Skip to content
← Back to job listings

Engineering Manager of Detect & Respond

Betterment · New York, United States

External listingfull-time3 months ago

About The Role

Join Betterment, a company dedicated to making people's lives better through smarter financial tools. As the Engineering Manager of Detection Engineering, you will lead the team responsible for building and operating Betterment's security detection capabilities. You will own the strategy and execution for threat detection across our cloud infrastructure, SaaS ecosystem, and product. This role requires a hands-on leader who can drive the roadmap, grow the team, and translate security priorities into engineering outcomes.

  • Lead the team responsible for building and operating Betterment's security detection capabilities, including strategy and execution for threat detection across various environments.
  • Collaborate with cross-functional teams to mature the detection program, balancing the delivery of new capabilities with operational rigor.
  • Mentor and grow a team of detection engineers, investing in their craft and careers while holding a high bar for engineering quality.
  • Compliance: Experience collaborating with Compliance, Risk, and Audit teams on security controls and evidence collection
  • Communication: Clear, direct communicator who can translate security context for technical and non-technical audiences alike
  • Cloud & Tooling: Familiarity with cloud environments (AWS), endpoint security (CrowdStrike or similar), and identity platforms (Okta or similar)
  • Engineering Quality: Passion for engineering quality, you hold the team to the same standards as any product engineering team
  • External SOC: Experience working with or managing an external SOC, including defining escalation paths and performance expectations
  • We are seeking a team member with 7+ years in security engineering or operations, with 2+ years managing security or detection engineering teams including senior engineers
  • Detection Expertise: Strong background in SIEM platforms (Splunk preferred), detection-as-code practices, and threat-informed detection development including familiarity with adversary TTPs and frameworks like MITRE ATT&CK
  • Incident Response: Experience leading or overseeing incident response, including establishing IR playbooks and driving post-incident review practices
  • Player-Coach: A track record as a true player-coach, comfortable going deep on technical problems while also leading people and programs

This is an external listing. JobSpring does not represent or verify the employer. Report this listing