обновлено 2 дня назад
Staff Offensive Security Engineer (Fintech)
191 250 - 225 000CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Offensive Security Engineer (Fintech): Designing and executing red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes with an accent on threat modeling, vulnerability research, exploit development, and detection validation. Focus on emulating sophisticated attackers, developing custom offensive tooling, evaluating incident response readiness, and strengthening security controls across cloud, containerized, and identity environments.
Location: Toronto, Canada; in-person attendance required at least 3 days per week
Base pay: CAD 191,250–225,000 per year, plus bonus opportunities, equity, and benefits
Company
Robinhood is building financial products intended to democratize finance and expand access to investing.
What you will do
- Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.
- Perform threat modeling for new and existing services and communicate security risks and tradeoffs to engineering and risk stakeholders.
- Conduct vulnerability research, exploit development, and testing using custom tooling and public proof-of-concept techniques.
- Partner with detection and response teams to simulate realistic attacks and evaluate monitoring and incident response readiness.
- Build and maintain tooling to automate and scale offensive security assessments.
- Document findings, recommend remediation strategies, mentor security engineers, and share knowledge through documentation, presentations, talks, or blog posts.
Requirements
- 8+ years of hands-on experience in red teaming, offensive security, or penetration testing.
- Experience mentoring or guiding other security engineers.
- Strong knowledge of threat modeling methodologies and the MITRE ATT&CK framework.
- Experience testing AWS or GCP environments, Docker and Kubernetes systems, CI pipelines, and identity systems.
- Knowledge of IDS/IPS, EDR, packet capture, network monitoring, and common evasion techniques.
- Proficiency in Python, Go, or JavaScript for exploit development, tooling, or automation, with strong written and verbal communication skills.
Nice to have
- Experience in financial technology or regulated environments.
- Experience serving as a technical lead on security initiatives.
Culture & Benefits
- High-impact work focused on strengthening security across a financial technology platform.
- Performance-driven compensation with bonus programs and equity ownership.
- Supplemental health, ancillary insurance, mental health support, and a flexible lifestyle wallet for wellness, childcare, learning, and other expenses.
- Paid time off, company holidays, sick time, paid volunteer time, and parental leave.
- Office meals, events, comfortable workspaces, and a monthly commuter stipend.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →