Security Testing Engineer
Robinhood
Join us in building the future of finance.
Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading.
We are building an elite team, applying frontier technologies to the world’s biggest financial problems. Builders who are wired to make an impact. The Security Operations (SecOps) team works to safeguard Robinhood and its customers by identifying, investigating, and responding to security threats. The team monitors production systems, endpoints, and cloud environments, and uses threat intelligence and structured testing to uncover risks before they affect customers. The team’s focus is clear: reduce risk, improve visibility, and protect customer trust every day!
As a Security Engineer, Detection & Response, you will strengthen Robinhood’s ability to detect, investigate, and contain security incidents. You will design and improve detection logic, analyze security telemetry across cloud and endpoint systems, and contribute to measurable reductions in false positives and detection gaps. You will work directly with SOC analysts and security engineers to refine investigation workflows and document incident findings. The role is located in the office location(s) listed on this job description which will align with our in-office working environment. Please connect with your recruiter for more information regarding our in-office philosophy and expectations.
Investigate security alerts across SIEM, EDR, and cloud security platforms, perform log analysis, and coordinate containment or remediation steps with engineering partners
Develop, test, and tune detection rules using query languages to improve signal quality and reduce false positives
Correlate data from multiple telemetry sources to identify attack patterns and determine appropriate response actions
Monitor emerging threats and update detection logic based on investigation findings and threat intelligence reporting
Contribute to automation efforts by building or refining SOAR playbooks and scripts that improve investigation speed and consistency
2–4 years of experience in security operations, detection engineering, or incident response
- Experience analyzing logs and tuning alerts within SIEMs, EDR platforms, and cloud security tools
- Experience writing detections using query languages (e.g., SQL-like, KQL, or similar)
- Familiarity with threat hunting and investigation techniques across cloud and endpoint environments
- Ability to analyze security telemetry, identify patterns of malicious activity, and recommend practical improvements
- Clear written and verbal communication skills when documenting incidents and collaborating with technical teams
Familiarity with AWS, Okta, Kubernetes, and/or Google Workspace security monitoring tools
Experience writing software to support detection and response tooling with a focus on secure, maintainable code
Experience in building Agentic workflows, optimizing workflows with Generative AI
AI Usage Disclosure: Robinhood uses artificial intelligence (AI) tools to support parts of our recruiting process. These tools enhance the efficiency and consistency of our hiring process; In addition to the base pay range listed below, this role is also eligible for bonus opportunities + equity + benefits.
Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. 136,000 - $160,000 CAD
If our mission energizes you and you’re ready to build the future of finance, we look forward to seeing your application.
Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with applicable equal employment and privacy laws. Inclusion is built into how we hire and work—welcoming different backgrounds, perspectives, and experiences so everyone can do their best.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Testing Engineer. Be the first to apply!
- product security engineer Toronto, ON
- security engineering manager Toronto, ON
- physical security engineer Toronto, ON
- aws security engineer Toronto, ON
- security engineer remote Toronto, ON
- product security engineer
- security engineering manager
- cloud security engineer
- physical security engineer
- aws security engineer
