Skip to content
← Back to job listings

Staff Security Engineer (Product)

Rogo · New York, United States

External listingfull-time19 days ago

About The Role

Join Rogo as a Staff Security Engineer (Product) and play a key role in strengthening the security of our AI-driven platform. You will identify and address vulnerabilities, integrate security into the software development lifecycle, and provide guidance to stakeholders. Your responsibilities will include designing and building backend systems, performing security reviews, and responding to security incidents. You should have experience in application security testing, backend engineering, and cloud security.

  • Identifying and addressing vulnerabilities through code reviews, penetration testing, and security assessments.
  • Partnering closely with development teams to integrate security into the software development lifecycle, ensuring secure coding practices.
  • Designing, building, and maintaining backend features, frameworks, services, and automation that enforce security controls across the platform.
  • You’ve integrated automated checks into CI/CD pipelines (SCA, SAST, DAST)
  • Strong communication skills and ability to collaborate with developers, product teams, and leadership
  • You’re comfortable working with infrastructure automation (Terraform or equivalents)
  • Understanding of security frameworks such as SOC 2, CIS Benchmarks, ISO 27001/42001, or NIST CSF
  • Worked as a backend engineer owning systems, services, or platforms, building security capabilities directly into those systems
  • Strong backend engineer whose primary job is to design, build, and maintain the abstractions, tooling, and guardrails that allow the entire engineering team to ship product securely by default, without slowing down velocity
  • Demonstrated deep experience in application security testing, penetration testing, and code review
  • You’ve worked with, or are excited to learn, tools that help you understand how systems behave under stress or misuse (security-specific tools like Burp, ZAP, or Snyk are a plus)
  • Applied knowledge of threat modeling, cryptography fundamentals, and vulnerability management
  • Professional experience developing in a strongly typed language (e.g., Rust, C++, Java)
  • Familiarity with Kubernetes security (RBAC, admission controllers, ingress, and network policies)
  • Hands-on cloud security experience in AWS or GCP
  • Customer facing meetings when deep dive sessions are needed
  • You thrive in fast-paced environments. You are high-intensity and care a lot about what you do, and you're ecstatic to work at a startup
  • You are an owner. You are autonomous, self-directed, and comfortable working with ambiguity
  • You are ambitious. You have fun solving problems that others think are impossible
  • You are curious. You find joy in learning about AI, technology, and finance
  • You are collaborative, organized, thoughtful, and kind

This is an external listing. JobSpring does not represent or verify the employer. Report this listing