CronJobs

security jobs

Security Engineer, Detect & Respond

Betterment · Betterment HQ - New York City

hybridmid$145,000–$180,000Posted Sep 23, 2026AWSSIEMSOARMITRE ATT&CKCrowdStrikeOkta

Apply on the employer site

About this role

**Security Engineer, Detect & Respond — Betterment** **About Betterment** Betterment is a leading, technology-driven financial services company offering investing, savings, and retirement solutions for retail investors and investment advisors, plus financial wellness solutions (including a 401(k) for small and medium-sized businesses). We’re headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays). **About the Role** As a Security Engineer on the Detect and Respond team, you’ll help keep customers and their money safe by building and operating the detection capabilities the security team relies on daily. You’ll work with experienced engineers focused on software quality—writing reliable alerts, building integrations, contributing to incident response, and improving the on-call experience. **A Day in the Life** - Build and evolve detection and response capabilities across Betterment’s infrastructure, emphasizing high-signal detection and reliable operational response - Improve detections over time using on-call feedback and false positive trends to reduce noise and close coverage gaps - Bring SaaS application logs into the SIEM, coordinating with other teams as needed - Participate in Security On Call cycles: respond to alerts and improve triage processes - Contribute to SIEM administration (lookups, integrations, and alert hygiene) - Build and maintain automations to streamline on-call and reduce manual toil - Use AI tooling to increase leverage in detection development and triage—while being transparent about where it doesn’t help - Expand detection coverage for the growing AI surface (agent/connector activity, misuse, prompt injection, and company data movement through AI tools) - Improve visibility into how AI tools are used across the organization, partnering with AI Governance and Workforce Security - Review new systems and data sources with engineering partners to determine needed telemetry and what to detect before launch - Support incident response (triage, investigation, containment) and keep playbooks current **What We’re Looking For** - 3+ years of experience in security operations or security engineering - Experience with SIEM/SOAR platforms, including writing searches and building alerts - Familiarity with attacker tactics/techniques (e.g., MITRE ATT&CK) and interest in turning threat behavior into practical detections - Exposure to incident response (alert triage, investigation, or containment) - Programming/scripting background; comfortable reading and writing code - Enthusiasm for AI tools and workflows, with judgment to verify outputs and introduce capabilities responsibly - Awareness of security questions raised by AI (permissions, prompt injection, non-human identity, data leaving via AI tools) or drive to ramp quickly - Familiarity with cloud environments (AWS) and SaaS security tools (e.g., CrowdStrike, Okta) - Interest in security engineering as a craft: reliable, well-documented, maintainable systems - Curiosity to explore new tools, data sources, and problem spaces - Strong written communication skills (e.g., clear runbooks and explaining concepts to non-technical colleagues) **Location & Compensation (NYC)** - Hybrid NYC-based role (four days/week in-office) - Base salary range (New York City): **$145,000 – $180,000** - May also be eligible for variable compensation via a company incentive bonus **What Happens Ne

Listing freshness

CronJobs last confirmed this listing 3h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord