Security Operations Engineer

Roblox
London, UK
2 months ago
Apply on gamesjobsdirect.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Intrusion Detection Systems Security Information and Event Management Virtualization Technology Mitre Att&ck Containerization Information Technology Roblox

Job description

While you will work in close collaboration with peers at our US West Coast Headquarters, the nature of the time difference requires a leader who can operate independently, making critical decisions without immediate oversight. You will help scale our ability to monitor and protect players, developers, employees, and the platform globally. We favor automation, orchestration, and risk-based prioritization, while retaining the deep technical skills required to conduct detailed, hands-on analysis and response when the situation warrants., * Exercise High Autonomy: Act as the primary Incident Commander for the European time zone, making critical, time-sensitive decisions independently before US HQ comes online. You will serve as the senior-most security operations point of contact in the region.

  • Command Security Incidents: Ensure serious threats and impacts are understood, mitigated, and learned from with speed and professionalism, often leading responses end-to-end without immediate escalation paths during local hours.
  • Drive Strategy & Operations: Go beyond individual contribution to shape the strategic direction of the SIRT/SOC function, specifically identifying how global hand-offs and ā€œfollow-the-sunā€ models can be optimized.
  • Conduct Advanced Investigations: Dig into complex context, determining if threats exist and taking decisive action to prevent them.
  • Collaborate Cross-Functionally: Work with Legal, HR, Executive teams, and external partners (Developers & Customers). You will also travel semi-regularly to the USA to visit HQ, ensuring deep alignment with central engineering and security leadership.
  • Lead High-Profile Responses: Collaborate with Security and Engineering to lead responses to major vulnerabilities or platform-wide events.
  • Build & Automate: Produce and refine security response procedures (runbooks, IRPs, workflows) with a focus on automation to reduce manual toil.
  • Threat Hunt: Proactively hunt for anomalous activity in our signals, distinguishing between outliers and threats., * A Strategic Self-Starter: You don’t wait for instructions. You identify gaps in coverage-especially those unique to regional or time-zone specific challenges-and fix them.
  • Detailed Thinker: You enjoy exploring the details and considering the second and third-order effects of your decisions.
  • Eager Problem Solver: You are drawn to complex issues rather than avoidant of them.
  • Emboldened to Make Change: You instinctively ask what you can do to improve the situation rather than waiting to be prompted.
  • Compelled by our Mission: You are driven by the opportunity to protect our community and the safe space we’ve created.
  • A Calculated Risk Taker: You move fast, navigating reasonable risks to take action and build capabilities as quickly as possible.

Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).

Requirements

  • Experience: 10+ years of experience across Infosec, IT, Infra/SRE, and/or Incident Response.
  • Specialization: 7+ years of experience specifically in Detection or Response (& Incident Response) roles.
  • Autonomous Leadership: Proven ability to work independently in satellite offices or distributed teams. You are comfortable being the ā€œperson in chargeā€ during your shift and making calls that impact the business.
  • Incident Command: Extensive experience operating as an incident commander. You can flex into deep engineering work but also possess the executive presence to coordinate responders and communicate status to leadership.
  • Investigations: Expert-level capability in investigating threats in enterprise and production environments, taking ownership from identification to resolution.
  • Knowledge/Tools/Techniques: Deep understanding of security tools (SIEM, EDR, IDS/IPS, NDS, SOAR). You are proficient in applying Incident Response frameworks (NIST IR Lifecycle, Cyber Kill Chain, MITRE ATT&CK) to real-world scenarios. Collaborate effectively with engineering colleagues, leveraging extensive expertise across various infrastructure and technologies (Public Cloud, OS, Virtualization, Containerization, Networking, Build/Development infrastructure, and Hardware).
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field; advanced degree preferred or equivalent experience.

About the company

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences- all created by our global community of developers and creators.

At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device.We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.

A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.

As a founding member of the Security Operations team in EMEA, you will be joining us at an exciting time in Roblox’s SIRT & SOC program. This is a highly autonomous role where you will be a primary decision-maker, core to our mission to maintain a highly capable 24/7/365 monitoring and response capability.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on gamesjobsdirect.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:41 min

Equipping agents with runtime context and telemetry data

May Walter May Walter Ā· World Congress 2026 Europe

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber Ā· World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

Videos

See all

Related articles

See all