Principal Detection and Response Engineer

Roblox Roblox · Consumer · San Mateo, CA · Software Engineering

Principal Security Engineer on the Detection and Response (D&R) team responsible for designing and developing custom security data pipeline systems, detection strategies, and automations for response workflows. The role involves leading real-time incident response, investigating events, and analyzing threat actor techniques to mitigate emerging threats. Key responsibilities include building threat detection systems, automating processes, implementing ETL pipelines, conducting security operations, and collaborating with internal teams.

What you'd actually do

  1. Be a D&R authority! You will deliver robust detection & response capabilities: build new threat detection systems (keeping false positives low) while also automating processes with scripts, playbooks and orchestration tooling.
  2. Implement ETL pipelines: Design and develop customized data processing pipelines.
  3. Conduct security operations: Actively monitor security events and participate in on-call rotations to lead real-time incident response to contain and mitigate potential security issues.
  4. Build positive relationships: Collaborate with internal teams like InfoSec, Engineering, Product and Safety to design scalable solutions.
  5. Help grow the D&R team: Guide and support junior engineer careers and contribute to hiring.

Skills

Required

  • Detection and/or Response
  • Security Data Engineering
  • streaming pipelines
  • Kafka / PubSub
  • Spark / Flink
  • Athena / BigQuery
  • Software Development (SWE)
  • C, Golang or Java
  • SIEM, EDR, NDR, and SOAR technologies
  • incident response
  • network protocols
  • operating systems
  • cloud environments
  • containers
  • Analytical thinking
  • crisis management
  • root cause analysis
  • problem-solving

Nice to have

  • threat hunting
  • automations
  • orchestration tooling
  • on-call rotations
  • virtualized hosts

What the JD emphasized

  • 8+ years of experience in Detection and/or Response
  • 4+ years of Security Data Engineering experience with streaming pipelines
  • Software Development (SWE): Mastery building efficient, reliable, CI/CD deployed, scalable systems using programming languages like C, Golang or Java.
  • Engineering experience with SIEM, EDR, NDR, and SOAR technologies
  • Conducted incident response