Privacy and Security Counsel

Roblox Roblox · Consumer · San Mateo, CA · Legal

This role is for a Privacy and Security Counsel at Roblox, focusing on legal security guidance related to laws, regulations, incidents, and policies. The counsel will provide subject-matter expertise, engage in incident response, support security compliance initiatives, and act as a legal resource for various security teams. The role requires experience in data security, privacy laws, and working with information security teams, including incident response and breach reporting.

What you'd actually do

  1. Provide subject-matter expertise and guidance on the evolving global security and privacy legal landscape, including legislation, regulations, enforcement actions, and best practices, translating analysis into clear, concise, and actionable guidance to both legal and security teams.
  2. Engage with the Detection and Response and Global Security teams during incidents. Provide legal guidance throughout the incident, including during verification, triage, containment, remediation, post-mortem, table-top exercises, counseling internal stakeholders throughout the incident lifecycle, reporting to regulators, and notifying customers to meet our global obligations.
  3. Own and deliver complex, cross-functional cybersecurity legal initiatives end-to-end (e.g., new regulatory regimes, major incident response improvements), with clear milestones, stakeholder alignment, and measurable outcomes. Continuously improve incident response policies and playbooks that meet the standards of applicable global data privacy and security laws.
  4. Embed within security pods as a trusted partner and go-to legal resource for regular expertise, insights, guidance, and support to different security teams, including Application Security, GRC, Privacy Engineering, Global Security, and Infrastructure/Platform teams, developing a working understanding of Roblox’s architecture, data flows, and operational constraints.
  5. Provide subject matter expertise in privacy and security and support to cross-functional legal advocacy teams, including corporate, employment, compliance, policy, regulatory, product, privacy, and commercial.

Skills

Required

  • 5+ years of data security, data privacy, data protection and governance experience.
  • Expertise in US and global data security and protection laws and regulations.
  • Knowledge of security regulations and frameworks, such as GDPR, NIS2, CCPA, COPPA, CA SB 553, NIST CSF, and PCI.
  • Experience working with Information Security teams, including Incident Response, Application Security and Governance.
  • Experience with security incidents including, breaches, breach reporting to regulators, customer notifications.
  • Experience implementing global data protection and security requirements.
  • Active membership in at least one U.S. state bar
  • Excellent business-oriented judgment.
  • Experience operating as a senior individual contributor in a fast-paced technology company, driving complex, cross-functional programs.
  • Proven track record of taking ambiguous, cross-functional projects from concept to delivery, using strong project management skills to drive accountability and hit deadlines.
  • Exceptional written and verbal communication skills, including the ability to “speak the language of the business” (not the law firm) and tailor messaging to executives, engineers, and operations teams.
  • Working familiarity with large-scale, modern infrastructure (e.g., cloud platforms, microservices, observability, incident management tooling) sufficient to understand how technical architectures influence legal risk and incident response.

Nice to have

  • Training at a major national law firm
  • in-house experience a plus
  • California Bar admission preferred

What the JD emphasized

  • Expertise in US and global data security and protection laws and regulations.
  • Knowledge of security regulations and frameworks, such as GDPR, NIS2, CCPA, COPPA, CA SB 553, NIST CSF, and PCI.
  • Experience with security incidents including, breaches, breach reporting to regulators, customer notifications.
  • Proven track record of taking ambiguous, cross-functional projects from concept to delivery, using strong project management skills to drive accountability and hit deadlines.