Rogo

Staff Security Engineer, Product

Rogo
Apply
11 months ago

Responsibilities

  • Conduct continuous penetration testing and red team assessments across applications, APIs, AI/ML pipelines, and cloud environments.
  • Build agentic security tooling and automated pipelines that find, validate, and patch vulnerabilities across code review, dependency management, and infrastructure as code.
  • Develop custom offensive tools, exploit chains, attack simulations, and environments tailored to Rogo’s AI platform.
  • Perform adversarial testing for prompt injection, model manipulation, data poisoning, agent workflows, and tenant-isolation weaknesses.
  • Research vulnerabilities and bug-bounty opportunities beyond scanner output, including logic flaws, authentication bypasses, and chained exploits.
  • Lead threat modeling, purple team exercises, and security-control validation with engineering and infrastructure teams.
  • Contribute to backend codebases by fixing critical vulnerabilities, hardening authentication and authorization, and building security primitives.
  • Own external penetration-testing firm relationships and drive findings through remediation to closure.
  • Share offensive security techniques, findings, and lessons with engineering and leadership.

Requirements

  • Professional penetration-testing experience across web applications, APIs, cloud environments, and ideally AI/ML systems.
  • Experience writing real exploits and developing custom offensive tooling or exploit chains.
  • Professional development experience in a strongly typed language such as Rust, Go, Java, or C++, along with scripting languages such as Python and Bash.
  • Familiarity with Burp Suite, Nuclei, Semgrep, custom fuzzing frameworks, and security testing tools.
  • Experience integrating SCA, SAST, and DAST checks into CI/CD pipelines.
  • Familiarity with Terraform, Kubernetes, and identifying misconfigurations and attack paths in AWS or GCP.
  • Knowledge of threat modeling, cryptography fundamentals, and compliance frameworks including SOC 2, ISO 27001, ISO 42001, and NIST CSF.
  • Bonus qualifications include OSCP, OSWE, GXPN, GWAPT, CPTS, or similar certifications; regulated multi-tenant SaaS security experience; cloud or Kubernetes penetration testing; bug bounty or published CVE/security research experience; and customer-facing security discussions.

Benefits

  • Opportunity to work on a rapidly scaling enterprise AI platform serving investment banks, private equity funds, hedge funds, and financial institutions.
  • Fast-paced startup environment with high ownership, strong learning opportunities, and a world-class team.
  • Exposure to frontier AI systems, reinforcement learning, published research, and security challenges in regulated financial services.
  • The role includes collaboration with engineering, infrastructure, product, leadership, and external penetration-testing firms.
Rogo

About Rogo

51-200 employees

Rogo is the purpose-built AI platform for finance.