> Markdown version of [/jobs/ext/533602-principal-security-software-engineer-enterprise-security-new](https://www.wearedevelopers.com/jobs/ext/533602-principal-security-software-engineer-enterprise-security-new). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Software Engineer, Enterprise Security New - **Company:** Roblox - **Location:** San Mateo, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Audit Trail, Authentication Protocols, Cyber Security, Software Debugging, DevOps, Identity and Access Management, Python (Programming Language), OAuth, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Software, Session Management, Enterprise Software Applications, Backend, Build Management, Roblox - **Published:** June 9, 2026 - **Apply:** https://www.gamesjobsdirect.com/job/roblox/principal-security-software-engineer-enterprise-security/347178 ## About the Role * Deep understanding of Human and Machine Identity and Authentication protocols like OAuth 2.0, SCIM 2.0, SAML 2.0, Transaction tokens, FIDO2/WebAuthn and Passkeys, SPIFFE/SPIRE * Experience with one or more policy-as-code or authorization frameworks (OPA/Rego, Cedar, Zanzibar/ReBAC) * Proficiency in at least one systems or backend language: Python, Go, Rust * Proficiency with security-relevant system design: session management, audit logging, rate limiting, secret storage * Experience in Threat modeling for authentication and authorization systems * Understanding of Zero trust architecture and least-privilege access patterns * 10+ years of relevant professional experience combining SWE and security You are: * Engineer First: You approach problems with code and systems thinking, building reliable security platforms that engineering teams can depend on * Protocol Fluent: You have hands-on experience implementing identity standards and can navigate RFC-level details to debug complex authentication and authorization issues. * Collaborative: You love working with your direct team and cross-functional partners across engineering, DevOps, and business teams to deliver security outcomes without slowing them down. * Strategic Thinker: You define clear technical requirements and assess commercial solutions to inform build vs. buy decisions, balancing security rigor with engineering pragmatism. * Comfortable with Ambiguity: You gather data, navigate complex situations, and make sound technical decisions even when facing incomplete information or unclear requirements. ## Description As a Principal Security Software Engineer in the Enterprise Security team, you will advance Roblox's Enterprise Security strategy by building the systems and integrations that protect Roblox's corporate infrastructure. Where traditional security engineers evaluate and deploy vendor solutions, you will design and build production-grade security software - Identity and Access governance, policy enforcement engines, and security integrations that scale with Roblox's business. You'll partner with security professionals across InfoSec and work cross-functionally with Corporate Engineering, DevOps, and Product teams to drive security initiatives. You will: * Build identity and access systems: Design, implement, and own integrations across Roblox's IAM ecosystem, including SSO federation, SCIM provisioning/deprovisioning pipelines, OAuth 2.0 authorization servers, and token lifecycle management. * Lead security automation: Develop production-quality tools and services that enforce security policies at scale, replace manual workflows, and surface actionable signals * Drive secure-by-design implementations: Partner with Corporate Engineering, DevOps, and product teams to embed security controls into enterprise systems and developer workflows. * Evaluate and extend vendor platforms: Assess commercial IAM and security tooling, then build the custom integrations, connectors, and automation layers that make them work at Roblox's scale. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)