Roblox - San Mateo, CA

posted about 1 month ago

Full-time - Senior
San Mateo, CA
Professional, Scientific, and Technical Services

About the position

At Roblox, we are on a mission to connect a billion people with optimism and civility through immersive digital experiences. As a Senior Application Security Engineer, you will play a crucial role in ensuring the security of our applications and the safety of our community. This position involves taking ownership of various engagement projects across different tech stacks, identifying security gaps, and enabling secure designs and mitigations. You will have the opportunity to automate and scale application security practices across the company, contributing to a safer environment for our users. In this role, you will direct and assist in Product Security guidance and processes, defining how we establish and expand partnerships with critical engineering organizations within Roblox. You will contribute to the ramp-up of Trust-by-Design security initiatives and security awareness programming, ensuring that security is integrated into our development processes. Your responsibilities will include conducting evaluations of Bug Bounty issues, providing recommendations, and developing security education and training materials to communicate best practices across the organization. You will also plan and perform penetration testing, write secure libraries or code patches, and build and maintain CI/CD secure tooling. Testing application code using the OWASP Testing Methodology will be a key part of your role, ensuring that our applications are resilient against vulnerabilities. This hybrid in-office role will report directly to the Senior Engineering Manager of the Application Security team, allowing you to collaborate closely with other security professionals and engineers to enhance our security posture.

Responsibilities

  • Direct and assist Product Security guidance and process.
  • Define how to establish, grow, and expand partnerships with critical Roblox engineering organizations.
  • Contribute to the ramp-up of Trust-by-Design security work and security awareness programming.
  • Conduct Bug Bounty issue evaluation, reproduction, and recommendations.
  • Help develop and deliver Security Education and Training materials and communication.
  • Plan and perform penetration testing.
  • Write secure libraries or code patches where appropriate.
  • Build and maintain CI/CD secure tooling and support other security tools.
  • Test application code with the OWASP Testing Methodology.

Requirements

  • 4 plus years of professional experience in application security.
  • Experience writing and maintaining code in at least one programming language such as Python, Golang, or C#.
  • Experience with at least one scripting language (Bash, Lua, Python).
  • Applied knowledge of cryptography, PKI, TLS, and practical implementation of the same.
  • Performed threat modeling and have experience with common code and network vulnerability types, impacts, and remediations.
  • Experience with Secure Software Development Life Cycles.
  • Knowledge of product security and integrations.
  • Experience operationalizing and communicating security best practices within a large-scale Internet environment.
  • Familiarity with network and server hardware.
  • Knowledge of Linux and Windows operating systems and security.

Nice-to-haves

  • Team-oriented and collaborative mindset.
  • Passionate about security principles and their organizational value.
  • Long-term impact focus over short-term wins.

Benefits

  • Industry-leading compensation package
  • Excellent medical, dental, and vision coverage
  • A rewarding 401k program
  • Flexible vacation policy
  • Roflex - Flexible and supportive work policy
  • Roblox Admin badge for your avatar
  • Free catered lunches five times a week
  • Several fully stocked kitchens with unlimited snacks
  • Onsite fitness center and fitness program credit
  • Annual CalTrain Go Pass
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service