# Senior Security Software Engineer, Application Security

[Roblox](https://gurify.com/jobs?q=Roblox) · San Mateo, CA · Posted 4 months ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/roblox/jobs/7896293)

## Job description

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.

At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.

A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.

The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards, build scalable controls, and enable product and infrastructure teams to operate securely by default. The Application Security team partners closely with engineering teams early in the development lifecycle to drive secure architectures, establish standards, and deliver scalable security solutions.

As a Senior Security Software Engineer - Application Security, you will be a hands-on engineer who designs, builds, and ships security solutions that integrate directly into developer workflows and platforms. You will play a key role in scaling application security through automation, CI/CD integrations, secure libraries, and reusable patterns.

In this role, you will help define how security is embedded across the software development lifecycle at Roblox, balancing deep technical work (threat modeling, code review, penetration testing) with systemic solutions that reduce risk at scale. You will also participate in AppSec on-call rotations and contribute to security tooling and platform evolution.

### You will:

- Integrate security into CI/CD pipelines and drive secure-by-default engineering practices

- Design and build security controls, libraries, and guardrails directly in code

- Develop and scale automated security tooling across CI/CD (SAST, dependency scanning, secrets detection, fuzzing, etc.)

- Build and improve detection and prevention mechanisms for abuse, data exfiltration, and supply chain risks

- Automate vulnerability triage, prioritization, and remediation workflows at scale

- Integrate security into developer workflows and internal platforms to reduce friction and increase adoption

- Design and implement security controls for agentic and AI-assisted workflows, building guardrails to mitigate risks such as prompt injection, data exfiltration, and misuse of developer and system privileges

- Contribute to secure system design and architecture reviews, including threat modeling for new products and features

### You have:

- 6+ years of experience in software engineering, application security, or security engineering

- Strong coding skills in at least one language (e.g., Python, Go, C#, JavaScript, Rust, C++)

- Build and scale security automation in CI/CD pipelines (SAST, SCA, secrets detection, and fuzzing)

- Solid understanding of application security fundamentals (OWASP Top 10, auth models, common vulnerabilities and mitigations)

- Background with cloud environments, and modern architectures (microservices, APIs)

- Working knowledge of Linux/Windows systems, networking fundamentals, and system-level security

- Experience designing and implementing secure, scalable systems, including APIs, microservices, and distributed architectures

- Ability to translate security risks into practical, scalable engineering solutions

- Bachelor’s degree in a relevant field or equivalent practical experience

### Nice to Have:

- Experience building security platforms, tools, or developer frameworks

- Knowledge of cryptography, PKI, TLS, and secure implementations

- Experience with container security and Kubernetes

- Experience building internal security platforms or developer tooling

- Background of supply chain security (SBOMs, signing, provenance, build integrity)

### You Are

- Think long-term, building resilient and scalable security solutions rather than one-off fixes

- Highly execution-focused and drive outcomes in fast-paced environments

- Take ownership and proactively identify and mitigate risks

- Collaborate effectively and influence engineering teams through practical solutions

- Balance security and developer productivity to enable the business

For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.

### Annual Salary Range

$269,170—$326,060 USD

Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).

Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.

For US based roles only, please note the Company may not be able to employ candidates for this role who have United States work authorization related to certain U.S. visa categories, or support future H-1B sponsorship at this time.

**Live in Roblox’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- WR [Security engineer, application security](https://gurify.com/job/security-engineer-application-security-at-writer-f9471c606c4a) Writer · New York City, NY · 2 weeks ago
- AS [Security Engineer](https://gurify.com/job/security-engineer-at-assembledhq-280ac1c5d778) Assembledhq · New York City, NY · 4 days ago
- EV [Information Security Engineer (maternity cover)](https://gurify.com/job/information-security-engineer-maternity-cover-at-evoke-8ec4a93fd8ab) Evoke · Herzliya Pituach, Israel, IL · 3 weeks ago
- RO [Senior Security Software Engineer, IAM](https://gurify.com/job/senior-security-software-engineer-iam-at-roblox-884ae808a0c6) Roblox · San Mateo, CA · 3 months ago
- GI [Intermediate Software Engineer, Security Factory: Vulnerability ...](https://gurify.com/job/intermediate-software-engineer-security-factory-vulnerability-at-1d9ec8f2ea7f) Gitlab · Remote, United States · 4 weeks ago
- GO [Senior Security Engineer, Product Security](https://gurify.com/job/senior-security-engineer-product-security-at-goodleap-788ee656f8bd) Goodleap · Remote, United States · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Security Software Engineer, Application Security","description":"\u003Cp\u003EEvery day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences\u2013 all created by our global community of developers and creators.\u003C/p\u003E\u003Cp\u003EAt Roblox, we\u2019re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We\u2019re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.\u003C/p\u003E\u003Cp\u003EA career at Roblox means you\u2019ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.\u003C/p\u003E\u003Cp\u003EThe Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards, build scalable controls, and enable product and infrastructure teams to operate securely by default. The Application Security team partners closely with engineering teams early in the development lifecycle to drive secure architectures, establish standards, and deliver scalable security solutions.\u003C/p\u003E\u003Cp\u003EAs a Senior Security Software Engineer - Application Security, you will be a hands-on engineer who designs, builds, and ships security solutions that integrate directly into developer workflows and platforms. You will play a key role in scaling application security through automation, CI/CD integrations, secure libraries, and reusable patterns.\u003C/p\u003E\u003Cp\u003EIn this role, you will help define how security is embedded across the software development lifecycle at Roblox, balancing deep technical work (threat modeling, code review, penetration testing) with systemic solutions that reduce risk at scale. You will also participate in AppSec on-call rotations and contribute to security tooling and platform evolution.\u003C/p\u003E\u003Ch3\u003EYou will:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EIntegrate security into CI/CD pipelines and drive secure-by-default engineering practices\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign and build security controls, libraries, and guardrails directly in code\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop and scale automated security tooling across CI/CD (SAST, dependency scanning, secrets detection, fuzzing, etc.)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild and improve detection and prevention mechanisms for abuse, data exfiltration, and supply chain risks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAutomate vulnerability triage, prioritization, and remediation workflows at scale\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate security into developer workflows and internal platforms to reduce friction and increase adoption\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign and implement security controls for agentic and AI-assisted workflows, building guardrails to mitigate risks such as prompt injection, data exfiltration, and misuse of developer and system privileges\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to secure system design and architecture reviews, including threat modeling for new products and features\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYou have:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E6\u002B years of experience in software engineering, application security, or security engineering\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong coding skills in at least one language (e.g., Python, Go, C#, JavaScript, Rust, C\u002B\u002B)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild and scale security automation in CI/CD pipelines (SAST, SCA, secrets detection, and fuzzing)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESolid understanding of application security fundamentals (OWASP Top 10, auth models, common vulnerabilities and mitigations)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBackground with cloud environments, and modern architectures (microservices, APIs)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking knowledge of Linux/Windows systems, networking fundamentals, and system-level security\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience designing and implementing secure, scalable systems, including APIs, microservices, and distributed architectures\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to translate security risks into practical, scalable engineering solutions\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBachelor\u2019s degree in a relevant field or equivalent practical experience\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to Have:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience building security platforms, tools, or developer frameworks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of cryptography, PKI, TLS, and secure implementations\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with container security and Kubernetes\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience building internal security platforms or developer tooling\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBackground of supply chain security (SBOMs, signing, provenance, build integrity)\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYou Are\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EThink long-term, building resilient and scalable security solutions rather than one-off fixes\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHighly execution-focused and drive outcomes in fast-paced environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETake ownership and proactively identify and mitigate risks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate effectively and influence engineering teams through practical solutions\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBalance security and developer productivity to enable the business\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EFor roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.\u003C/p\u003E\u003Ch3\u003EAnnual Salary Range\u003C/h3\u003E\u003Cp\u003E$269,170\u2014$326,060 USD\u003C/p\u003E\u003Cp\u003ERoles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).\u003C/p\u003E\u003Cp\u003ERoblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.\u003C/p\u003E\u003Cp\u003EFor US based roles only, please note the Company may not be able to employ candidates for this role who have United States work authorization related to certain U.S. visa categories, or support future H-1B sponsorship at this time.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-security-software-engineer-application-security-at-roblox-69ebcc4b49ee"},"url":"https://gurify.com/job/senior-security-software-engineer-application-security-at-roblox-69ebcc4b49ee","datePosted":"2026-05-06","validThrough":"2026-11-05T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Roblox","sameAs":"https://job-boards.greenhouse.io/roblox"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"US","addressLocality":"San Mateo"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United States","item":"https://gurify.com/jobs/united-states"},{"@type":"ListItem","position":3,"name":"Senior Security Software Engineer, Application Security","item":"https://gurify.com/job/senior-security-software-engineer-application-security-at-roblox-69ebcc4b49ee"}]}
```
