Rogo

Staff Security Engineer, Product

Rogo
Apply
12 months ago

Responsibilities

  • Conduct continuous penetration testing and red team assessments across applications, APIs, AI/ML pipelines, and cloud environments.
  • Build agentic security tooling and automated pipelines that find, validate, and patch vulnerabilities across code review, dependency management, and infrastructure as code.
  • Develop custom offensive tools, exploit chains, attack simulations, and environments tailored to Rogo’s AI platform.
  • Perform adversarial testing for prompt injection, model manipulation, data poisoning, agent workflows, and tenant-isolation weaknesses.
  • Research vulnerabilities and bug-bounty opportunities beyond scanner output, including logic flaws, authentication bypasses, and chained exploits.
  • Lead threat modeling, purple team exercises, and security-control validation with engineering and infrastructure teams.
  • Contribute to backend codebases by fixing critical vulnerabilities, hardening authentication and authorization, and building security primitives.
  • Own external penetration-testing firm relationships and drive findings through remediation to closure.
  • Share offensive security techniques, findings, and lessons with engineering and leadership.

Requirements

  • Professional penetration-testing experience across web applications, APIs, cloud environments, and ideally AI/ML systems.
  • Experience writing real exploits and developing custom offensive tooling or exploit chains.
  • Professional development experience in a strongly typed language such as Rust, Go, Java, or C++, along with scripting languages such as Python and Bash.
  • Familiarity with Burp Suite, Nuclei, Semgrep, custom fuzzing frameworks, and security testing tools.
  • Experience integrating SCA, SAST, and DAST checks into CI/CD pipelines.
  • Familiarity with Terraform, Kubernetes, and identifying misconfigurations and attack paths in AWS or GCP.
  • Knowledge of threat modeling, cryptography fundamentals, and compliance frameworks including SOC 2, ISO 27001, ISO 42001, and NIST CSF.
  • Bonus qualifications include OSCP, OSWE, GXPN, GWAPT, CPTS, or similar certifications; regulated multi-tenant SaaS security experience; cloud or Kubernetes penetration testing; bug bounty or published CVE/security research experience; and customer-facing security discussions.

Benefits

  • Opportunity to work on a rapidly scaling enterprise AI platform serving investment banks, private equity funds, hedge funds, and financial institutions.
  • Fast-paced startup environment with high ownership, strong learning opportunities, and a world-class team.
  • Exposure to frontier AI systems, reinforcement learning, published research, and security challenges in regulated financial services.
  • The role includes collaboration with engineering, infrastructure, product, leadership, and external penetration-testing firms.
Rogo

About Rogo

201-500 employees

Rogo builds an AI operating system for finance, offering a suite of agents that handle sourcing, diligence, modeling, and turning analysis into deliverables for investment banks, private equity funds, and investment firms. It sells enterprise software and advisory services to large financial institutions. Founded in 2022 and headquartered in New York, the privately held company focuses on Wall Street workflows and is used by global finance teams.

Contact me