Security Engineer Product

Enterprise AI platform for financial institutions, providing agentic research, analysis, workflow automation, and client-ready deliverables.

New York, NY, United States
About Rogo

Rogo builds bespoke, enterprise-grade AI systems for financial workflows, including research, analysis, modeling, reporting, and deal work. Its platform emphasizes financial-domain models, integrated firm and market data, auditability, governance, and security.

View jobs by Rogo

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will conduct penetration testing, red team exercises, and adversarial assessments across applications, APIs, AI systems, and cloud environments. You will build security automation and offensive tooling, investigate vulnerabilities, model threats, remediate security issues in code, run attack simulations, and coordinate external penetration testing.

Requirements

  • Professional penetration testing experience across web applications, APIs, and cloud environments
  • Professional development experience with a strongly typed language and scripting languages
  • Knowledge of Burp Suite, Nuclei, Semgrep, fuzzing, and custom security tooling
  • Experience integrating SCA, SAST, and DAST into CI/CD pipelines
  • Knowledge of Terraform, Kubernetes, and AWS or GCP security
  • Knowledge of threat modeling, cryptography, SOC 2, ISO 27001, ISO 42001, and NIST CSF
  • Ability to collaborate with developers, product teams, and leadership

Responsibilities

  • Conduct penetration testing and red team assessments across applications, APIs, AI and ML pipelines, and cloud environments
  • Build agentic security tooling to find, validate, and patch vulnerabilities
  • Develop offensive tooling, exploit chains, and attack simulations
  • Build automated security testing and remediation pipelines
  • Perform adversarial testing of AI-specific attack surfaces
  • Research vulnerabilities and identify logic flaws, authorization bypasses, and chained exploits
  • Run threat modeling sessions and prioritize remediation
  • Build attack simulation environments and validate security controls
  • Contribute to backend codebases and harden authentication and authorization flows
  • Lead purple team exercises
  • Manage external penetration testing relationships and remediation
  • Share offensive security techniques and lessons learned

Benefits

  • Equity
  • Comprehensive medical coverage
  • Dental coverage
  • Vision coverage
  • Paid time off
Security Engineer Product at Rogo | JobStash