Enable job alerts via email!

Security Developer, Detection & Response

Robinhood

Toronto

On-site

CAD 70,000 - 110,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a leading fintech company dedicated to democratizing finance as a Detection & Response Engineer. In this pivotal role, you will enhance the company's ability to detect and respond to security incidents, collaborating with various teams to develop high-quality detections and improve response workflows. Your expertise in security operations and incident response will be crucial in safeguarding the organization against ever-evolving cyber threats. This innovative firm values growth-minded thinkers who are passionate about creating a secure financial environment for all. If you're ready to make a significant impact in the world of finance, this opportunity is for you.

Qualifications

  • 2-4 years of experience in security operations, detection engineering, or incident response.
  • Strong understanding of log analysis and detection tuning within security tools.

Responsibilities

  • Investigate security alerts and incidents, conduct log analysis, and mitigate threats.
  • Develop and fine-tune detection logic to improve visibility into security threats.

Skills

Security Operations
Detection Engineering
Incident Response
Log Analysis
Threat Monitoring
Problem-Solving

Tools

SIEMs
EDRs
SOAR tools
AWS
Okta
Kubernetes
Google Workspace

Job description

Security Developer, Detection & Response

Toronto, ON

Join a leading fintech company that’s democratizing finance for all.

Robinhood Markets was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood and its subsidiaries and affiliates are lowering barriers and providing greater access to financial information. Together, we are building products and services that help create a financial system everyone can participate in.

With growth as the top priority...

The business is seeking curious, growth-minded thinkers to help shape our vision, structures and systems; playing a key-role as we launch into our ambitious future. If you’re invigorated by our mission, values, and drive to change the world — we’d love to have you apply.

About the Role + Team

The Security Operations (SecOps) team’s mission is to proactively safeguard Robinhood and its customers. SecOps is responsible for monitoring, detecting, and responding to security incidents in real time. We do this by staying ahead of threats through gathering threat intelligence, conducting Red Team operations, and working with external security researchers to identify and mitigate potential risks before they can be exploited. By maintaining a robust defense posture, the team protects Robinhood customers from ever-evolving cyber threats.

As a Detection & Response Engineer, you will focus on strengthening Robinhood’s ability to detect, investigate, and respond to security incidents. You’ll work on developing high-quality detections, improving response workflows, and collaborating with security teams to reduce detection gaps. This role requires technical expertise in security operations, detection engineering, and incident response while working closely with SOC analysts, engineers, and security stakeholders.

The role is located in the office location(s) listed on this job description which will align with our in-office working environment. Please connect with your recruiter for more information regarding our in-office philosophy and expectations.

What you’ll do
  • Incident Detection & Response - Investigate Security alerts and incidents, conduct log analysis, and collaborate with teams to mitigate threats.
  • Detection Engineering - Develop and fine-tune detection logic to improve visibility into security threats, reducing false positives and detection gaps.
  • Triage & Investigation - Analyze security signals, correlate data across multiple sources, and determine response actions.
  • Threat Monitoring & Analysis - Continuously monitor, evaluate, and improve security detections based on evolving threats and real-time feedback from investigations.
  • Automation & Process Improvements - Assist in automating detection workflows and enhancing security operations efficiency through scripting or SOAR tools.
  • Incident Documentation & Postmortems - Contribute to post-incident reports, helping identify areas for improvement in detections, response, and remediation strategies.
What you bring
  • 2-4 years of experience in security operations, detection engineering, or incident response.
  • Strong understanding of log analysis, detection tuning, and alert triage within security tools (SIEMs, EDRs, cloud security platforms).
  • Experience with writing detections using query languages.
  • Familiarity with threat hunting, log correlation, and investigation techniques across cloud and endpoint environments.
  • Ability to analyze security telemetry, identify attack patterns and contribute to continuous detection improvements.
  • Strong problem-solving skills and ability to collaborate across security teams in fast-paced incident response scenarios.
Nice to haves
  • Hands-on experience developing and deploying SOAR playbooks to automate detection and response workflows.
  • Familiarity with AWS, Okta, Kubernetes, and/or Google Workspace security monitoring tools.
  • Proficient in software development, with a focus on creating secure and efficient code for detection and response solutions.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Developer, Detection & Response

Robinhood

Toronto

On-site

CAD 70’000 - 110’000

30+ days ago

Security Developer, Detection & Response

Robinhood

Toronto

On-site

CAD 70’000 - 110’000

30+ days ago

TEST - Security engineer – SOC (VIE Toronto, Canada – 2 years)

Soprasteria

Toronto

On-site

CAD 70’000 - 110’000

30+ days ago