About the company
Robinhood was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood is lowering barriers and providing greater access to financial information. Together, we are building products and services that help create a financial system everyone can participate in.
Job Summary
What you’ll do
📍Conduct and lead detailed technical risk assessments with application developers, platform engineers, and security teams to uncover insecure coding practices, architectural vulnerabilities, or third-party technology risks 📍Assess risks at the network, infrastructure, and application levels—including traffic flows, API misuse, misconfigured cloud resources, or exposed endpoints 📍Design and maintain frameworks that translate engineering-level risks (e.g., data leakage from flawed encryption, weak access control patterns) into business-impacting scenarios and measurable risk statements 📍Serve as a trusted advisor on secure engineering principles, threat modeling, and secure software development lifecycle (SSDLC) governance 📍Collaborate with leadership across engineering, security, and product to ensure risk mitigation strategies are practical, adopted, and embedded into daily decision-making
What you bring
📍10+ years of experience in technology or cybersecurity risk management, ideally in regulated financial services (banks, fintechs, or broker-dealers) 📍Demonstrated technical depth in application development, secure coding principles, and software architecture risk identification 📍Strong working knowledge of networking fundamentals (e.g., DNS, firewalls, TLS, routing protocols), network segmentation, and cloud-native environments (e.g., AWS, Kubernetes) 📍Prior experience influencing engineering and infrastructure teams through clear articulation of technical risks and control requirements 📍Familiarity with NIST CSF, ISO 27001, OWASP, and secure code analysis tools (e.g., SAST, DAST, or SCA) 📍Strong communication, storytelling, and stakeholder engagement skills—especially when simplifying complex risk topics for executive audiences 📍Bonus Points: CISSP, CISM, CRISC, CISA or related security certifications, PMP or Agile-related certification, Series 7, 24, or 4 licensing
Looking for your next challenge? The world of crypto offers exciting roles in blockchain development, web3 innovations, and remote opportunities.





