Security Engineer, Detect & Respond
About Betterment
Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays).
About the Role:
As a Security Engineer on the Detect and Respond team at Betterment, you'll help keep our customers and their money safe by building and operating the detection capabilities our security team depends on every day. You'll work alongside experienced engineers on a team that takes software quality seriously, writing reliable alerts, building integrations, contributing to incident response, and improving the on-call experience.
This role is a great fit for an engineer who has a security foundation and wants to grow their craft in a collaborative, engineering-forward environment.
This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment’s total compensation package for employees.
- New York City: $145,000 - $180,000
This job may also be eligible for variable compensation in the form of a company incentive bonus.
A Day in the Life:
- Build and evolve detection and response capabilities across Betterment's infrastructure, with an emphasis on high-signal detection and reliable operational response-
- Help improve our detections over time, using on-call feedback and false positive trends to quiet what's noisy and close the gaps in what we're missing
- Help bring SaaS application logs from across the organization into our SIEM, coordinating with other teams as needed
- Participate in Security On Call cycles, responding to alerts and helping improve triage processes over time
- Contribute to SIEM administration, including lookups, integrations, and alert hygiene
- Build and maintain automations that streamline the on-call experience and reduce manual toil for Security Engineering
- Help the team get real leverage out of AI tooling, building it into how we develop detections and run triage, and being open about where it doesn't pull its weight
- Build detection coverage for our growing AI surface — agent and connector activity, misuse and prompt injection, company data moving through AI tools — much of it detection work without an established playbook yet
- Help build visibility into how AI tools are used across the organization, partnering with our AI Governance and Workforce Security colleagues as that surface grows
- Take part in reviews of new systems and data sources alongside engineering partners, helping work out what telemetry we need and what we'd want to detect before those systems ship
- Support incident response — triage, investigation, and containment — and help keep our response playbooks current as we learn from each one
What We're Looking For:
- We're seeking a team member with 3+ years of experience in security operations or security engineering.
- Experience with common industry SIEM and SOAR platforms, including writing searches and building alerts
- Familiarity with common attacker tactics and techniques, including frameworks like MITRE ATT&CK, and an interest in turning threat behavior into practical detections
- Exposure to incident response — alert triage, investigation, or containment work
- Programming or scripting background; you're comfortable reading and writing code
- Enthusiasm for AI tools and workflows, with the judgment to know where their output needs verifying and the appetite to introduce new capabilities responsibly
- Awareness of the security questions AI systems raise — agent and connector permissions, prompt injection, non-human identity, data leaving through AI tools — or the drive to get up to speed quickly
- Familiarity with cloud environments (AWS) and common SaaS security tools like CrowdStrike or Okta
- An interest in security engineering as a craft — you want to build things that are reliable, well-documented, and easy for others to maintain
- Curiosity and a willingness to dig into new tools, data sources, and problem spaces
- Strong written communication skills — you can write a clear runbook and explain a security concept to a non-technical colleague
Join a team built on these core values
We change lives
Be a part of a community of innovators working to transform financial outcomes for real people. Your work will make an impact, always laddering up to our mission; to empower people to build wealth with confidence and ease.
We set audacious goals
We set them for the company, our customers, and ourselves, and we won’t stop until we reach them. We don’t just show up; we give our all, then celebrate our wins.
We value all perspectives
When we collaborate, we're at our best. We believe diverse perspectives lead to better outcomes and strive to uphold our supportive and inclusive community.
We simplify financial services
We’re financial services pioneers, always finding new ways to improve, optimize, and enhance. Constant improvement is in our DNA.
Our Commitment to Your Total Well-being:
- We offer a competitive suite of benefits, including medical, dental, and vision coverage; life and AD&D insurance; short- and long-term disability; infertility support and WPATH-aligned transgender health benefits; an Employee Assistance Program (EAP); transit benefits and FSA and HSA options
- Ownership: Equity for all employees, including new hire and refresher grants.
- Time: Flexible paid time off, paid parental leave, and a fully paid four-week sabbatical in your sixth year.
- Growth: Company-paid professional coaching for all employees.
- Wealth: Day-one 401(k) match plus matching on qualified student loan payments.
What happens next
We’ll take a few weeks to review all applications. If we’d like to spend more time with you, we’ll reach out to arrange next steps, which will include 3-4 sets of meetings with your future colleagues.
In the interview process, we’ll look to learn more about your skills, experiences, capabilities, and motivators. Many of our questions will be aimed at understanding how you might operate here at Betterment. Depending on the role, we may ask you to complete a case study exercise or technical assessments, as we want to collect a robust set of data points to better inform our decisions.
On average, it takes us around 3-5 weeks to make a hiring decision, depending on your availability and sense of urgency. As a best practice, we aim to interview at least 2-3 final round candidates before making a hiring decision. Please note that, as we usually receive an overwhelming number of applications for open positions, we’re unable to offer individual feedback during the interview process.
We recognize that interviewing for a new role is a big deal. We appreciate you considering Betterment as the next step in your career, and our Recruiting Team is here to support and advocate for you through the interview process!
Betterment is dedicated to providing accommodations to candidates upon request. If you need accommodations at any point throughout the interview process, please reach out to your recruiter.
Please note that in any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Come join us!
We’re an equal opportunity employer and comply with all applicable federal, state, and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees, applicants, or any other covered persons because of race, color, religion, creed, national origin or ancestry, ethnicity, sex, gender (including gender nonconformity and status as a transgender or transsexual individual), sexual orientation, marital status, age, physical or mental disability, citizenship, past, current or prospective service in the uniformed services, predisposing genetic characteristic, domestic violence victim status, arrest records, or any other characteristic protected under applicable federal, state or local law.