Responsibilities
- Lead Incident Response: Command security incident response workstreams with decisive leadership, rapidly containing threats, quantifying impact, and communicating effectively with leadership.
- Elevate Detection Rigor: Build, tune, and maintain our global detection catalog across our cloud and kubernetes environments to ensure high precision and actionable alerting.
- Drive Strategic Innovation: Architect our Autonomic Security Operations (ASO) roadmap, integrating AI agents and automated issue discovery to transform response capabilities.
- Code & Architecture Analysis: Read and reason through complex, multi-language codebases to identify security vulnerabilities, evaluate threat vectors, and guide remediation.
- Mentor & Elevate the Team: Foster a culture of technical excellence, trust, and continuous learning by mentoring engineers and bringing charisma to team development.
- On-Call Support: Participate in an on-call rotation (1 week per rotation) to maintain real-time operational readiness.
Requirements
- 8+ years of experience in Detection & Response, Incident Response, or Security Operations.
- Proven Command Presence: Demonstrated success leading complex incident responses under pressure with clear, action-oriented executive communication.
- Deep Cloud & Infrastructure Expertise: Advanced technical experience securing cloud environments with a focus on Kubernetes.
- Code Reasoning Skills: Ability to fluently read, analyze, and reason through code across multiple programming languages to solve complex security challenges.
- Detection Engineering Mastery: Track record of designing, tuning, and operating scalable detection engineering pipelines and SOAR playbooks, as well as leveraging AI technologies to improve speed, scale, and quality.
- AI Experience: Hands-on experience designing and implementing agentic AI workflows for security operations.
- Agility: Ability to thrive in high-growth, fast-paced environments with evolving threat landscapes.
Nice to Have
- Hands-on experience with Threat Hunting, Threat Intelligence, Vulnerability Management, or Red Team operations.
- Background in high-growth fintech, crypto platforms, or managed security service providers.
- Familiarity with DeFi/crypto, blockchain, and related technologies.
Benefits
- Challenging, high-impact work to grow your career.
- Performance-driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching.
- Best-in-class benefits to fuel your work, including 100% paid health insurance for employees with 90% coverage for dependents.
- Lifestyle wallet — a highly flexible benefits spending account for wellness, learning, and more.
- Employer-paid life & disability insurance, fertility benefits, and mental health benefits.
- Time off to recharge including company holidays, paid time off, sick time, parental leave, and more!
- Exceptional office experience with catered meals, events, and comfortable workspaces.
Work Arrangement
On-site — Bellevue, WA, Menlo Park, CA
Additional Information
- This role is based in Bellevue, WA and Menlo Park, CA office(s), with in-person attendance expected at least 3 days per week.
- At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community.
- Our office experience is intentional, energizing, and designed to fully support high-performing teams.
- On-call rotation: 1 week per rotation.