> Markdown version of [/jobs/ext/2943064-security-software-engineer](https://www.wearedevelopers.com/jobs/ext/2943064-security-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Software Engineer - **Company:** Roblox - **Location:** San Mateo, CA, United States - **Experience:** Expert - **Salary:** $269,170.0 - $326,060.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, C++ (Programming Language), Linux, Fuzz Testing, Hypervisor, System Programming, Operating System Security - **Published:** September 16, 2026 - **Apply:** https://careers.roblox.com/jobs/8198167?gh_jid=8198167 ## About the Role * Deep, hands-on knowledge of the OS security model on at least one of Linux, macOS, or Windows, and the sandboxing primitives that platform provides. * Strong grasp of attack surface analysis: how sandboxes are escaped and how to shrink the ways in. * Fluency in the boundary between sandbox and host (brokers, IPC, syscall filtering, privilege separation) and how to design a minimal, well-audited interface. * Systems programming in C, C++, or Rust; comfort at the syscall and kernel-interface level. * Sound judgment on tradeoffs: knowing when tighter isolation is worth the cost and when it isn't. * A security mindset: you default to least privilege and distrust every input crossing the boundary. Nice to have * Experience across more than one of the three platforms. * Kernel, hypervisor, or low-level OS internals work. * Fuzzing, exploit development, or red-team experience against isolation boundaries. ## Description We build the isolation layers that contain untrusted and semi-trusted code. You will design, build, and harden process sandboxes across one or more of Linux, macOS, and Windows, the last line of defense when something inside goes wrong. This is a deep systems role for someone who thinks in terms of attack surface, threat models, and the exact boundary between trusted and untrusted., * Design and implement sandboxes using platform primitives: nsjail, seccomp-bpf, namespaces, cgroups, and Landlock on Linux; the Seatbelt (sandbox_init / SBPL) and related mechanisms on macOS; AppContainer, job objects, restricted tokens, and integrity levels on Windows. * Define and lock down every communication path in and out of the sandbox: syscalls, IPC, shared memory, file descriptors, sockets, brokers, and minimize what each one exposes. * Enumerate and reduce attack surface: kernel syscall surface, broker interfaces, device access, and side channels. Assume the code inside is hostile. * Make deliberate engineering tradeoffs between isolation strength, performance, compatibility, and maintainability, and document the reasoning. * Write threat models, review designs, and respond to sandbox escapes and hardening findings. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [An alternative approach to digital sovereignty: Confidential Computing](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Blindspots and How to Learn About Them - Anna Oliveira](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)