SecJobs
RoleSuite
CompaniesRemoteAboutMethodologyContactPrivacy
Updated 2026-06-10 21:00 UTC·© 2025–2026 RoleSuite
← Back to listings

Senior Security Analyst, Threat Intelligence

Robinhood · Toronto, Canada

Join us in building the future of finance.

Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading.

About the team + role

We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. 

The Threat Intelligence team reduces organizational risk by rapidly detecting, understanding, and disrupting adversary activity. We research criminal ecosystems targeting our brand, customers, and infrastructure, and work with partners to translate that intelligence into detections, controls, and customer protections. Our work enables Security, Engineering, Trust & Safety, and executive leaders to focus resources where risk is highest. We operate with a strong sense of ownership, clear communication, and a commitment to protecting customers so they can confidently participate in the financial system!

As a Senior Security Analyst, Threat Intelligence, you will operate at the forefront of advanced and evolving threats targeting Robinhood and our customers. You will actively hunt for emerging phishing, scam, impersonation, fraud, and infrastructure abuse campaigns while building scalable systems that turn intelligence into action. This role combines hands-on investigation, program design, mentorship, and stakeholder engagement. Your work will shape proactive controls, influence product and security decisions, and strengthen our overall threat defense strategy.

This role is based in our Toronto, Canada office(s), with in-person attendance expected at least 3 days per week. 

At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams. 

What you’ll do

  • Proactively hunt and map criminal ecosystems targeting Robinhood and its customers, and translate intelligence into detections and coordinated defenses that disrupt adversaries before they cause harm.
  • Build and maintain a comprehensive "Universe of Threats" by identifying, tracking, and prioritizing adversaries across phishing, scams, impersonation, fraud, and infrastructure abuse.
  • Support and contribute to a proactive threat intelligence lifecycle through industry partnerships, collaboration with trusted peers and federal authorities, and cultivating online personas to generate early warning capabilities that protect Robinhood's business operations.
  • Investigate attacker infrastructure across domains, DNS, certificate transparency logs, cloud providers, and telecom platforms, and convert findings into concrete detections, controls, and customer protections.
  • Coordinate threat actor infrastructure takedowns with hosting providers, domain registrars, cloud platforms, and other infrastructure partners to disrupt adversary operations.
  • Leverage and improve intelligence workflows using OSINT tooling, enrichment pipelines, data analysis tools, and case management systems to scale analysis and reporting.
  • Partner with Detection & Response, Automation, Customer Trust & Safety (Fraud and Financial Crimes), Security Engineering, Corporate Security, and Risk to prioritize threats based on measurable business risk.

What you bring

  • 5+ years of total experience, including 2–3+ years operating at a senior scope in threat intelligence, brand protection, or cyber investigations.
  • Hands-on experience tracking criminal ecosystems tied to phishing, scams, impersonation, fraud, and infrastructure abuse, and the ability to move from isolated indicators to campaign- and actor-level analysis.
  • Familiarity with domain registration patterns, DNS and certificate transparency analysis, cloud and hosting abuse across providers (e.g., AWS, GCP, Azure, VPS), and attacker monetization methods.
  • Experience using OSINT tooling, SQL, Python, notebooks, SIEM or SOAR platforms, OpenCTI, and case management systems to analyze data and automate workflows.
  • Ability to translate complex technical threats into clear business risk for technical teams and immediate stakeholders through strong written and verbal communication.
  • Experience contributing to team initiatives and supporting peers, with a high level of accountability and sound risk judgment in ambiguous situations.

What we offer

  • Challenging, high-impact work to grow your career
  • Performance driven compensation with multipliers for outsized impact, bonus programs, and equity ownership
  • Performance driven compensation with multipliers for outsized impact and bonus programs
  • Top tier benefits to fuel your work, including supplemental health insurance, ancillary insurance, and mental health support programs
  • Lifestyle wallet - a highly flexible employer-paid benefits spending account expenses beyond traditional benefits such as wellness, childcare, learning, and more.
  • Time off to recharge including company holidays, paid time off, sick time, paid volunteer time off, parental leave, and more!
  • Exceptional office experience with catered meals, events, and comfortable workspaces. 
  • Monthly commuter stipend to help offset in-office commuting costs

Our team is committed to providing an inclusive and welcoming interview experience for all candidates. If you require a specific accommodation during the application or interview process due to a physical or mental condition, please complete this Applicant Accommodation Form to notify our team. The form should only be completed if you need a specific accommodation.

AI Usage Disclosure: Robinhood uses artificial intelligence (AI) tools to support parts of our recruiting process. These tools enhance the efficiency and consistency of our hiring process; however, all hiring decisions are made by our hiring teams.

Vacancy Notice: This job posting represents an existing vacancy that we are actively seeking to fill.

In addition to the base pay range listed below, this role is also eligible for bonus opportunities + equity + benefits.

Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. The expected base pay range for this role is based on the location where the work will be performed.

Base Pay Range:

Toronto, ON
$131,750—$155,000 CAD

Click here to learn more about our Total Rewards, which vary by region and entity.

If our mission energizes you and you’re ready to build the future of finance, we look forward to seeing your application.

Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with applicable equal employment and privacy laws. Inclusion is built into how we hire and work—welcoming different backgrounds, perspectives, and experiences so everyone can do their best. Please review the Privacy Policy for your country of application.

Security pay context

Based on 1,696 disclosed Security salaries on RoleSuite, the role pays a median of $142K/year, with most offers between $112K and $183K (10th–90th percentile: $91K–$216K).

This posting lists $132K–$155K, in line with the $142K market median.

See the full Security salary breakdown →
Apply →

Other roles at Robinhood

  • Staff Data Scientist, Credit Card and BankingMenlo Park, CA; New York, NY; Washington, DC
  • Staff Product ManagerMenlo Park, CA; New York, NY
  • Senior Security Analyst, Threat IntelligenceMenlo Park, CA
  • Senior Software Engineer, Robinhood Command CenterNew York, NY
  • Senior Software Engineer, Streaming PlatformBellevue, WA
  • Senior Product Designer, CryptoBellevue, WA; Menlo Park, CA; New York, NY
  • Engineering Manager, Advisory PlatformMenlo Park, CA; New York, NY
  • Staff Software EngineerLondon, UK
  • Compliance Communications Senior SpecialistChicago, IL; Denver, CO; Lake Mary, FL; New York, NY
  • Underwriting Operations LeadChicago, IL; Denver, CO; Lake Mary, FL; New York, NY

More Security roles

  • Senior Data Scientist, Trust & SafetyChime · San Francisco, CA, USA
  • Security Guard - ADESA MinneapolisCarvana · Dayton, MN
  • Senior Incident Response Analyst (R-19347)D&B · Center Valley - Pennsylvania - United States
  • Senior Staff Security Engineer, Ripple TreasuryRipple · Chicago, Illinois, United States
  • Senior Staff Security Engineer, Ripple TreasuryRipple · San Francisco, CA, United States
  • Senior Cloud Security Engineer Roblox · San Mateo, CA, United States
  • Security Officer: Sat-Tues(3pm-11pm)Comstock · Washington, DC
  • Cybersecurity Manager (Incident Response & Security Operations)Match Group · Vancouver, British Columbia
  • Security Analyst II (SOC Analyst)UltraViolet Cyber · Camas, WA
  • Cloud Security EngineerFullscript · Ottawa, ON / Toronto, ON / Calgary, AB / Vancouver, BC