Rogo
Security Engineer, Product
New York City$270k–$330kfulltimemidAdded 2 days ago
About this role
Join Rogo as a hands-on Security Engineer focused on offensive security and adversarial testing of our AI-driven financial platform. You'll conduct continuous penetration testing, build automated security tooling, and partner with engineering teams to harden our products before attackers do.
What you'll do
- Conduct hands-on penetration testing and red team assessments against applications, APIs, AI/ML pipelines, and cloud infrastructure on a continuous basis
- Build agentic security tooling that autonomously finds, validates, and patches vulnerabilities across code, dependencies, and infrastructure
- Perform deep adversarial testing of AI-specific attack surfaces including prompt injection, model manipulation, data poisoning, and tenant isolation
- Develop custom offensive tools, exploit chains, and attack simulations tailored to Rogo's architecture
- Contribute directly to backend codebases to fix vulnerabilities and harden authentication, authorization, and security primitives
- Design threat modeling sessions with engineering teams and lead purple team exercises to validate detection and response capabilities
What they're looking for
- Penetration testing across web applications, APIs, and cloud environments
- Exploit development and custom offensive tooling (Python, Bash)
- Strongly-typed programming languages (Rust, Go, Java, C++)
- Security testing tools (Burp Suite, Nuclei, Semgrep, fuzzing frameworks)
- CI/CD pipeline security integration and SAST/DAST/SCA tooling
- Cloud infrastructure security (AWS/GCP, Terraform, Kubernetes)
- AI/ML security and attack surface assessment
- Vulnerability research and threat modeling
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Rogo
Rogo builds a financial AI platform with a focus on data-driven insights and user experience. The company is hiring Analytics Engineers to develop data pipelines and reporting tools, and Design Engineers to enhance its design system and user interactions.
View all jobs at RogoLikely interview questions
- Describe a time you found a critical vulnerability through manual testing that automated scanners missed—what was your methodology?
- How would you design an automated security testing pipeline that continuously performs offensive assessments without slowing developer velocity?