Staff Offensive Security Engineer
Robinhood · Menlo Park, CA · 4 days ago
On-siteInformation Technology$217k–$255k/yrFull-time
About the role
The Red Team’s mission is to identify and reduce real-world security risks across Robinhood by simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications, infrastructure, and physical environments, and partner closely with engineering and security teams to strengthen detection and response capabilities.
Responsibilities
- Evangelize the Offensive Security Team’s Findings and Projects with stakeholders throughout the company and collaborate with other teams to create solutions that balance security with other priorities.
- Mentor and provide guidance to the members of the Offensive Security team.
- Plan and execute red team exercises, including long-term assessments that simulate real-world attack scenarios.
- Perform threat modeling and penetration testing across applications, infrastructure, and corporate environments.
- Develop scripts and tools to support and automate security testing activities.
- Partner with detection and response teams to run adversarial simulations and improve incident readiness.
- Communicate findings clearly and work with engineering teams to remediate identified risks.
- Lead Security Incidents when Pentest or Red Team findings require them.
- Plan and participate in Adversarial Simulation exercises with various security teams.
Requirements
- 8+ years of experience conducting red team operations or advanced penetration testing.
- Experience mentoring or supporting the development of other security engineers.
- Passion and demonstrated experience for challenging security assumptions.
- Excellent written and verbal communication skills and ability to communicate your findings at many different levels of abstraction from Engineers to Executives.
- Passion for fixing security issues and not just identifying security issues.
- Familiarity with common network protocols and standards such as DNS and TCP/IP.
- Experience with MacOS and Linux.
- Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS, GCP), etc and be able to give hardening suggestions.
- Experience/knowledge of defensive tools/techniques (IDS/IPS, Packet Capture, Network Analysis, AV, EDR, etc.) and how to evade them.
- Deep understanding of Mitre’s ATT&CK Framework.
- Strong understanding of the security fundamentals of access and identity.
- Comfortable reading / writing python, go, and javascript.
- Ability to research and execute a testing plan to access a new technology or process.
- Demonstrated experience working with a distributed team.
- Proficiency to communicate over a text-based medium (Slack, JIRA Issues, GitHub issues, & Email) and can succinctly document technical details.
Qualifications
- Experience in the Financial Technology domain.
- Experience being a technical lead at other organizations.
Skills
- Python
- Go
- Javascript
Benefits
- Market competitive and pay equity-focused compensation structure
- 100% paid health insurance for employees with 90% coverage for dependents
- Annual lifestyle wallet for personal wellness, learning and development, and more!
- Lifetime maximum benefit for family forming and fertility benefits
- Dedicated mental health support for employees and eligible dependents
- Generous time away including company holidays, paid time off, sick time, parental leave, and more!
- Lively office environment with catered meals, fully stocked kitchens, and geo-specific commuter benefits
Pay
- Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands.
Schedule
- This role is based in our Bellevue, WA, New York, NY, or Menlo Park, CA office(s), with in-person attendance expected at least 3 days per week.