Senior Security Software Engineer, Infrastructure Security

Roblox Roblox · Consumer · San Mateo, CA · Software Engineering

Senior Security Software Engineer focused on hardening cloud and on-premise infrastructure, implementing secure configurations and guardrails, and partnering with various security and engineering teams to ensure secure outcomes. Requires strong coding experience, knowledge of Linux, Kubernetes, cloud security, and various security concepts like PKI and encryption.

What you'd actually do

  1. Identify security gaps and threats in our cloud and on premise infrastructure, partnering with Governance Risk and Compliance teams to create standards and policies along the way. This will help Roblox meet regulatory and compliance requirements.
  2. Harden our infrastructure by introducing secure by default configurations, designs and guardrails for all developers at Roblox.
  3. Own and drive solutions that enable Roblox engineers to design, build, and use infrastructure securely at scale.
  4. Work closely with other InfoSec teams (AppSec, D&R, GRC, CorpSec, CloudSec, NetSec) and partner with engineering teams across Roblox, specifically the Infrastructure organization, to ensure the secure outcomes of security and product driven initiatives.

Skills

Required

  • 5+ years of experience writing code and/or relevant technical experience
  • Experience with automation
  • IaC
  • system hardening
  • container security concepts
  • cloud security policy
  • observability
  • Deep knowledge of Linux systems
  • Kubernetes (EKS/GKE/AKS/RKS)
  • on premise and cloud based risk and supporting security infrastructure
  • Public Key Infrastructure (PKI)
  • Data Encryption (at-rest and in-transit)
  • platform security best practices
  • Secrets Management
  • orchestration at scale with systems such as Chef, Nomad, and ECS
  • Understanding of network security
  • application security concepts
  • information security industry best practices

What the JD emphasized

  • security gaps
  • threats
  • cloud and on premise infrastructure
  • regulatory and compliance requirements
  • secure by default configurations
  • designs and guardrails
  • securely at scale
  • security and product driven initiatives