> Markdown version of [/jobs/ext/2736829-senior-security-software-engineer-application-security-new](https://www.wearedevelopers.com/jobs/ext/2736829-senior-security-software-engineer-application-security-new). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Software Engineer, Application Security New - **Company:** Roblox - **Location:** San Mateo, CA, United States - **Experience:** Expert - **Salary:** $269,170.0 - $326,060.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, JavaScript (Programming Language), Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Architectural Patterns, C Sharp (Programming Language), C++ (Programming Language), Continuous Integration, Linux, Programming Tools, Distributed Systems, Fuzz Testing, Python (Programming Language), Networking Basics, Open Web Application Security, Public Key Infrastructure, Security Software, Software Engineering, Rust (Programming Language), Transport Layer Security, Cloud Platform System, Software Security, Build Management, Kubernetes, Software Coding, Static Application Security Testing, Golang, Microservices - **Published:** September 5, 2026 - **Apply:** https://www.gamesjobsdirect.com/job/roblox/senior-security-software-engineer-application-security/357360 ## About the Role * 6+ years of experience in software engineering, application security, or security engineering * Strong coding skills in at least one language (e.g., Python, Go, C#, JavaScript, Rust, C++) * Build and scale security automation in CI/CD pipelines (SAST, SCA, secrets detection, and fuzzing) * Solid understanding of application security fundamentals (OWASP Top 10, auth models, common vulnerabilities and mitigations) * Background with cloud environments, and modern architectures (microservices, APIs) * Working knowledge of Linux/Windows systems, networking fundamentals, and system-level security * Experience designing and implementing secure, scalable systems, including APIs, microservices, and distributed architectures * Ability to translate security risks into practical, scalable engineering solutions * Bachelor's degree in a relevant field or equivalent practical experience Nice to Have: * Experience building security platforms, tools, or developer frameworks * Knowledge of cryptography, PKI, TLS, and secure implementations * Experience with container security and Kubernetes * Experience building internal security platforms or developer tooling * Background of supply chain security (SBOMs, signing, provenance, build integrity) You Are * Think long-term, building resilient and scalable security solutions rather than one-off fixes * Highly execution-focused and drive outcomes in fast-paced environments * Take ownership and proactively identify and mitigate risks * Collaborate effectively and influence engineering teams through practical solutions * Balance security and developer productivity to enable the business ## Description * Design and build security controls, libraries, and guardrails directly in code * Develop and scale automated security tooling across CI/CD (SAST, dependency scanning, secrets detection, fuzzing, etc.) * Build and improve detection and prevention mechanisms for abuse, data exfiltration, and supply chain risks * Automate vulnerability triage, prioritization, and remediation workflows at scale * Integrate security into developer workflows and internal platforms to reduce friction and increase adoption * Design and implement security controls for agentic and AI-assisted workflows, building guardrails to mitigate risks such as prompt injection, data exfiltration, and misuse of developer and system privileges * Contribute to secure system design and architecture reviews, including threat modeling for new products and features ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)