Rogo
Staff Security Engineer, Product
New York City · Staff+
Sponsorship not specifiedDetected 289 days ago
PythonJavaGoRustC++BashCode ReviewAWSGCPCloud PlatformsKubernetesTerraformCI/CDMachine LearningCybersecurityPenetration TestingComplianceResearchLeadership
About the role
- Conduct hands-on penetration testing and red team assessments against Rogo's applications, APIs, AI/ML pipelines, and cloud environments on a continuous basis, not just during annual engagements.
- As a Staff Security Engineer at Rogo, you'll be our hands-on offensive security practitioner, focused on breaking our products before adversaries do.
- You'll conduct deep-dive penetration testing, red team exercises, and adversarial security assessments against our AI-driven platform, APIs, and cloud infrastructure, then turn those findings into engineering solutions that harden the product at its core.
Responsibilities
- If you thrive in a fast-paced environment, demand excellence, and want to help build the future of finance, we invite you to join us.
- You'll own real surface area and watch the world's most sophisticated users rely on your work.
- Build agentic security tooling that finds, validates, and patches vulnerabilities end-to-end, minimizing manual intervention across code review, dependency management, and IaC.
- Develop and maintain custom offensive tooling, exploit chains, and attack simulations tailored to Rogo's AI platform and architecture.
- Rather than gatekeeping releases through manual AppSec reviews, you'll build intelligent security automation to scale offensive testing, triage findings, and embed continuous security validation directly into the engineering workflow.
- You'll partner with development teams not just as a reviewer, but as a security engineer who contributes to the codebase, improves our systems, and raises the bar for what "secure by default" means at Rogo.
- Design and execute threat modeling sessions with engineering teams, translating offensive findings into concrete, prioritized remediation that ships in the same sprint.
- Own the relationship with external pen test firms and drive remediation of findings to closure.
- Have built or are excited to build agentic security tooling that autonomously finds, validates, and patches vulnerabilities, minimizing human-in-the-loop remediation.
- Are comfortable with Burp Suite, Nuclei, Semgrep, custom fuzzing frameworks, and building your own tools when off-the-shelf doesn't cut it.
Requirements
- You are high-intensity and care a lot about what you do, and you're ecstatic to work at a startup.
- You are ambitious.
- You have fun solving problems that others think are impossible.
- You are curious.
- You are an owner.
- You are autonomous, self-directed, and comfortable working with ambiguity.
- You are collaborative, organized, thoughtful, and kind.
- There is nowhere else you can work on it at this scale.
- Have applied knowledge of threat modeling, cryptography fundamentals, and compliance frameworks (SOC 2, ISO 27001/42001, NIST CSF).
Nice to have
- Have professional penetration testing experience across web apps, APIs, cloud environments, and ideally AI/ML systems.
- You've written real exploits, not just run scanners.
- Experience testing multi-tenant SaaS platforms serving regulated industries (financial services is a strong plus).
Skills
- Hands-on cloud penetration testing experience in AWS or GCP (privilege escalation, cross-account attacks, metadata abuse).
Compensation
- Conduct hands-on penetration testing and red team assessments against Rogo's applications, APIs, AI/ML pipelines, and cloud environments on a continuous basis, not just during annual engagements.
Benefits
- You find joy in learning about AI, technology, and finance.
Company info
- Rogo has strong product adoption with the world's leading financial institutions, and we are still early.
- The upside is enormous.
- Our mission is to transform global finance by empowering professionals at the world's top investment banks, private equity funds, and investment firms with AI that delivers unparalleled speed, accuracy, and insight.
- With a rapidly growing, global client base, proven product-market fit, and backing from world-class investors, we are scaling quickly and defining a new category of enterprise AI.
- Our team is sharp, motivated, and deeply committed to Rogo's mission.
This listing is sourced directly from Rogo's careers page and normalized into a canonical job model.