Principal Enterprise Security Engineer
Job description
About the role
Roblox is seeking a Principal Enterprise Security Engineer to advance and shape the company's enterprise security strategy while ensuring alignment with broader business goals. In this senior technical position, you will be responsible for designing, implementing, and governing security solutions that protect Roblox's corporate infrastructure and enable secure, scalable operations across the organization. You will work closely with teams including Corporate Engineering and Trust & Safety to translate organizational priorities into robust security capabilities that effectively balance risk management, regulatory compliance, and workforce productivity. This role sits within the Platform, Enterprise, and Application Security group and reports to the Senior Manager of Enterprise Security Engineering, offering the opportunity to collaborate with security professionals throughout the InfoSec organization and drive initiatives that scale alongside the business.
Key facts
What you'll do
- Define, document, and maintain enterprise-wide security standards and guiding principles that inform how security controls are implemented across business workflows, ensuring consistency, scalability, and alignment with the organization's overall risk posture.
- Lead strategic initiatives across multiple core security domains including Endpoint Security, SaaS Security, Identity and Access Management, Agentic AI Governance, and Supply Chain Security, driving each from concept through deployment and ongoing optimization.
- Partner with IT, engineering, DevOps, and business stakeholders to embed security tools, policies, and processes into enterprise systems and workflows, enabling secure-by-design implementations that do not impede productivity.
- Architect and operationalize security policies, principles, and technical controls across diverse teams and systems, ensuring that security requirements are clearly communicated and consistently enforced.
- Serve as a trusted advisor and mentor to engineers and stakeholders across the organization, providing guidance on security architecture, control design, and secure implementation patterns.
- Evaluate and recommend commercial security solutions, defining clear business requirements and conducting build-versus-buy analyses to inform procurement and development decisions.
- Collaborate with compliance and audit teams to ensure security controls satisfy regulatory frameworks such as SOC 2 and ISO 27001, supporting evidence collection and remediation efforts as needed.
- Design and operate workflows using low-code and no-code orchestration platforms to automate security processes, improve response times, and reduce manual overhead.
- Conduct threat modeling exercises and risk assessments to identify vulnerabilities in corporate infrastructure, SaaS applications, and identity systems, then develop mitigation strategies.
- Stay current with emerging threats, industry trends, and best practices in enterprise security, translating new knowledge into actionable improvements for the organization.
- Contribute to incident response activities when necessary, providing technical expertise and leadership during security events affecting corporate systems.
- Drive continuous improvement of security monitoring, detection, and response capabilities across the enterprise environment.
Requirements
- At least nine years of relevant professional experience in enterprise security, information security engineering, or a closely related field.
- Deep expertise in Identity and Access Management, including authentication and authorization mechanisms, single sign-on, multi-factor authentication, and privileged access management.
- Strong hands-on experience with endpoint management solutions, network security controls, and SaaS security posture management tools.
- Solid understanding of security concepts including zero trust architecture, threat modeling methodologies, and security frameworks such as SOC 2 and ISO 27001.
- Demonstrated ability to design, implement, and operationalize security policies and controls across diverse teams, systems, and business units.
- Experience working with modern enterprise infrastructure and SaaS ecosystems, including Google Workspace, Okta, mobile device management solutions, security service edge platforms, and cloud-native environments.
- Proven track record of collaborating effectively with cross-functional partners including IT, engineering, DevOps, and business stakeholders.
- Ability to gather data, navigate complex situations, and make sound decisions even when facing incomplete information or ambiguous requirements.
- Excellent communication skills with the ability to articulate technical concepts to both technical and non-technical audiences.
- Strategic mindset with the ability to balance security requirements against business objectives and user experience considerations.
Nice to have
- Experience designing or operating workflows using low-code and no-code orchestration platforms such as Tines, Torq, or similar automation tools.
- Familiarity with Agentic AI Governance and emerging security considerations related to autonomous AI systems.
- Background in supply chain security, including software bill of materials, vendor risk management, and third-party security assessments.
- Prior experience in a high-growth technology company or consumer-facing platform with large-scale infrastructure.
- Relevant certifications such as CISSP, CISM, or cloud security credentials.
- Experience contributing to security architecture for gaming, social, or metaverse platforms.
Skills & tools
- Identity and Access Management platforms including Okta, Azure AD, and Google Workspace
- Endpoint security and mobile device management solutions
- SaaS security posture management tools
- Zero trust architecture frameworks and implementations
- Network security controls and segmentation strategies
- Security frameworks including SOC 2, ISO 27001, and NIST
- Threat modeling methodologies
- Low-code and no-code orchestration platforms
- Cloud-native environments and infrastructure
- Security monitoring and detection tools
Practical notes
- This position is based at Roblox headquarters in San Mateo, California, with a hybrid work arrangement requiring onsite presence Tuesday, Wednesday, and Thursday each week; Monday and Friday attendance is optional.
- The annual base salary ranges from $293,800 to $343,340 USD, with actual compensation determined by factors including professional background, training, work experience, location, business needs, and market demand; in some circumstances the actual salary may fall outside this range.
- Full-time employees receive equity compensation in addition to base salary, along with a comprehensive benefits package.
- Candidates should be aware that the company may not be able to employ individuals whose United States work authorization is tied to certain visa categories, and H-1B sponsorship is not currently available for this role.
- Roblox is an equal opportunity employer and provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.
- The company is building tools and a platform that empower a global community of developers and creators to bring immersi
About the company
An online space lets people build and play games. Founded long ago by two creators, it grew into a shared world opened to everyone in the mid 2000s. Now reaching millions each day, it hosts games made by its users. A large share of young American children under sixteen are monthly players here. High daily activity shows a lasting community where creativity and shared play remain central.