Senior Security Analyst, Threat Intelligence

Robinhood Robinhood · Fintech · Ljubljana, Slovenia, Menlo Park, CA +1 · Security Division

Robinhood is seeking a Senior Security Analyst, Threat Intelligence to join their elite team. The role involves researching criminal ecosystems, detecting and disrupting adversary activity, and building scalable systems to translate intelligence into action. Responsibilities include proactive threat hunting, mapping criminal ecosystems, building a comprehensive 'Universe of Threats', investigating attacker infrastructure, coordinating takedowns, and leveraging intelligence workflows. The ideal candidate will have 5+ years of experience in threat intelligence or cyber investigations, with hands-on experience tracking criminal ecosystems and familiarity with domain registration, DNS, and cloud abuse. Experience with OSINT tooling, SQL, Python, SIEM/SOAR, and strong communication skills are required.

What you'd actually do

  1. Proactively hunt and map criminal ecosystems targeting Robinhood and its customers, and translate intelligence into detections and coordinated defenses that disrupt adversaries before they cause harm.
  2. Build and maintain a comprehensive "Universe of Threats" by identifying, tracking, and prioritizing adversaries across phishing, scams, impersonation, fraud, and infrastructure abuse.
  3. Support and contribute to a proactive threat intelligence lifecycle through industry partnerships, collaboration with trusted peers and federal authorities, and cultivating online personas to generate early warning capabilities that protect Robinhood's business operations.
  4. Investigate attacker infrastructure across domains, DNS, certificate transparency logs, cloud providers, and telecom platforms, and convert findings into concrete detections, controls, and customer protections.
  5. Coordinate threat actor infrastructure takedowns with hosting providers, domain registrars, cloud platforms, and other infrastructure partners to disrupt adversary operations.

Skills

Required

  • threat intelligence
  • brand protection
  • cyber investigations
  • phishing
  • scams
  • impersonation
  • fraud
  • infrastructure abuse
  • domain registration patterns
  • DNS analysis
  • certificate transparency analysis
  • cloud hosting abuse
  • OSINT tooling
  • SQL
  • Python
  • SIEM
  • SOAR
  • OpenCTI
  • case management systems
  • written and verbal communication

Nice to have

  • mentorship
  • stakeholder engagement
  • program design

What the JD emphasized

  • 5+ years of total experience, including 2–3+ years operating at a senior scope in threat intelligence, brand protection, or cyber investigations.
  • Hands-on experience tracking criminal ecosystems tied to phishing, scams, impersonation, fraud, and infrastructure abuse, and the ability to move from isolated indicators to campaign- and actor-level analysis.
  • Familiarity with domain registration patterns, DNS and certificate transparency analysis, cloud and hosting abuse across providers (e.g., AWS, GCP, Azure, VPS), and attacker monetization methods.
  • Experience using OSINT tooling, SQL, Python, notebooks, SIEM or SOAR platforms, OpenCTI, and case management systems to analyze data and automate workflows.