About the company
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device.
We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
Responsibilities
- Integrate security into CI/CD pipelines and drive secure-by-default engineering practices
- Design and build security controls, libraries, and guardrails directly in code
- Develop and scale automated security tooling across CI/CD (SAST, dependency scanning, secrets detection, fuzzing, etc.)
- Build and improve detection and prevention mechanisms for abuse, data exfiltration, and supply chain risks
- Automate vulnerability triage, prioritization, and remediation workflows at scale
- Integrate security into developer workflows and internal platforms to reduce friction and increase adoption
- Design and implement security controls for agentic and AI-assisted workflows, building guardrails to mitigate risks such as prompt injection, data exfiltration, and misuse of developer and system privileges
- Contribute to secure system design and architecture reviews, including threat modeling for new products and features
Requirements
- 6+ years of experience in software engineering, application security, or security engineering
- Strong coding skills in at least one language (e.g., Python, Go, C#, JavaScript, Rust, C++)
- Build and scale security automation in CI/CD pipelines (SAST, SCA, secrets detection, and fuzzing)
- Solid understanding of application security fundamentals (OWASP Top 10, auth models, common vulnerabilities and mitigations)
- Background with cloud environments, and modern architectures (microservices, APIs)
- Working knowledge of Linux/Windows systems, networking fundamentals, and system-level security
- Experience designing and implementing secure, scalable systems, including APIs, microservices, and distributed architectures
- Ability to translate security risks into practical, scalable engineering solutions
- Bachelor’s degree in a relevant field or equivalent practical experience
Nice to Have:
- Experience building security platforms, tools, or developer frameworks
- Knowledge of cryptography, PKI, TLS, and secure implementations
- Experience with container security and Kubernetes
- Experience building internal security platforms or developer tooling
- Background of supply chain security (SBOMs, signing, provenance, build integrity)
Conditions
- Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).
- All full-time employees are also eligible for equity compensation and for benefits.