Security Engineer, Detect & Respond
Betterment · Betterment HQ - New York City
- Junior
- Full-time
- $145,000 – $180,000
- Posted 2026-09-23
- Confirmed live on 25 September 2026
Job description
About Betterment
Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays).
About the Role:
As a Security Engineer on the Detect and Respond team at Betterment, you'll help keep our customers and their money safe by building and operating the detection capabilities our security team depends on every day. You'll work alongside experienced engineers on a team that takes software quality seriously, writing reliable alerts, building integrations, contributing to incident response, and improving the on-call experience.
This role is a great fit for an engineer who has a security foundation and wants to grow their craft in a collaborative, engineering-forward environment.
This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment’s total compensation package for employees.
• New York City: $145,000 - $180,000
This job may also be eligible for variable compensation in the form of a company incentive bonus.
A Day in the Life:
- Build and evolve detection and response capabilities across Betterment's infrastructure, with an emphasis on high-signal detection and reliable operational response-
- Help improve our detections over time, using on-call feedback and false positive trends to quiet what's noisy and close the gaps in what we're missing
- Help bring SaaS application logs from across the organization into our SIEM, coordinating with other teams as needed
- Participate in Security On Call cycles, responding to alerts and helping improve triage processes over time
- Contribute to SIEM administration, including lookups, integrations, and alert hygiene
- Build and maintain automations that streamline the on-call experience and reduce manual toil for Security Engineering
- Help the team get real leverage out of AI tooling, building it into how we develop detections and run triage, and being open about where it doesn't pull its weight
- Build detection coverage for our growing AI surface — agent and connector activity, misuse and prompt injection, company data moving through AI tools — much of it detection work without an established playbook yet
- Help build visibility into how AI tools are used across the organization, partnering with our AI Governance and Workforce Security colleagues as that surface grows
- Take part in reviews of new systems and data sources alongside engineering partners, helping work out what telemetry we need and what we'd want to detect before those systems ship
- Support incident response — triage, investigation, and containment — and help keep our response playbooks current as we learn from each one
What We're Looking For:
- We're seeking a team member with 3+ years of experience in security operations or security engineering.
- Experience with common industry SIEM and SOAR platforms, including writing searches and building alerts
- Familiarity with common attacker tactics and techniques, including frameworks like MITRE ATT&CK, and an interest in turning threat behavior into practical detections
- Exposure to incident response — alert triage, investigation, or containment work
- Programming or scripting background; you're comfortable reading and writing code
- Enthusiasm for AI tools and workflows, with the judgment to know where their output needs verifying and the appetite to introduce new capabilities responsibly
- Awareness of the security questions AI systems raise — agent and connector permissions, prompt injection, non-human identity, data leaving through AI tools — or the drive to get up to speed quickly
- Familiarity with cloud environments (AWS) and common SaaS security tools like CrowdStrike or Okta
- An interest in security engineering as a craft — you want to build things that are reliable, well-documented, and easy for others to maintain
- Curiosity and a willingness to dig into new tools, data sources, and problem spaces
- Strong written communication skills — you can write a clear runbook and explain a security concept to a non-technical colleague
Join a team built on these core values
We change lives
Be a part of a community of innovators working to transform financial outcomes for real people. Your work will make an impact, always laddering up to our mission; to empower people to build wealth with confidence and ease.
We set audacious goals
We set them for the company
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Betterment
- Sr Engineering Manager – API & Auth Platform · Betterment HQ - New York City
- Sr. Software Engineer – API & Auth Platform · Betterment HQ - New York City
- Sr. Software Engineer · Betterment HQ - New York City
- Sr. Engineering Manager · Betterment HQ - New York City
- Sr. Manager, Channel Partnerships · Betterment HQ - New York City
- Business Development Representative · Betterment HQ - New York City
- Revenue Operations Manager - Revenue Planning & Insights · Betterment HQ - New York City
- Payroll & Benefits Coordinator · Betterment HQ - New York City