Offensive Security Engineer

RobinhoodMenlo Park, CA
1dHybrid

About The Position

Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. Robinhood is looking for an Offensive Security Engineer who is passionate about Red Teaming, Adversarial Simulation, and breaking / fixing systems, to join the Red Team. The Red Team is a core pillar of the Offensive Security team and situated within the Safety & Productivity Engineering organization. The Red Team works with teams across Robinhood to ensure our products, services, and processes are secure through threat modeling, penetration testing, adversarial simulations, and red teaming. Here are some examples of things our team does frequently that you’ll be heavily involved with: Red Teaming to validate assumptions, facilitate decisions, and improve our ability to detect and respond to incidents. Perform threat modeling against critical and new services. Articulate the actual security risk to risk working groups. Penetration testing our critical infrastructure, production applications, networks, offices, and processes. Sparring with Detection and Response and other stakeholders via Adversarial Simulations to prepare for incidents. Partnering with the physical security team to conduct assessments of Robinhood properties. Serving as a technical advocate and Subject Matter Expert for privacy and security decisions, designs, and discussions. Driving innovative ideas to implementation as the company evolves and grows. Conduct vulnerability research to understand latest TTPs, exploits, and forward looking capabilities. Leaving things better than you found them by partnering to fix the issues and not just finding broken things. As an Offensive Security Engineer, you will work across multiple domains, partner with key teams across Robinhood, and help build an even more resilient and secure product for our customers. This role is based in our Menlo Park, CA and Bellevue, WA offices, with in-person attendance expected at least 3 days per week. At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.

Requirements

  • 2+ years of Red Team experience.
  • Experience mentoring other team members.
  • Passion and demonstrated experience for challenging security assumptions.
  • Excellent written and verbal communication skills and ability to communicate your findings at many different levels of abstraction from Engineers to Executives.
  • Passion for fixing security issues and not just identifying security issues.
  • Familiarity with common network protocols and standards such as DNS and TCP/IP.
  • Experience with MacOS and Linux.
  • Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS, GCP), etc and be able to give hardening suggestions.
  • Experience/knowledge of defensive tools/techniques (IDS/IPS, Packet Capture, Network Analysis, AV, EDR, etc.) and how to evade them.
  • Deep understanding of Mitre’s ATT&CK Framework.
  • Strong understanding of the security fundamentals of access and identity.
  • Comfortable reading / writing python, go, and javascript.
  • Ability to research and execute a testing plan to access a new technology or process.
  • Demonstrated experience working with a distributed team.
  • Proficiency to communicate over a text-based medium (Slack, JIRA Issues, GitHub issues, & Email) and can succinctly document technical details.

Nice To Haves

  • Experience in the Financial Technology domain.
  • Experience being a technical lead at other organizations.

Responsibilities

  • Evangelize the Offensive Security Team’s Findings and Projects with stakeholders throughout the company and collaborate with other teams to create solutions that balance security with other priorities.
  • Mentor and provide guidance to the members of the Offensive Security team.
  • Utilize threat modeling to identify threats and shape Red Team priorities and exercises.
  • Plan and execute long term, broadly scoped, black box Red Team exercises utilizing vulnerability research, exploit development, and utilizing public proof of concept code.
  • Perform penetration testing, code reviews, and design/architecture reviews.
  • Write tooling to assist with and automate Red Team assessments.
  • Plan and participate in Adversarial Simulation exercises with various security teams.
  • Lead Security Incidents when Pentest or Red Team findings require them.
  • Publish blog posts and present talks at security conferences.

Benefits

  • Challenging, high-impact work to grow your career
  • Performance driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching
  • Best in class benefits to fuel your work, including 100% paid health insurance for employees with 90% coverage for dependents
  • Lifestyle wallet - a highly flexible benefits spending account for wellness, learning, and more
  • Employer-paid life & disability insurance, fertility benefits, and mental health benefits
  • Time off to recharge including company holidays, paid time off, sick time, parental leave, and more!
  • Exceptional office experience with catered meals, events, and comfortable workspaces.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service