Senior Penetration Tester

Robinhood Robinhood · Fintech · Bellevue, WA · Security Division

Robinhood is seeking a Senior Penetration Tester to join their Offensive Security program. The role involves performing application security assessments, building and operating AI-assisted tools for testing, conducting threat modeling, and collaborating with engineers to fix vulnerabilities. A key focus is on researching and testing AI/ML systems, including prompt injection, tool/agent misuse, and RAG pipelines. The role also requires experience with Go and Python services, cloud environments, and cryptocurrency security.

What you'd actually do

  1. Perform application security assessments, including code reviews (primarily Go and Python), design reviews, and manual penetration testing of web applications, services, and infrastructure.
  2. Build and operate AI-assisted tools (e.g. LLM-based code review, AI-driven fuzzing, agentic recon pipelines) to increase testing throughput and coverage.
  3. Conduct threat modeling for high-impact systems and articulate security risk in terms of business logic, fraud potential, and customer impact.
  4. Collaborate on the triage of bug bounty submissions.
  5. Validate critical vulnerabilities surfaced by automated tools and improve detection coverage through scripting and configuration.

Skills

Required

  • 5+ years of experience in penetration testing, application security, or security engineering.
  • Proactive communication and engagement with stakeholders.
  • Demonstrated impact using AI tools (models, agentic frameworks, et al) as force multipliers in security work.
  • Proficiency in auditing and exploiting Go and Python services.
  • Strong grasp of application security principles, authentication and authorization models, and common vulnerability patterns.
  • Experience with vulnerability research, business logic flaws, and application-layer misuse patterns.
  • Experience targeting AI/ML systems: prompt injection, tool/agent misuse, context and model exfiltration, and the broader stack (RAG pipelines, MCP servers, agentic frameworks).
  • Working knowledge of cryptocurrency and blockchain security: custody and signing flows, wallet and key-management design, on-chain integrations, and misuse patterns specific to digital-asset movement (transfer validation, replay, signature handling, bridge/staking integrations).
  • Familiarity with Linux systems, intrusion detection, and common log formats.
  • Hands-on experience testing cloud environments (AWS, GCP, or similar) and container orchestration platforms (Docker, Kubernetes).
  • Knowledge of network protocols (TCP/IP, DNS) and secure architecture best practices.
  • Ability to work independently, structure and execute testing plans, and clearly communicate risk to technical and non-technical stakeholders.
  • Comfort collaborating and documenting work asynchronously using tools like Slack, GitHub, and JIRA.

Nice to have

  • Experience in the financial technology (fintech) industry or highly regulated environments.
  • Passion for improving security through fixing—not just finding—vulnerabilities.
  • Demonstrated history of challenging security assumptions and creatively solving complex problems.

What the JD emphasized

  • AI-assisted tools
  • AI/ML systems
  • agentic frameworks

Other signals

  • AI-assisted tools
  • AI/ML systems testing
  • agentic recon pipelines
  • agentic frameworks