Security Engineer, Detect & Respond
Core
Build and evolve high-signal detection and response capabilities across Betterment's infrastructure, focusing on SIEM administration, alert triage, and automations to reduce manual toil.
Role type
Security Engineer (Detect & Respond)
Builds
Detection coverage and organizational visibility for AI tools, agents, connectors, prompt injection, non-human identities, and data movement.
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | infrastructure
Required skills
SIEM and SOAR platform experience, incident response (alert triage, investigation, containment), programming/scripting, AWS familiarity, SaaS security tools knowledge (CrowdStrike, Okta), MITRE ATT&CK framework awareness
Preferred skills
Experience with AI tool security (agent/connector permissions, prompt injection, data exfiltration), building reliable and maintainable security systems
Technologies
SIEM, SOAR, AWS, CrowdStrike, Okta
Responsibilities
Build and evolve high-signal detection and response capabilities; Improve detections using on-call feedback and false-positive trends; Bring SaaS application logs into the SIEM; Participate in Security On Call cycles, alert triage, investigations, and containment; Administer SIEM lookups, integrations, and alert hygiene; Build automations that improve the on-call experience; Develop detection coverage for AI tools and non-human identities; Review new systems to define telemetry and detection requirements; Maintain incident-response playbooks
Seniority
Mid-level (3+ years experience), hands-on IC