Staff Offensive Security Engineer

Robinhood Robinhood · Fintech · Bellevue, WA +1 · Security Division

Staff Offensive Security Engineer at Robinhood, focusing on red teaming, adversarial simulations, and penetration testing to identify and mitigate security risks in financial platforms. Responsibilities include threat modeling, vulnerability research, exploit development, and creating automation tools, with a strong emphasis on collaboration and mentoring.

What you'd actually do

  1. Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.
  2. Perform threat modeling for new and existing services, clearly articulating security risks and tradeoffs to engineering and risk stakeholders.
  3. Conduct vulnerability research, exploit development, and testing using both custom tooling and public proof-of-concept techniques.
  4. Partner with detection and response teams to simulate realistic attack scenarios and evaluate monitoring and incident response readiness.
  5. Write and maintain tooling to automate and scale offensive security assessments.

Skills

Required

  • 8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
  • Demonstrated experience mentoring or guiding other security engineers.
  • Strong understanding of threat modeling methodologies and the MITRE ATT&CK framework.
  • Experience testing modern environments, including cloud platforms (AWS, GCP), containerized systems (Docker, Kubernetes), CI pipelines, and identity systems.
  • Working knowledge of defensive security tools such as IDS/IPS, EDR, packet capture, and network monitoring, including common evasion techniques.
  • Proficiency in Python, Go, or JavaScript for exploit development, tooling, or automation.
  • Clear written and verbal communication skills, with the ability to explain technical findings to both engineers and senior leaders.
  • Experience collaborating with distributed teams and documenting work through tools such as Slack, Jira, GitHub, and email.

Nice to have

  • Experience working in financial technology or regulated environments.
  • Prior experience serving as a technical lead on security initiatives.

What the JD emphasized

  • 8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
  • Demonstrated experience mentoring or guiding other security engineers.