Senior Security Engineer, AI Vulnerability Management

Robinhood Robinhood · Fintech · Menlo Park, CA +1 · Security Division

Robinhood is seeking a Senior Security Engineer to lead the transformation of vulnerability management using AI and agentic systems. The role involves architecting automated defense systems that use AI agents to triage findings, correlate threat intelligence, and generate remediations. The engineer will also build systems to model blast radius, automate triage, and create LLM-powered dashboards for security insights. Experience with AI/agentic systems, security engineering, and modern infrastructure is required.

What you'd actually do

  1. Set Strategic RBVM Vision: Act as the technical lighthouse, defining the multi-year roadmap and driving the move toward Risk-Based Vulnerability Management (RBVM), prioritizing vulnerabilities based on real-world exploitability and business context.
  2. Architect Agentic AI Systems: Design and deploy AI agents that autonomously triage findings, correlate threat intelligence, and generate production-ready remediations (e.g., automated Pull Requests for dependency updates and config drift).
  3. Build Exposure Intelligence: Develop systems that correlate vulnerabilities with runtime context and infrastructure topology (Kubernetes/AWS) to accurately model real-world blast radius and ensure engineers only fix what is actually exploitable.
  4. Automate Triage & Self-Healing: Create "paved roads" and CI/CD guardrails that prevent specific vulnerability categories from ever reaching production, reducing manual toil for the entire engineering organization.
  5. Lead Emergency Response: Orchestrate the technical response to high-impact zero-days by rapidly performing cross-environment blast-radius analysis.

Skills

Required

  • 5+ years in Security Engineering
  • Hands-on experience building or deploying agentic systems or LLM orchestration frameworks
  • Strong software engineering background with proficiency in Go or Python
  • Deep knowledge of securing AWS and Kubernetes-based architectures
  • High familiarity with vulnerability categories, exploitability, and modern risk frameworks (CVSS, EPSS, CISA KEV)

Nice to have

  • Experience navigating security in highly regulated or high-growth financial environments
  • Experience implementing "Security as Code" within large-scale CI/CD environments

What the JD emphasized

  • AI agents
  • agentic systems
  • LLM orchestration frameworks
  • LLM-powered summarization

Other signals

  • AI agents for security
  • LLM for summarization
  • Automated remediation