Manager of Response, Automation, Intelligence & Detection Engineering

Robinhood Robinhood · Fintech · Bellevue, WA +2 · Security Division

Manager leading teams focused on security operations, detection engineering, incident response, and threat intelligence. The role involves maturing these capabilities by improving detection coverage, response workflows, and operational readiness, with a strong emphasis on driving the adoption of AI and automation to enhance analyst productivity, accelerate investigations, and scale security operations. The position requires leadership experience in security operations and the ability to translate emerging threats into scalable defenses.

What you'd actually do

  1. Lead the Detection & Response and Threat Intelligence organizations across North America, setting the technical vision, organizational strategy, and execution priorities for both teams.
  2. Mature Robinhood's detection and incident response capabilities by improving detection coverage, response workflows, operational readiness, and measurable security outcomes.
  3. Define and track operational metrics such as detection coverage, response time, investigation quality, and control effectiveness, using data to continuously improve team performance.
  4. Lead security incident response for high-severity events, serving as an Incident Commander when needed and ensuring thorough post-incident reviews that drive lasting improvements.
  5. Partner with Security Engineering, Infrastructure, Product Security, Trust & Safety, and Engineering leaders to translate emerging threats into scalable detection, response, and prevention capabilities.

Skills

Required

  • 8+ years of experience in security operations, incident response, detection engineering, threat intelligence, or a closely related security discipline.
  • 4+ years of experience leading high-performing security engineering or security operations teams, including hiring, coaching, and organizational development.
  • Demonstrated experience building and scaling detection and response programs, including incident response, detection engineering, operational processes, and security metrics.
  • Experience leading high-severity security incidents and coordinating cross-functional response efforts involving engineering, communications, legal, and executive stakeholders.
  • Strong technical foundation across modern cloud environments, endpoint security, identity systems, SIEM, EDR, and detection engineering practices, with the ability to provide technical leadership without needing to be the primary implementer.
  • Experience applying automation, AI, or software engineering practices to improve the scale and effectiveness of security operations.
  • Excellent communication and stakeholder management skills, with the ability to influence engineering leaders and clearly communicate technical risk to executive audiences.
  • Demonstrated ability to balance strategic planning with operational execution in a fast-paced, high-growth environment.

What the JD emphasized

  • AI and automation
  • automation, AI, and modern engineering practices
  • applying automation, AI, or software engineering practices

Other signals

  • applying frontier technologies
  • embracing AI and automation
  • AI, automation, and modern engineering practices
  • applying automation, AI, or software engineering practices