Back to Search
Overview
Principal

Principal Security Software Engineer, Application Security

Confirmed live in the last 24 hours

Roblox

Roblox

San Mateo, CA, United States
On-site
Posted April 8, 2026

Job Description

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. 

At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. 

A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.

As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You will play a pivotal role in shaping the growth of Information Security's (InfoSec) Application Security team, collaborating with engineering teams early in their processes to provide secure design solutions and establish security standards. Your responsibilities will include threat modeling, secure system design, automation, and penetration testing.

As a key member of the team, you will drive company-wide projects across diverse tech stacks, working with engineering leaders to remediate security challenges. You will define and evolve the technical vision for scaling application security practices across the organization.

You will:
  • Lead company-wide security initiatives to address critical security challenges.
  • Build and nurture cross-company relationships to achieve security objectives.
  • Provide guidance on product security processes and standards.
  • Define and expand partnerships with key engineering teams across Roblox.
  • Apply critical thinking and analytical skills to develop security protocols and communicate effectively with stakeholders.
  • Research and evaluate new technologies to enhance the company's security posture.
  • Identify potential threats and vulnerabilities in our systems and data, as well as help develop and implement solutions to safeguard them.
  • Enable cross-functional teams to implement security solutions aligned with Trust-by-Design principles.
  • Contribute to security education and awareness programs by partnering across teams to collaboratively build and promote shared understanding of security practices throughout the company.
  • Shape strategies to automate and scale application and product security efforts.
  • Design and secure autonomous agentic workflows.
  • Test application code following the OWASP Testing Methodology.
  • Mentor and guide other security engineers!

You have:

  • 8+ years of professional experience in cybersecurity, with a deep background in application security, data encryption, and compliance with security standards, as well as knowledge of network and cloud security.
  • Expertise in explaining complex security challenges and solutions to both technical and non-technical leadership.
  • Proven ability to build strong relationships and influence principal engineers across teams.
  • Experience in software and infrastructure architecture with a focus on security.
  • Extensive experience with common code and network vulnerabilities, their impacts, and remediation strategies.
  • Background in writing code in at least one programming language, such as Python, Golang, or C#, and a scripting language like Bash or Python.
  • Applied knowledge of cryptography, PKI, TLS, and practical implementations.
  • Experience with threat modeling and Secure Software Development Life Cycles.
  • Experience operationalizing security best practices in large-scale internet environments.
  • Familiarity with network and server hardware, as well as Linux and Windows security.
  • Familiarity with secure deployment patterns for AI agents, including isolation strategies (sandboxing, microVMs), secrets p
pythongorustawsaidataproductdesign