Staff Security Analyst, Threat Intelligence
$8 - $12/year
Job Description
Staff Security Analyst, Threat Intelligence
Toronto, Canada
Apply
Join us in building the future of finance.
Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading.
About the team + role
We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.
The Threat Intelligence team reduces organizational risk by rapidly detecting, understanding, and disrupting adversary activity. We research criminal ecosystems targeting our brand, customers, and infrastructure, and work with partners to translate that intelligence into detections, controls, and customer protections. Our work enables Security, Engineering, Trust & Safety, and executive leaders to focus resources where risk is highest. We operate with a strong sense of ownership, clear communication, and a commitment to protecting customers so they can confidently participate in the financial system!
As a Staff Security Analyst, Threat Intelligence, you will operate at the forefront of advanced and evolving threats targeting Robinhood and our customers. You will actively hunt for emerging phishing, scam, impersonation, fraud, and infrastructure abuse campaigns while building scalable systems that turn intelligence into action. This role combines hands-on investigation, program design, mentorship, and stakeholder engagement. Your work will shape proactive controls, influence product and security decisions, and strengthen our overall threat defense strategy.
This role is based in our Toronto, Canada office(s), with in-person attendance expected at least 3days per week.
At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.
What you’ll do
- Proactively hunt and map criminal ecosystems targeting Robinhood and its customers, then translate intelligence into scalable systems and coordinated defenses that disrupt adversaries before they cause harm.
- Build and operationalize a comprehensive “Universe of Threats” by identifying, tracking, and prioritizing adversaries across phishing, scams, impersonation, fraud, and infrastructure abuse.
- Establish and mature a proactive threat intelligence lifecycle by developing industry partnerships, collaborating with trusted peers and federal authorities, and cultivating online personas to generate early warning capabilities that protect Robinhood’s business operations.
- Investigate attacker infrastructure across domains, DNS, certificate transparency logs, cloud providers, and telecom platforms, and convert findings into concrete detections, controls, and customer protections.
- Coordinate threat actor infrastructure takedowns with hosting providers, domain registrars, cloud platforms, and other infrastructure partners to disrupt adversary operations at scale.
- Design and automate intelligence workflows using OSINT tooling, enrichment pipelines, data analysis tools, and case management systems to scale analysis and reporting.
- Partner directly with Detection & Response, Automation, Customer Trust & Safety (Fraud and Financial Crimes), Security Engineering, Corporate Security, Risk, and executive leaders to prioritize threats based on measurable business risk.
What you bring
- 8–12+ years of total experience, including 3–5+ years operating at a senior or staff-level scope in threat intelligence, brand protection, or cyber investigations.
- Hands-on experience tracking criminal ecosystems tied to phishing, scams, impersonation, fraud, and infrastructure abuse, and the ability to move from isolated indicators to campaign- and actor-level analysis.
- Deep familiarity with domain registration patterns, DNS and certificate transparency analysis, cloud and hosting abuse across providers (e.g., AWS, GCP, Azure, VPS), and attacker monetization methods.
- Experience using OSINT tooling, SQL, Python, notebooks, SIEM or SOAR platforms, OpenCTI, and case management systems to analyze data and automate workflows.
- Ability to translate complex technical threats into clear business risk for technical teams and executive audiences through strong written and verbal communication.
- Experience mentoring others or leading initiatives across teams, with a high level of accountability and sound risk judgment in ambiguous situations.
Nice to have
- Experience with crypto investigations or on-chain analysis.
- Background in highly regulated industries such as fintech, financial services, payments, crypto, healthcare, or government.
About the team + role
We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.
The Red Team team’s mission is to proactively identify and simulate real-world threats against Robinhood’s platforms, properties, and people. Through red teaming and adversarial simulations, the team evaluates security controls, uncovers vulnerabilities, and helps continuously strengthen Robinhood’s overall security posture in close partnership with Detection & Response, Physical Security, and Engineering.
As a Staff Offensive Security Engineer, you will take a hands-on role in designing and executing stealthy adversarial simulations to validate assumptions and uncover gaps in detection and response. You’ll leverage threat modeling, penetration testing, and research-driven techniques to emulate sophisticated attackers, while collaborating cross-functionally to improve defenses and shape more secure systems.
This role is based in our Toronto, Canada office(s), with in-person attendance expected at least 3days per week.
At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.
What you’ll do
- Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.
- Perform threat modeling for new and existing services, clearly articulating security risks and tradeoffs to engineering and risk stakeholders.
- Conduct vulnerability research, exploit development, and testing using both custom tooling and public proof-of-concept techniques.
- Partner with detection and response teams to simulate realistic attack scenarios and evaluate monitoring and incident response readiness.
- Write and maintain tooling to automate and scale offensive security assessments.
- Serve as a subject matter expert by documenting findings, recommending remediation strategies, and supporting teams through fixes.
- Mentor teammates and contribute to shared knowledge through internal documentation, presentations, and external talks or blog posts.
What you bring
- 8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
- Demonstrated experience mentoring or guiding other security engineers.
- Strong understanding of threat modeling methodologies and the MITRE ATT&CK framework.
- Experience testing modern environments, including cloud platforms (AWS, GCP), containerized systems (Docker, Kubernetes), CI pipelines, and identity systems.
- Working knowledge of defensive security tools such as IDS/IPS, EDR, packet capture, and network monitoring, including common evasion techniques.
- Proficiency in Python, Go, or JavaScript for exploit development, tooling, or automation.
- Clear written and verbal communication skills, with the ability to explain technical findings to both engineers and senior leaders.
- Experience collaborating with distributed teams and documenting work through tools such as Slack, Jira, GitHub, and email.
Bonus points:
- Experience working in financial technology or regulated environments.
- Prior experience serving as a technical lead on security initiatives.
What we offer
- Challenging, high-impact work to grow your career
- Performance driven compensation with multipliers for outsized impact, bonus programs, and equity ownership
- Top tier benefits to fuel your work, including supplemental health insurance, ancillary insurance, and mental health support programs
- Lifestyle wallet - a highly flexible employer-paid benefits spending account expenses beyond traditional benefits such as wellness, childcare, learning, and more.
- Time off to recharge including company holidays, paid time off, sick time, paid volunteer time off, parental leave, and more!
- Exceptional office experience with catered meals, events, and comfortable w
For more details click Job Post.
About Robinhood
Robinhood is a financial technology company offering commission-free stock, ETF, options, and cryptocurrency trading through its mobile app, aimed at democratizing access to financial markets. Industry: Financial Technology & Investment App
