Engineering Manager, Detect & Respond

Betterment Betterment · Fintech · New York, NY · Engineering

Engineering Manager for Detection Engineering at Betterment, leading a team responsible for building and operating security detection capabilities across cloud infrastructure, SaaS, and product. The role involves owning the strategy and execution for threat detection, partnering with various security and engineering teams, and ensuring operational rigor. Key responsibilities include detection program strategy, quality, threat modeling, incident response leadership, team management, and external SOC partnership. Requires 7+ years in security engineering/operations with 2+ years managing security/detection teams, strong SIEM and detection-as-code expertise, and experience with cloud environments.

What you'd actually do

  1. Help own, drive, and execute the Detection Engineering roadmap, balancing new capability development with the operational health of existing systems, including driving threat-informed, TTP-aligned detection development across the team.
  2. Work with engineers and the business to maintain and refine the measurement framework for detection health, coverage, precision, false positive rates, and safe rollout practices, holding the team to a continuously improving bar.
  3. Set expectations for how the team engages with engineering and infrastructure partners on new systems, ensuring D&R requirements (telemetry, threat models, response playbooks) are defined before systems ship.
  4. Lead or oversee the team's response to security incidents, ensuring clear ownership, fast time-to-contain, and strong post-incident review practices.
  5. Lead, mentor, and grow a team of detection engineers, investing in their craft and careers.

Skills

Required

  • Security engineering
  • Security operations
  • Team management
  • Detection engineering
  • SIEM platforms (Splunk preferred)
  • Detection-as-code practices
  • Threat-informed detection development
  • MITRE ATT&CK framework
  • Incident response
  • External SOC management
  • AWS
  • CrowdStrike or similar endpoint security
  • Okta or similar identity platforms
  • Engineering quality standards
  • Compliance collaboration
  • Communication skills

What the JD emphasized

  • 7+ years in security engineering or operations, with 2+ years managing security or detection engineering teams including senior engineers
  • Player-Coach
  • Detection Expertise
  • Incident Response
  • External SOC
  • Cloud & Tooling
  • Engineering Quality
  • Compliance