Senior Application Security Engineer

  • San Mateo, CA
  • Posted 9 hours ago | Updated 9 hours ago

Overview

On Site
USD 212,430.00 - 263,890.00 per year
Full Time

Skills

3D Computer Graphics
Positive Attitude
Stacks Blockchain
Reporting
Management
Partnership
Security Awareness
Evaluation
Communication
Penetration Testing
Continuous Integration
Continuous Delivery
OWASP
Test Methods
Software Security
Writing
Golang
C#
Scripting Language
Bash
Lua
Python
Cryptography
PKI
TLS
Threat Modeling
Software Development
Internet
Network
Server Hardware
Linux
Microsoft Windows
Operating Systems
WINS
Training
Genetics

Job Details

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences- all created by our global community of developers and creators.

At Roblox, we're building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device.We're on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.

A career at Roblox means you'll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.

As a Senior Application Security Engineer, you will take on ownership of engagement projects with opportunities across various tech stacks; strive to discover gaps and enable secure designs and mitigations. You will have the opportunity to tackle projects for automating and scaling out the way application security is conducted across the company. This is a hybrid in-office role and will report directly to the Engineering Manager of the Application Security team.
You will:
  • Direct and assist Product Security guidance and process.
  • Define how we establish, grow, and expand our partnerships with critical Roblox engineering organizations.
  • Contribute to the ramp-up of Trust-by-Design security work as well as security awareness programming.
  • Conduct Bug Bounty issue evaluation, reproduction, and recommendations!
  • Help develop and deliver Security Education and Training - prepare materials and communication through diverse parts of the organization.
  • Plan and perform penetration testing!
  • Write secure libraries or code patches where appropriate - especially scale secure code practices or prototype examples.
  • Build and maintain CI/CD secure tooling and support other security tools as well as automate tools and processes.
  • Test application code with the OWASP Testing Methodology.
You have:
  • 4 plus years of professional experience in application security.
  • Experience writing and maintaining code in at least one programming language such as Python, Golang or C#, and you want to learn new languages and technologies.
  • Experience with at least one scripting language (Bash, Lua, Python).
  • Applied knowledge of cryptography, PKI, TLS and practical implementation of the same.
  • Performed threat modeling and have experience of common code and network vulnerability types, impacts, and remediations.
  • Experience with Secure Software Development Life Cycles.
  • Knowledge of product security and integrations.
  • Experience operationalizing and communicating security best practices within a large-scale Internet environment.
  • Familiarity with network and server hardware.
  • Knowledge of Linux and Windows operating systems and security.
You are:
  • Team-oriented: a collaborative teammate who enjoys working with others.
  • Passionate about security: You have experience with security principles and understand the value they provide the organization.
  • Always taking the long view: You prioritize making changes that have a long-term impact, as opposed to focusing on short-term wins.

For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.

Annual Salary Range

$212,430-$263,890 USD

Roles that are based in our San Mateo, CA Headquarters are in-office Tuesday, Wednesday, and Thursday, with optional in-office on Monday and Friday (unless otherwise noted).

Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations for all candidates during the interview process.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.