Senior Security Engineer, Detection and Response
Job description
About the role
This role is responsible for designing detection logic and owning incident command for the EMEA region. The position demands autonomous decision-making and deep technical follow-through to protect players and the platform through precise, scalable monitoring. You will be a foundational member of the Security Operations team, establishing and maintaining a 24/7/365 monitoring and response capability.
Work Environment
This role is based in London, England, United Kingdom. You will be working from a dedicated, private space located within a shared office environment, designed to enable collaboration while remaining secure.
Key Facts
What You Will Do
You will design, write, and maintain production-quality detections, automations, and integrations. This work reduces manual toil and scales monitoring capability across a global user base. You will guide follow-the-sun hand-offs, ensuring alert quality and enrichment to support reliable global response coverage.
As the primary Incident Commander for the European time zone, you will make critical, time-sensitive decisions independently before US headquarters opens. You will architect risk-based prioritization and detections-as-code to automate security workflows efficiently. Conducting forensic investigations and threat hunting, you will distinguish genuine threats from legitimate outliers in complex data sets.
You will lead responses to major vulnerabilities or platform-wide events in collaboration with engineering partners. This work is conducted under strict confidentiality. Coordination with legal teams, external partners, customers, and developers is a core duty. You will travel to the US headquarters for alignment and planning. Reviewing case outcomes and lessons learned, you will convert these insights into durable detection logic to prevent future incidents.
Requirements
You must have three to five years of experience building detections and operating response processes. You must possess a thorough understanding of log sources, data pipelines, and enrichment for security monitoring. You must be able to write SOAR playbooks and integrations that scale across global teams.
You must be capable of working independently across time zones with minimal supervision. You must conduct detailed forensic analysis during complex security incidents, making decisive judgments under pressure.
Nice to Have
Experience traveling to US headquarters for security alignment is valued.
Skills and Tools
Proficiency with Splunk SOAR (Phantom), Palo Alto Cortex XSOAR, ServiceNow, Jira, PagerDuty, and Slack is required.
The Mission
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences-all created by our global community of developers and creators. At Roblox, we are building the tools and platform that empower our community to bring any experience they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We are on a mission to connect a billion people with optimism and civility.
A career at Roblox means you will be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a founding member of the Security Operations team in EMEA, you will join us at an exciting time in our Security Operations & Incident Response program. You will serve as a primary decision-maker, core to our mission to maintain a highly capable 24/7/365 monitoring and response capability. While you will work in close collaboration with peers at our US West Coast Headquarters, the time difference requires an engineer who can operate independently. We favor engineering our way out of toil through automation, orchestration, detections-as-code, and risk-based prioritization, while retaining the deep technical skills required to conduct detailed, hands-on analysis and lead response end-to-end when necessary.