About the company
Roblox is a global platform bringing millions of people together through shared experiences. Our mission is to connect a billion people with optimism and civility.
Responsibilities
- Perform offensive security assessments: conducting full-stack security assessments across our entire technology stack, including web applications, APIs, cloud infrastructure, and backend systems.
- Drive detection engineering partnerships: collaborating with detection engineers through purple team exercises, attack simulations, and threat emulation to validate and improve detection coverage.
- Develop custom tools and frameworks: creating and maintaining security testing tools, BAS frameworks, and automation scripts that enable repeatable testing and quantifiable security improvements.
- Build security metrics: designing and implementing frameworks to measure security control effectiveness, detection coverage, and improvement over time through consistent testing methodologies.
- Research and innovate: staying current with latest attack techniques, tools, and methodologies while contributing to both offensive and defensive security improvements.
- Broadly collaborate: sharing knowledge across security teams and fostering a culture of continuous security improvement.
Requirements
- 4+ years of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration.
- Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management.
- Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems.
- Platform expertise: implementing and managing breach attack simulation platforms while working with detection engineering teams to validate and improve detection coverage.
- Deep understanding of OWASP Top 10 vulnerabilities, common attack techniques, exploit development, post-exploitation methodologies, security assessment frameworks (MITRE ATT&CK, PTES), BAS methodologies, and modern detection stack components (EDR, SIEM, XDR).
- Knowledge of security concepts including reverse engineering, cloud security (AWS/Azure/GCP), container security, CI/CD pipeline security, API security, and security metrics development.
- Certifications such as OSCP, OSCE, GXPN, or equivalent practical experience.
- Strong analytical and problem-solving abilities, excellent technical writing, ability to clearly communicate complex technical concepts, self-motivated with a passion for offensive security and detection engineering.
Conditions
- Hybrid role: onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday.
- Annual salary range: $196,750 — $243,290 USD (as per similar roles).
- Eligible for equity compensation and benefits.