiarity with AWS, Okta, Kubernetes, and/or
Google Workspace security monitoring tools Experience writing
software to support detection and response tooling with a focus on
secure, maintainable code Experience in building Agentic workflows,
optimizing workflows with Generative AI What we offer Challenging,
high-impact work to grow your career. Performance-driven
compensation with multipliers for outsized impact, bonus programs,
equity ownership, and 401(k) matching. Best-in-class benefits to
fuel your work, including 100% paid health insurance for employees
with 90% coverage for dependents. Lifestyle wallet — a highly
flexible benefits spending account for wellness, learning, and
more. Employer-paid life & disability insurance, fertility
benefits, and mental health benefits. Time off to recharge
including company holidays, paid time off, sick time, parental
leave, and more! Exceptional office experience with catered meals,
events, and comfortable workspaces. In addition to the base pay
range listed below, this role is also eligible for bonus
opportunities equity benefits. Base pay for the successful
applicant will depend on a variety of job-related factors, which
may include education, training, experience, location, business
needs, or market demands. The expected base pay range for this role
is based on the location where the work will be performed and is
aligned to one of 3 compensation zones. For other locations not
listed, compensation can be discussed with your recruiter during
the interview process. Base Pay Range: Zone 1 (Menlo Park, CA; New
York, NY; Bellevue, WA; Washington, DC) $157,000 - $185,000 USD
Zone 2 (Denver, CO; Westlake, TX; Chicago, IL) $139,000 - $163,000
USD Zone 3 (Lake Mary, FL; Clearwater, FL; Gainesville, FL)
$122,000 - $144,000 USD Click here to learn more about our Total
Rewards, which vary by region and entity. If our mission energizes
you and you’re ready to build the future of finance, we look
forward to seeing your application. Robinhood provides equal
opportunity for all applicants, offers reasonable accommodations
upon request, and complies with applicable equal employment and
privacy laws. Inclusion is built into how we hire and
work—welcoming different backgrounds, perspectives, and experiences
so everyone can do their best. Please review the for your country
of application.
Keywords: Robinhood, Concord , Security Engineer, Detection & Response, IT / Software / Systems , Menlo Park, California