Principal Security Software Engineer, IAM
Job description
About the role
You will set the technical direction for how identity and access work across Roblox's production infrastructure, owning the strategy and execution for production IAM from mTLS-based service-to-service authentication to privileged engineer access. You will define multi-year roadmaps, drive architectural consistency across Roblox Platform, and mentor senior and staff engineers on the hardest identity and access challenges. In this role, you will personally build critical components of the machine identity platform, the centralized authorization engine, and the just-in-time access systems that keep production secure and reliable. As AI agents become first-class actors in production, you will pioneer how they obtain identity, prove who they are, and receive safely-scoped access across hybrid on-prem and cloud environments. You will ensure that secure access is invisible when it can be and intuitive when it needs attention, balancing security with developer experience at global scale. This is an opportunity to shape the future of human interaction and help connect a billion people with optimism and civility through robust identity infrastructure.
Key facts
What you'll do
Lead the architecture for production identity and access, defining and evolving the end-to-end design for machine, workload, human, and AI-agent identity across our hybrid on-prem and cloud fleet.
Drive mTLS and workload identity to full production enforcement, leading the technical strategy for our SPIFFE/SPIRE-based identity platform, service-mesh integration, managed service accounts, and certificate issuance, storage, and rotation.
Advance just-in-time, least-privilege access for engineers, architecting solutions that replace static, long-lived credentials with short-lived, auditable access that remains reliable even during dependency or identity-provider outages.
Evolve the centralized authorization engine and a secure golden path, maturing our access-control models including RBAC, ABAC, and risk-based access so decisions are consistent, fine-grained, and testable.
Pioneer identity and access for AI agents, defining how agents obtain credentials, receive scoped permissions, and have their sessions managed across their lifecycle.
Lead across the organization and raise the technical bar, authoring RFCs and multi-year roadmaps while aligning stakeholders across Roblox Platform.
Mentor senior and staff engineers, providing hands-on guidance during design reviews, on-call ownership, and hiring to build the strongest possible security engineering team.
Build the hardest parts of these systems yourself, taking ownership of end-to-end delivery for the most complex and impactful identity and access capabilities at Roblox.
Requirements
8+ years of relevant professional experience building scalable, distributed backend systems, with a track record of driving architecture end to end in production environments.
Deep expertise in identity and access management, including authentication, authorization, and access-control models such as RBAC, ABAC, or risk-based access control.
Hands-on experience with several of the following: PKI and certificate/key lifecycle management, mTLS, SPIFFE/SPIRE or comparable workload-identity systems, service mesh, secret management (e.g., Vault), and privileged access management (PAM).
Proficiency in at least one systems language such as Go, Rust, Java, C++, Python, or C# .NET, and a habit of building systems rather than only configuring vendor tools.
Experience leading the technical work of other engineers, including setting direction across teams, writing influential designs, and mentoring through code reviews and on-call responsibilities.
Strong understanding of production reliability and security tradeoffs, with a demonstrated ability to operate critical identity services at global scale under demanding uptime and audit requirements.
Comfort operating in ambiguous, fast-paced environments while maintaining rigorous security standards and clear documentation practices.
Excellent written and verbal communication skills for collaborating with cross-functional partners and articulating complex technical concepts to diverse audiences.
Practical notes
This is a full-time position based in San Mateo, California, United States.
Applicants must be authorized to work in the United States without sponsorship for this position.
No relocation assistance or visa sponsorship is available for this role.
Travel is not expected for this role.
Candidates must be able to start within 4 weeks of offer acceptance.
The engagement type is Full-time.
This role reports to the Principal Security Engineering Manager.
This role is not eligible for compensation data disclosure in the job posting.