Confirmed on the employer's own hiring board on Oct 10, 2026. First seen by Alion on Jul 18, 2026.
Join Rogo as a Security Engineer, where you'll be responsible for offensive security practices, including penetration testing, red team exercises, and adversarial security assessments. You'll build intelligent security automation, contribute to the codebase, and partner with development teams to enhance security measures. Your role will involve deep adversarial testing of AI-specific attack surfaces, vulnerability research, threat modeling, and collaboration with external pen test firms.
Missions
- Conduct deep-dive penetration testing, red team exercises, and adversarial security assessments against Rogo's AI-driven platform, APIs, and cloud infrastructure.
- Build intelligent security automation to scale offensive testing, triage findings, and embed continuous security validation directly into the engineering workflow.
- Own vulnerability research and bug hunting across the product, go beyond scanner output to find the logic flaws, auth bypasses, and chained exploits that automated tools miss.
Profil recherché
- Are comfortable with infrastructure automation (Terraform, Kubernetes) and can identify misconfigurations and attack paths in AWS/GCP environments- Communicate crisply and can collaborate effectively with developers, product teams, and leadership
- Have integrated automated security checks into CI/CD pipelines (SCA, SAST, DAST) and understand how to give developers fast, actionable feedback without blocking velocity
- Have applied knowledge of threat modeling, cryptography fundamentals, and compliance frameworks (SOC 2, ISO 27001/42001, NIST CSF)
- Have professional development experience in a strongly typed language (e.g., Rust, Go, Java, C++) alongside scripting languages (Python, Bash) for exploit development and tooling
- Have built or are excited to build agentic security tooling that autonomously finds, validates, and patches vulnerabilities, minimizing human-in-the-loop remediation
- Are comfortable with Burp Suite, Nuclei, Semgrep, custom fuzzing frameworks, and building your own tools when off-the-shelf doesn't cut it
- Have professional penetration testing experience across web apps, APIs, cloud environments, and ideally AI/ML systems. You've written real exploits, not just run scanners
- You thrive in fast-paced environments. You are high-intensity and care a lot about what you do, and you're ecstatic to work at a startup
- You are curious. You find joy in learning about AI, technology, and finance
- You are collaborative, organized, thoughtful, and kind
- You are an owner. You are autonomous, self-directed, and comfortable working with ambiguity
- You are ambitious. You have fun solving problems that others think are impossible
- OSCP, OSWE, GXPN, GWAPT, CPTS, or similar offensive security certifications
- Experience testing multi-tenant SaaS platforms serving regulated industries (financial services is a strong plus)
- Hands-on cloud penetration testing experience in AWS or GCP (privilege escalation, cross-account attacks, metadata abuse)
- Bug bounty track record or published CVEs / security research
- Kubernetes security testing (RBAC abuse, container escapes, admission controller bypasses, network policy evasion)
- Experience in customer-facing security conversations, deep-dive technical sessions, pen test debrief calls, and security architecture reviews

