Security Engineer, Detect & Respond
Job Description
<h2>About Betterment</h2> <p><a href="http://www.betterment.com/">Betterment</a> is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays).</p> <h2><strong>About the Role:</strong></h2> <p>As a Security Engineer on the Detect and Respond team at Betterment, you'll help keep our customers and their money safe by building and operating the detection capabilities our security team depends on every day. You'll work alongside experienced engineers on a team that takes software quality seriously, writing reliable alerts, building integrations, contributing to incident response, and improving the on-call experience.</p> <p>This role is a great fit for an engineer who has a security foundation and wants to grow their craft in a collaborative, engineering-forward environment.</p> <p>This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment’s total compensation package for employees.</p> <ul> <li>New York City: $145,000 - $180,000</li> </ul> <p>This job may also be eligible for variable compensation in the form of a company incentive bonus.</p> <h2><strong>A Day in the Life:</strong></h2> <p>- Build and evolve detection and response capabilities across Betterment's infrastructure, with an emphasis on high-signal detection and reliable operational response-</p> <p>- Help improve our detections over time, using on-call feedback and false positive trends to quiet what's noisy and close the gaps in what we're missing<br><br>- Help bring SaaS application logs from across the organization into our SIEM, coordinating with other teams as needed</p> <p>- Participate in Security On Call cycles, responding to alerts and helping improve triage processes over time</p> <p>- Contribute to SIEM administration, including lookups, integrations, and alert hygiene</p> <p>- Build and maintain automations that streamline the on-call experience and reduce manual toil for Security Engineering</p> <p>- Help the team get real leverage out of AI tooling, building it into how we develop detections and run triage, and being open about where it doesn't pull its weight</p> <p>- Build detection coverage for our growing AI surface — agent and connector activity, misuse and prompt injection, company data moving through AI tools — much of it detection work without an established playbook yet</p> <p>- Help build visibility into how AI tools are used across the organization, partnering with our AI Governance and Workforce Security colleagues as that surface grows</p> <p>- Take part in reviews of new systems and data sources alongside engineering partners, helping work out what telemetry we need and what we'd want to detect before those systems ship</p> <p>- Support incident response — triage, investigation, and containment — and help keep our response playbooks current as we learn from each one</p> <h2>What We're Looking For:</h2> <p>- We're seeking a team member with 3+ years of experience in security operations or security engineering.</p> <p>- Experience with common industry SIEM and SOAR platfor