Staff Offensive Security Engineer

Robinhood
Toronto, CanadaPosted 11 February 2026

Job Description

<div class="content-intro"><h2>Join us in building the future of finance.</h2> <p>Our mission is to democratize finance for all. <a href="https://www.cerulli.com/press-releases/cerulli-anticipates-124-trillion-in-wealth-will-transfer-through-2048" target="_blank">An estimated $124 trillion of assets</a> will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading.</p></div><h2><strong>About the team + role</strong></h2> <p>The Offensive Security team at Robinhood is responsible for proactively identifying and validating security risks across our products, infrastructure, and corporate environment. Situated within the Safety & Productivity Engineering organization, the team partners closely with engineering, detection and response, privacy, and physical security to strengthen Robinhood’s overall security posture. Our work is grounded in ethical testing, clear risk communication, and close collaboration to ensure findings lead to real improvements. We operate with high standards, direct ownership, and a shared commitment to protecting our customers and the company.</p> <p>As a Staff Offensive Security Engineer, you will focus on red teaming, adversarial simulation, and hands-on security testing to evaluate real-world threats against Robinhood’s systems and processes. You will design and execute offensive security engagements that challenge assumptions and improve detection and response capabilities. This role emphasizes depth of technical execution, clear communication of risk, and partnership with teams to remediate findings—not just identify them!</p> <p><strong>The role is located in the office location(s) listed on this job description which will align with our in-office working environment. Please connect with your recruiter for more information regarding our in-office philosophy and expectations.</strong></p> <h2><strong>What you’ll do</strong></h2> <ul> <li>Plan and execute red team operations, adversarial simulations, and penetration tests across applications, infrastructure, networks, offices, and internal processes.</li> <li>Perform threat modeling for new and existing services, clearly articulating security risks and tradeoffs to engineering and risk stakeholders.</li> <li>Conduct vulnerability research, exploit development, and testing using both custom tooling and public proof-of-concept techniques.</li> <li>Partner with detection and response teams to simulate realistic attack scenarios and evaluate monitoring and incident response readiness.</li> <li>Write and maintain tooling to automate and scale offensive security assessments.</li> <li>Serve as a subject matter expert by documenting findings, recommending remediation strategies, and supporting teams through fixes.</li> <li>Mentor teammates and contribute to shared knowledge through internal documentation, presentations, and external talks or blog posts.</li> </ul> <h2><strong>What you bring</strong></h2> <ul> <li>8+ years of hands-on experience in red teaming, offensive security, or penetration testing.</li> <li>Demonstrated experience mentoring or guiding other security engineers.</li> <li>Strong understanding of threat modeling methodologies and the MITRE ATT&CK framework.</li> <li>Experience testing modern environments, including cloud platforms (AWS, GCP), containerized systems (Docker, Kubernetes), CI pipelines, and identity systems.</li> <li>Working knowledge of defensive security tools such as IDS/IPS, EDR, packet capture, and network monito ... (truncated, view full listing at source)