Engineering Manager, Application Security
Job description
About the role
As an Engineering Manager for Application Security at Roblox, you will play a pivotal role in safeguarding our platform and ensuring the integrity of our applications. You will lead a dedicated team of security engineers focused on identifying vulnerabilities, implementing security measures, and fostering a culture of security awareness across the organization. Your expertise will guide the development of secure coding practices, threat modeling, and incident response strategies, ultimately contributing to the protection of millions of users worldwide.
Key facts
What you'll do
- Lead and mentor a team of application security engineers, fostering a collaborative and innovative environment that encourages professional growth and knowledge sharing.
- Develop and implement security strategies and best practices that align with Roblox's overall security posture and business objectives.
- Collaborate closely with cross-functional teams, including software engineering, product management, and operations, to integrate security into the software development lifecycle.
- Conduct regular security assessments, including code reviews, penetration testing, and vulnerability scanning, to identify and remediate security weaknesses in applications.
- Establish and maintain security metrics and reporting mechanisms to track the effectiveness of security initiatives and communicate findings to stakeholders.
- Drive the adoption of secure coding standards and practices across development teams, providing training and resources to enhance security awareness.
- Respond to security incidents and breaches, leading investigations and coordinating with relevant teams to mitigate risks and implement corrective actions.
- Stay informed about the latest security threats, vulnerabilities, and industry trends, ensuring that Roblox remains proactive in its security efforts.
- Collaborate with external security researchers and organizations to enhance the security of the Roblox platform through bug bounty programs and partnerships.
- Advocate for security within the organization, promoting a culture of security awareness and responsibility among all employees.
- Participate in the development of security policies and procedures, ensuring compliance with industry regulations and standards.
- Contribute to the continuous improvement of security tools and processes, identifying opportunities for automation and efficiency gains.
Requirements
- Proven experience in application security, with a strong understanding of secure software development practices and methodologies.
- At least 5 years of experience in a technical role within security engineering or a related field, with a track record of leading teams.
- Familiarity with security frameworks and standards, such as OWASP, NIST, and ISO 27001.
- Strong knowledge of programming languages such as Python, Java, or C#, and experience with web application security testing tools.
- Excellent problem-solving skills and the ability to think critically about security challenges and solutions.
- Strong communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences.
- Experience with incident response and management, including the ability to lead investigations and coordinate with multiple stakeholders.
Nice to have
- Relevant security certifications, such as CISSP, CISM, or CEH, that demonstrate your commitment to the field.
- Experience working in an Agile development environment, with familiarity in DevSecOps practices.
- Knowledge of cloud security principles and experience with cloud platforms such as AWS, Azure, or Google Cloud.
- Previous experience in the gaming industry or with consumer-facing applications is a plus.
Skills & tools
- Proficiency in security tools such as static and dynamic analysis tools, vulnerability scanners, and penetration testing frameworks.
- Familiarity with CI/CD pipelines and tools that integrate security into the development process.
- Strong analytical skills and the ability to assess risk and prioritize security initiatives effectively.
- Experience with threat modeling methodologies and risk assessment frameworks.
Practical notes
- This position is based in San Mateo, CA, and may require occasional travel for conferences or team-building activities.
- The role may involve working outside of standard business hours in response to security incidents or urgent projects.
- Candidates must be eligible to work in the United States and may require sponsorship for a work visa.
Join Roblox and be part of a team that is dedicated to creating a safe and secure environment for our users. Your leadership in application security will help shape the future of our platform and ensure that we continue to provide a trusted experience for millions of players around the globe.