Principal Security Software Engineer, Application Security
Job description
About the role
Roblox is seeking a Principal Security Software Engineer to join the Application Security team, reporting directly to the Manager of Application Security who oversees the Security Design and Review pod. This senior technical position involves partnering with engineering teams from the earliest stages of product development to embed secure design principles and establish organization-wide security standards. You will serve as a strategic leader driving critical security initiatives across the entire company, working with diverse technology stacks and collaborating with engineering leadership to address complex security challenges. The role combines hands-on technical work including threat modeling, penetration testing, and automation development with high-level strategic planning to scale application security practices across a platform that serves tens of millions of daily users exploring, creating, and connecting in immersive 3D experiences.
Key facts
What you'll do
- Spearhead enterprise-wide security initiatives that tackle the most pressing and critical security challenges facing the organization, ensuring comprehensive protection across all systems and platforms.
- Cultivate and maintain strong cross-functional relationships throughout the company to achieve security objectives and foster a culture of security awareness among engineering teams.
- Provide expert guidance on product security processes, standards, and best practices to ensure consistent implementation across all development efforts.
- Establish and expand strategic partnerships with key engineering teams across Roblox, serving as a trusted security advisor and technical resource.
- Apply rigorous critical thinking and analytical capabilities to develop robust security protocols while communicating complex concepts effectively to stakeholders at all levels.
- Conduct research and evaluation of emerging technologies, tools, and methodologies to continuously enhance the organization's overall security posture and defensive capabilities.
- Identify potential threats, vulnerabilities, and attack vectors within systems and data infrastructure, then develop and implement comprehensive solutions to safeguard these assets.
- Enable cross-functional teams to successfully implement security solutions that align with Trust-by-Design principles, ensuring security is built into products from the ground up.
- Contribute to security education and awareness programs by collaborating with teams across the organization to build and promote shared understanding of security practices.
- Shape and execute strategies to automate and scale application and product security efforts, improving efficiency while maintaining rigorous security standards.
- Design and secure autonomous agentic workflows, ensuring AI-powered systems operate safely within defined security boundaries.
- Perform application code testing following the OWASP Testing Methodology to identify vulnerabilities and ensure compliance with security standards.
- Mentor and guide other security engineers on the team, sharing knowledge and helping develop the next generation of security professionals.
Requirements
- Minimum of 8 years of professional experience in cybersecurity with deep expertise in application security, data encryption, and compliance with established security standards, along with solid knowledge of network and cloud security principles.
- Demonstrated expertise in articulating complex security challenges and proposed solutions to both technical teams and non-technical leadership in clear, understandable terms.
- Proven track record of building strong relationships and effectively influencing principal engineers and technical leaders across multiple teams and departments.
- Substantial experience in software and infrastructure architecture with a particular emphasis on security considerations and secure design patterns.
- Extensive hands-on experience with common code and network vulnerabilities, understanding their potential impacts and implementing effective remediation strategies.
- Proficiency in writing production-quality code in at least one programming language such as Python, Golang, or C#, combined with scripting capabilities in Bash or Python.
- Applied knowledge of cryptographic principles including PKI, TLS, and practical implementations of encryption technologies in real-world systems.
- Experience conducting threat modeling exercises and implementing Secure Software Development Life Cycle practices within engineering organizations.
- Demonstrated success in operationalizing security best practices within large-scale internet environments serving millions of users.
- Working familiarity with network and server hardware configurations, as well as security hardening for both Linux and Windows operating systems.
Nice to have
- Familiarity with secure deployment patterns for AI agents, including isolation strategies such as sandboxing and microVMs, secrets protection mechanisms, and comprehensive audit and logging capabilities for agent activities.
- Experience enabling safe AI adoption at enterprise scale, effectively balancing security requirements with developer productivity and organizational risk tolerance.
- Background in building security automation tools and frameworks that can scale across large engineering organizations.
- Experience with cloud-native security tools and practices across major cloud providers.
- Contributions to open-source security projects or published security research.
- Relevant security certifications such as OSCP, CISSP, or similar credentials.
Skills & tools
- Programming languages: Python, Golang, C#, Bash scripting
- Security frameworks: OWASP Testing Methodology, Secure Software Development Life Cycle
- Cryptography: PKI, TLS, data encryption, practical cryptographic implementations
- Infrastructure: Linux security, Windows security, network and server hardware, cloud security
- AI security: Agentic workflow security, sandboxing, microVMs, secrets management, audit logging
- Methodologies: Threat modeling, penetration testing, secure design review, vulnerability assessment and remediation
- Soft skills: Cross-functional collaboration, stakeholder communication, mentorship, strategic planning
Practical notes
- This position is based at Roblox headquarters in San Mateo, California, with a hybrid work arrangement requiring onsite presence on Tuesday, Wednesday, and Thursday each week.
- Monday and Friday office attendance is optional unless otherwise specified for particular meetings or events.
- Compensation includes a competitive base salary ranging from $326,060 to $385,050 USD annually, with actual pay determined by factors including professional background, training, work experience, location, business needs, and market demand.
- All full-time employees receive equity compensation in addition to base salary, providing opportunity to share in the company's growth and success.
- Comprehensive benefits package is included as described on the company's benefits page.
- Roblox is committed to equal employment opportunity and prohibits discrimination and harassment based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable laws.
- Reasonable accommodations are provided to candidates with qualifying disabilities or religious beliefs during the recruiti
About the company
An online space lets people build and play games. Founded long ago by two creators, it grew into a shared world opened to everyone in the mid 2000s. Now reaching millions each day, it hosts games made by its users. A large share of young American children under sixteen are monthly players here. High daily activity shows a lasting community where creativity and shared play remain central.