Security Engineer, Product
New York City • FullTime
Posted 11mo ago
About the job
Rogo is transforming global finance with AI, empowering professionals at top investment firms with unparalleled speed, accuracy, and insight. We are redefining financial workflows and are a rapidly growing, global company with proven product-market fit and strong investor backing. We are scaling quickly and defining a new category of enterprise AI. Our team is sharp, motivated, and deeply committed to our mission, taking ownership of complex problems and focusing on our users. If you thrive in a fast-paced environment and want to help build the future of finance, join us.
Responsibilities
- Conduct hands-on penetration testing and red team assessments against applications, APIs, AI/ML pipelines, and cloud environments.
- Build agentic security tooling to find, validate, and patch vulnerabilities end-to-end.
- Develop and maintain custom offensive tooling, exploit chains, and attack simulations tailored to the AI platform.
- Build and operate automated security testing and remediation pipelines.
- Perform adversarial testing of AI-specific attack surfaces like prompt injection and model manipulation.
- Conduct vulnerability research and bug hunting, identifying logic flaws and chained exploits.
- Design and execute threat modeling sessions with engineering teams.
- Build attack simulation environments and validate security controls against real-world TTPs.
- Contribute directly to backend codebases to fix vulnerabilities and harden authentication/authorization.
- Lead purple team exercises to test detection and response capabilities.
- Own the relationship with external pen test firms and drive remediation.
- Share offensive tradecraft and emerging attack techniques with engineering and leadership.
Requirements
- Professional penetration testing experience across web apps, APIs, cloud environments, and AI/ML systems.
- Experience building agentic security tooling that autonomously finds, validates, and patches vulnerabilities.
- Professional development experience in a strongly typed language (e.g., Rust, Go, Java, C++) and scripting languages (Python, Bash).
- Comfort with tools like Burp Suite, Nuclei, Semgrep, and custom fuzzing frameworks.
- Experience integrating automated security checks into CI/CD pipelines (SCA, SAST, DAST).
- Comfort with infrastructure automation (Terraform, Kubernetes) and identifying misconfigurations in AWS/GCP.
- Strong communication and collaboration skills with developers, product teams, and leadership.
- Applied knowledge of threat modeling, cryptography fundamentals, and compliance frameworks (SOC 2, ISO 27001/42001, NIST CSF).
- Experience testing multi-tenant SaaS platforms serving regulated industries.
- Hands-on cloud penetration testing experience in AWS or GCP.
- Kubernetes security testing experience.
- Experience in customer-facing security conversations and technical sessions.