11 months ago
Responsibilities
- Conduct continuous penetration testing and red team assessments across applications, APIs, AI/ML pipelines, and cloud environments.
- Build agentic security tooling and automated pipelines that find, validate, and patch vulnerabilities across code review, dependency management, and infrastructure as code.
- Develop custom offensive tools, exploit chains, attack simulations, and environments tailored to Rogo’s AI platform.
- Perform adversarial testing for prompt injection, model manipulation, data poisoning, agent workflows, and tenant-isolation weaknesses.
- Research vulnerabilities and bug-bounty opportunities beyond scanner output, including logic flaws, authentication bypasses, and chained exploits.
- Lead threat modeling, purple team exercises, and security-control validation with engineering and infrastructure teams.
- Contribute to backend codebases by fixing critical vulnerabilities, hardening authentication and authorization, and building security primitives.
- Own external penetration-testing firm relationships and drive findings through remediation to closure.
- Share offensive security techniques, findings, and lessons with engineering and leadership.
Requirements
- Professional penetration-testing experience across web applications, APIs, cloud environments, and ideally AI/ML systems.
- Experience writing real exploits and developing custom offensive tooling or exploit chains.
- Professional development experience in a strongly typed language such as Rust, Go, Java, or C++, along with scripting languages such as Python and Bash.
- Familiarity with Burp Suite, Nuclei, Semgrep, custom fuzzing frameworks, and security testing tools.
- Experience integrating SCA, SAST, and DAST checks into CI/CD pipelines.
- Familiarity with Terraform, Kubernetes, and identifying misconfigurations and attack paths in AWS or GCP.
- Knowledge of threat modeling, cryptography fundamentals, and compliance frameworks including SOC 2, ISO 27001, ISO 42001, and NIST CSF.
- Bonus qualifications include OSCP, OSWE, GXPN, GWAPT, CPTS, or similar certifications; regulated multi-tenant SaaS security experience; cloud or Kubernetes penetration testing; bug bounty or published CVE/security research experience; and customer-facing security discussions.
Benefits
- Opportunity to work on a rapidly scaling enterprise AI platform serving investment banks, private equity funds, hedge funds, and financial institutions.
- Fast-paced startup environment with high ownership, strong learning opportunities, and a world-class team.
- Exposure to frontier AI systems, reinforcement learning, published research, and security challenges in regulated financial services.
- The role includes collaboration with engineering, infrastructure, product, leadership, and external penetration-testing firms.
Categories
About Rogo
Rogo is the purpose-built AI platform for finance.
