robinhood
Staff Offensive Security Engineer
At a Glance
- Location
- Canada
- Experience
- 8+ years
- Posted
- 2026-02-12T13:13:58-05:00
Key Requirements
Required Skills
Domain Knowledge
- Automation
- Finance
Requirements
8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
Strong understanding of threat modeling methodologies and the MITRE ATT&CK framework.
Experience testing modern environments, including cloud platforms (AWS, GCP), containerized systems (Docker, Kubernetes), CI pipelines, and identity systems.
Working knowledge of defensive security tools such as IDS/IPS, EDR, packet capture, and network monitoring, including common evasion techniques.
Proficiency in Python, Go, or JavaScript for exploit development, tooling, or automation.
Prior experience serving as a technical lead on security initiatives.
Responsibilities
Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.
Perform threat modeling for new and existing services, clearly articulating security risks and tradeoffs to engineering and risk stakeholders.
Conduct vulnerability research, exploit development, and testing using both custom tooling and public proof-of-concept techniques.
Partner with detection and response teams to simulate realistic attack scenarios and evaluate monitoring and incident response readiness.
Write and maintain tooling to automate and scale offensive security assessments.
Serve as a subject matter expert by documenting findings, recommending remediation strategies, and supporting teams through fixes.
Team
The Offensive Security team at Robinhood is responsible for proactively identifying and validating security risks across our products, infrastructure, and corporate environment. Situated within the Safety & Productivity Engineering organization, the team partners closely with engineering, detection and response, privacy, and physical security to strengthen Robinhood’s overall security posture. Our work is grounded in ethical testing, clear risk communication, and close collaboration to ensure findings lead to real improvements. We operate with high standards, direct ownership, and a shared commitment to protecting our customers and the company.
As a Staff Offensive Security Engineer, you will focus on red teaming, adversarial simulation, and hands-on security testing to evaluate real-world threats against Robinhood’s systems and processes. You will design and execute offensive security engagements that challenge assumptions and improve detection and response capabilities. This role emphasizes depth of technical execution, clear communication of risk, and partnership with teams to remediate findings—not just identify them!
The role is located in the office location(s) listed on this job description which will align with our in-office working environment. Please connect with your recruiter for more information regarding our in-office philosophy and expectations.