Security Engineer, Detect & Respond at Betterment in Betterment HQ - New York City
- Company: Betterment
- Location: Betterment HQ - New York City
- Posted: Sep 24, 2026
- Type: Full-time
- Salary: $145,000 - $180,000
- Experience: 3+ years
- Visa sponsorship available
Overview
As a Security Engineer on the Detect and Respond team at Betterment, you'll help keep our customers and their money safe by building and operating the detection capabilities our security team depends on every day. You'll work alongside experienced engineers on a team that takes software quality seri…
Job description
- As a Security Engineer on the Detect and Respond team at Betterment, you'll help keep our customers and their money safe by building and operating the detection capabilities our security team depends on every day. You'll work alongside experienced engineers on a team that takes software quality seriously, writing reliable alerts, building integrations, contributing to incident response, and improving the on-call experience.
- This role is a great fit for an engineer who has a security foundation and wants to grow their craft in a collaborative, engineering-forward environment.
- This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment’s total compensation package for employees.
- New York City: $145,000 - $180,000
- This job may also be eligible for variable compensation in the form of a company incentive bonus.
Responsibilities
- - Build and evolve detection and response capabilities across Betterment's infrastructure, with an emphasis on high-signal detection and reliable operational response-
- - Help improve our detections over time, using on-call feedback and false positive trends to quiet what's noisy and close the gaps in what we're missing
- - Help bring SaaS application logs from across the organization into our SIEM, coordinating with other teams as needed
- - Participate in Security On Call cycles, responding to alerts and helping improve triage processes over time
- - Contribute to SIEM administration, including lookups, integrations, and alert hygiene
- - Build and maintain automations that streamline the on-call experience and reduce manual toil for Security Engineering
- - Help the team get real leverage out of AI tooling, building it into how we develop detections and run triage, and being open about where it doesn't pull its weight
- - Build detection coverage for our growing AI surface — agent and connector activity, misuse and prompt injection, company data moving through AI tools — much of it detection work without an established playbook yet
- - Help build visibility into how AI tools are used across the organization, partnering with our AI Governance and Workforce Security colleagues as that surface grows
- - Take part in reviews of new systems and data sources alongside engineering partners, helping work out what telemetry we need and what we'd want to detect before those systems ship
- - Support incident response — triage, investigation, and containment — and help keep our response playbooks current as we learn from each one
Requirements
- - We're seeking a team member with 3+ years of experience in security operations or security engineering.
- - Experience with common industry SIEM and SOAR platforms, including writing searches and building alerts
- - Familiarity with common attacker tactics and techniques, including frameworks like MITRE ATT&CK, and an interest in turning threat behavior into practical detections
- - Exposure to incident response — alert triage, investigation, or containment work
- - Programming or scripting background; you're comfortable reading and writing code
- - Enthusiasm for AI tools and workflows, with the judgment to know where their output needs verifying and the appetite to introduce new capabilities responsibly
- - Awareness of the security questions AI systems raise — agent and connector permissions, prompt injection, non-human identity, data leaving through AI tools — or the drive to get up to speed quickly
- - Familiarity with cloud environments (AWS) and common SaaS security tools like CrowdStrike or Okta
- - An interest in security engineering as a craft — you want to build things that are reliable, well-documented, and easy for others to maintain
- - Curiosity and a willingness to dig into new tools, data sources, and problem spaces
- - Strong written communication skills — you can write a clear runbook and explain a security concept to a non-technical colleague
Skills
Required
- Security operations
- Security engineering
- SIEM and SOAR platforms
- Writing searches and building alerts
- Programming or scripting
- AI tools and workflows
- Cloud environments (AWS)
- SaaS security tools (CrowdStrike, Okta)
- Strong written communication
Benefits
- We offer a competitive suite of benefits, including medical, dental, and vision coverage; life and AD&D insurance; short- and long-term disability; infertility support and WPATH-aligned transgender health benefits; an Employee Assistance Program (EAP); transit benefits and FSA and HSA options
- Ownership: Equity for all employees, including new hire and refresher grants.
- Time: Flexible paid time off, paid parental leave, and a fully paid four-week sabbatical in your sixth year.
- Growth: Company-paid professional coaching for all employees.
- Wealth: Day-one 401(k) match plus matching on qualified student loan payments.
About Betterment
Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays). We change lives Be a part of a community of innovators working to transform financial outcomes for real people. Your work will make an impact, always laddering up to our mission; to empower people to build wealth with confidence and ease. We set audacious goals We set them for the company, our customers, and ourselves, and we won’t stop until we reach them. We don’t just show up; we give our all, then celebrate our wins. We value all perspectives When we collaborate, we're at our best. We believe diverse perspectives lead to better outcomes and strive to uphold our supportive and inclusive community. We simplify financial services We’re financial services pioneers, always finding new ways to improve, optimize, and enhance. Constant improvement is in our DNA.