Назад
6 дней назад

Senior Security Software Engineer, Application Security

269 170 - 326 060$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Software Engineer, Application Security (CI/CD, AI): Building scalable application security controls, automation, libraries, and developer workflow integrations for Roblox with an accent on secure-by-default engineering, vulnerability management, and AI-assisted workflow protections. Focus on designing threat models, mitigating prompt injection and data exfiltration, and scaling security tooling across distributed systems.

Location: San Mateo, California, United States; office attendance is required Tuesday, Wednesday, and Thursday, with optional presence Monday and Friday

Salary: $269,170–$326,060 USD base pay annually

Company

Roblox builds a 3D immersive digital platform and tools that enable developers and creators to build interactive experiences for a global community.

What you will do

  • Integrate application security into CI/CD pipelines and developer workflows.
  • Design and build security controls, libraries, guardrails, and reusable engineering patterns.
  • Develop automated security tooling for SAST, dependency scanning, secrets detection, and fuzzing.
  • Build detection and prevention mechanisms for abuse, data exfiltration, and software supply chain risks.
  • Automate vulnerability triage, prioritization, and remediation workflows at scale.
  • Design security controls for AI-assisted and agentic workflows, including protections against prompt injection and privilege misuse.

Requirements

  • 6+ years of experience in software engineering, application security, or security engineering.
  • Strong coding skills in at least one language such as Python, Go, C#, JavaScript, Rust, or C++.
  • Experience building security automation in CI/CD pipelines, including SAST, SCA, secrets detection, and fuzzing.
  • Strong understanding of application security fundamentals, OWASP Top 10, authentication models, vulnerabilities, and mitigations.
  • Experience with cloud environments, microservices, APIs, distributed architectures, Linux or Windows, networking, and system-level security.
  • Bachelor’s degree in a relevant field or equivalent practical experience.

Nice to have

  • Experience building security platforms, tools, or developer frameworks.
  • Knowledge of cryptography, PKI, TLS, and secure implementations.
  • Experience with container security, Kubernetes, internal security platforms, or developer tooling.
  • Experience with supply chain security, including SBOMs, signing, provenance, and build integrity.

Culture & Benefits

  • Hands-on work focused on resilient, scalable security solutions rather than one-off fixes.
  • Close collaboration with engineering teams to balance security and developer productivity.
  • Participation in Application Security on-call rotations.
  • Full-time employees are eligible for equity compensation and company benefits.
  • For US-based roles, certain US visa categories may not be supported and future H-1B sponsorship may not be available.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →