Principal Enterprise Security Engineer

Roblox Roblox · Consumer · San Mateo, CA · Software Engineering

This role is for a Principal Enterprise Security Engineer at Roblox. The primary focus is on advancing the company's enterprise security strategy by shaping and evolving security architecture, leading the design and deployment of security solutions, and ensuring secure operations. The role involves defining security standards, leading initiatives in core security domains (including Agentic AI Governance), collaborating with IT and engineering teams, and mentoring other engineers. Experience with modern enterprise infrastructure, SaaS ecosystems, and security frameworks like SOC 2 and ISO 27001 is required. The role also involves experience with low-code and no-code orchestration platforms.

What you'd actually do

  1. Define and maintain enterprise-wide security standards and principles that guide how security is implemented across business workflows, ensuring consistency, scalability, and alignment with organizational risk posture.
  2. Lead and drive initiatives across core security domains, including Endpoint Security, SaaS Security, Identity & Access Management (IAM), Agentic AI Governance, and Supply Chain Security.
  3. Collaborate closely with IT, engineering, DevOps, and business stakeholders to integrate security tools, policies, and processes into enterprise systems and workflows, enabling secure-by-design implementations
  4. Mentor engineers and stakeholders, serving as a trusted advisor on security architecture, control design, and secure implementation patterns.

Skills

Required

  • 9+ years of relevant professional experience
  • Deep expertise in Identity and Access Management, Authentication & Authorization, Endpoint management, Network Security controls and SaaS security posture management
  • Strong understanding of security concepts including zero trust architecture, threat modeling, security frameworks (SOC 2, ISO 27001), and best practices in corporate security environments
  • Demonstrated ability to design and operationalize security policies, principles, and controls across diverse teams and systems.
  • Experience with modern Enterprise infrastructure and SaaS ecosystems, including Google Workspace, Okta, MDM solutions, SSPM, ZTA and cloud-native environments.
  • Experience designing or operating workflows using low-code and no-code orchestration platforms.

Nice to have

  • Experience with AI tools
  • Experience with AI governance

What the JD emphasized

  • Agentic AI Governance