Robinhood Logo

Robinhood

Security Operations Detection & Response Technical Lead

Posted 4 Hours Ago
Be an Early Applicant
Toronto, ON
Senior level
Toronto, ON
Senior level
As the Detection & Response Tech Lead, you will manage incident response efforts, oversee detection engineering, track metrics for continuous improvement, and foster team development while collaborating with stakeholders to drive security initiatives.
The summary above was generated by AI
Join a leading fintech company that’s democratizing finance for all.

Robinhood Markets was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood and its subsidiaries and affiliates are lowering barriers and providing greater access to financial information. Together, we are building products and services that help create a financial system everyone can participate in.

With growth as the top priority...

The business is seeking curious, growth-minded thinkers to help shape our vision, structures and systems; playing a key-role as we launch into our ambitious future. If you’re invigorated by our mission, values, and drive to change the world — we’d love to have you apply.

About the Team + Role

The Security Operations (SecOps) team’s mission is to proactively safeguard Robinhood and its customers. SecOps is responsible for monitoring, detecting, and responding to security incidents in real time. We do this by staying ahead of threats through gathering threat intelligence, conducting Red Team operations, and working with external security researchers to identify and mitigate potential risks before they can be exploited. By maintaining a robust defense posture, the team protects Robinhood customers from ever-evolving cyber threats.

As the Detection & Response Tech Lead, you will be a pivotal part of our Security Operations team, leading and evolving our Detection & Response capabilities to detect, respond to, and mitigate threats effectively. You’ll have the opportunity to drive critical response efforts, build robust detection pipelines, and foster a culture of trust, resilience, collaboration and continuous improvement within the team. This role combines technical leadership, team mentorship, and close partnership with stakeholders across Security Operations and the wider organization.

The role is located in the office location(s) listed on this job description which will align with our in-office working environment. Please connect with your recruiter for more information regarding our in-office philosophy and expectations.

What You’ll Do

  • Incident Response Leadership: Lead and manage incident response efforts, providing clear direction and authority during high-stakes situations. Efficiently organize and drive response work streams, ensuring thorough and timely resolution. Provide high-quality and comprehensive post-incident reporting and insights to guide future improvements.
  • Detection Engineering & Development: Oversee the development and codification of high-quality, scalable detections. Collaborate with business stakeholders to prioritize detection engineering efforts to address top risks and threats. Work closely with SOC analysts and other security stakeholders to build effective detection pipelines, utilizing real-time feedback and metrics to refine our detection strategy.
  • Metrics & Continuous Improvement: Establish and track metrics on detection efficacy, response speed, and continuous improvement initiatives. Implement strategies to measure and enhance detection accuracy, reduce false positives, and optimize response workflows.
  • Stakeholder Management & Communication: Serve as a primary point of contact for Detection & Response. Build and maintain trusted relations with key stakeholders, communicating security events, strategy updates, and progress on team initiatives. Ensure clear, concise, and timely updates to all relevant parties during and post-incident.
  • Team Development & Leadership: Mentor and develop a high-performing Detection & Response team, providing coaching, feedback, and growth opportunities. Drive team capability-building through structured training, hands-on learning, and by establishing best practices for incident handling, detection engineering, and collaboration.

What You Bring

  • Experience with the principles and practices of modern security operations frameworks such as Autonomic Security Operations (ASO).
  • Proven track record in incident response, with deep expertise in managing and driving incident workstreams to timely resolution.
  • Strong technical experience in detection engineering, including detection codification, pipeline development, tuning & coverage strategies for accuracy and efficiency.
  • Demonstrated capability to measure and improve detection effectiveness using metrics and data analysis.
  • Exceptional crisis leadership and authority under pressure; communicates clearly, concisely, and effectively with technical and non-technical stakeholders alike.
  • Skilled in building trust, credibility, and strong relations with stakeholders, maintaining a professional, positive, and solution-oriented attitude.
  • Proven team leadership experience, with the ability to inspire, coach, and develop team members, helping them level-up technically and professionally.

Bonus

  • Hands-on experience developing and deploying SOAR playbooks to automated detection and response workflows.
  • Experience using and configuring robust Case Management systems to effectively collect and store incident details and data.
  • Proficient in software development, with a focus on creating secure and efficient code for detection and response solutions.

Our team is committed to providing an inclusive and welcoming interview experience for all candidates. If you require a specific accommodation during the application or interview process due to a physical or mental condition, please complete this Applicant Accommodation Form to notify our team. The form should only be completed if you need a specific accommodation.

Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. The expected salary range for this role is based on the location where the work will be performed. This role is also eligible to participate in a Robinhood bonus plan and Robinhood’s equity plan.

Toronto, ON

$161,500$190,000 CAD

Click here to learn more about available Benefits, which vary by region and Robinhood entity.

We’re looking for more growth-minded and collaborative people to be a part of our journey in democratizing finance for all. If you’re ready to give 100% in helping us achieve our mission—we’d love to have you apply even if you feel unsure about whether you meet every single requirement in this posting. At Robinhood, we're looking for people invigorated by our mission, values, and drive to change the world, not just those who simply check off all the boxes.

Robinhood embraces a diversity of backgrounds and experiences and provides equal opportunity for all applicants and employees. We are dedicated to building a company that represents a variety of backgrounds, perspectives, and skills. We believe that the more inclusive we are, the better our work (and work environment) will be for everyone. Additionally, Robinhood provides reasonable accommodations for candidates on request and respects applicants' privacy rights. Please review the specific Robinhood Privacy Policy applicable to the country where you are applying.

Similar Jobs

Be an Early Applicant
2 Days Ago
Toronto, ON, CAN
Hybrid
7,000 Employees
Mid level
7,000 Employees
Mid level
Cloud • Insurance • Professional Services • Analytics • Cybersecurity
The Risk Control Consultant conducts risk assessments, evaluates and recommends risk improvement strategies for clients while collaborating with underwriting and senior staff. Responsibilities include performing loss analysis, developing client relationships, leading training programs, and identifying new business opportunities. This role requires excellent communication, analytical, and organizational skills.
Be an Early Applicant
2 Days Ago
Toronto, ON, CAN
Hybrid
7,000 Employees
Senior level
7,000 Employees
Senior level
Cloud • Insurance • Professional Services • Analytics • Cybersecurity
The Consulting Director will lead and manage IT security workflows for CNA Canada, acting as a tactical advisor for project teams. Responsibilities include developing security standards, conducting security assessments, guiding cloud application deployments, and identifying vulnerabilities while serving as a liaison between IT leadership and the global security organization.
Be an Early Applicant
2 Days Ago
Aurora, ON, CAN
Hybrid
171,000 Employees
Internship
171,000 Employees
Internship
Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
As an IT Co-op Student at Magna, you'll assist in providing technical support, troubleshoot IT-related issues, and help with the installation and maintenance of computer systems. You will collaborate with IT professionals to optimize technology operations and conduct research on emerging technologies.

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account