This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join us in building the future of finance. Our mission is to democratize finance for all. Robinhood is looking for an Offensive Security Engineer who is passionate about Red Teaming, Adversarial Simulation, and breaking / fixing systems, to join the Red Team. The Red Team is a core pillar of the Offensive Security team and situated within the Safety & Productivity Engineering organization. The Red Team works with teams across Robinhood to ensure our products, services, and processes are secure through threat modeling, penetration testing, adversarial simulations, and red teaming.
Job Responsibility:
Evangelize the Offensive Security Team’s Findings and Projects with stakeholders throughout the company and collaborate with other teams to create solutions that balance security with other priorities
Mentor and provide guidance to the members of the Offensive Security team
Utilize threat modeling to identify threats and shape Red Team priorities and exercises
Plan and execute long term, broadly scoped, black box Red Team exercises utilizing vulnerability research, exploit development, and utilizing public proof of concept code
Perform penetration testing, code reviews, and design/architecture reviews
Write tooling to assist with and automate Red Team assessments
Plan and participate in Adversarial Simulation exercises with various security teams
Lead Security Incidents when Pentest or Red Team findings require them
Publish blog posts and present talks at security conferences
Requirements:
2+ years of Red Team experience
Experience mentoring other team members
Passion and demonstrated experience for challenging security assumptions
Excellent written and verbal communication skills and ability to communicate your findings at many different levels of abstraction from Engineers to Executives
Passion for fixing security issues and not just identifying security issues
Familiarity with common network protocols and standards such as DNS and TCP/IP
Experience with MacOS and Linux
Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS, GCP), etc and be able to give hardening suggestions
Experience/knowledge of defensive tools/techniques (IDS/IPS, Packet Capture, Network Analysis, AV, EDR, etc.) and how to evade them
Deep understanding of Mitre’s ATT&CK Framework
Strong understanding of the security fundamentals of access and identity
Comfortable reading / writing python, go, and javascript
Ability to research and execute a testing plan to access a new technology or process
Demonstrated experience working with a distributed team
Proficiency to communicate over a text-based medium (Slack, JIRA Issues, GitHub issues, & Email) and can succinctly document technical details
Nice to have:
Experience in the Financial Technology domain
Experience being a technical lead at other organizations
What we offer:
Performance driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching
100% paid health insurance for employees with 90% coverage for dependents
Lifestyle wallet - a highly flexible benefits spending account for wellness, learning, and more
Employer-paid life & disability insurance, fertility benefits, and mental health benefits
Time off to recharge including company holidays, paid time off, sick time, parental leave, and more
Exceptional office experience with catered meals, events, and comfortable workspaces