Senior Security Operations Engineer, Incident Response Program Lead
at Roblox
San Mateo, United States
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
As a Senior member of the Security Operations team, you will serve as the Incident Response Program Lead at Roblox headquarters. In this pivotal role, you will hold the ultimate responsibility for building, improving, and scaling our SIRT capabilities across people, process, and technology. You will be the architect of our response maturity, moving us beyond ad-hoc firefighting into a structured, highly orchestrated operation. While you will still be hands-on during events, your primary focus will be force multiplying: ensuring that our alert pipeline, response procedures, tooling and capabilities integrate deeply with the rest of the company. You will work directly with leadership to influence the roadmap for the Security Incident Response Team, operate cohesively with SOC operations and ensure our team is equipped to protect Roblox’s platform, developers, and millions of users.
You will:
- Lead the SIRT Program: Own the strategy and execution of the Incident Response program. Define success metrics, identify maturity gaps, and drive projects that scale our capabilities (People, Process, Technology).
- Command Security Incidents: Serve as an Incident Commander for high-severity events, ensuring threats are mitigated with speed and professionalism.
- Build & Scale Process: Create and maintain the "source of truth" for response—developing comprehensive runbooks, Incident Response Plans (IRPs), and workflows that standardize excellence across the team.
- Drive Automation & Technology: Be a driving force in SOAR and response tooling. Identify manual toil and ruthlessly automate it to free up time for high-value hunting.
- IR Mentorship & Training: Elevate the skills of the broader team. Design tabletop exercises, conduct post-incident reviews (blameless post-mortems), and ensure lessons learned are fed back into the program.
- Collaborate Cross-Functionally: Become best friends with Legal, Privacy, Comms, HR and Engineering teams to ensure our incident response processes are legally sound and technically integrated.
- Threat Hunt: Lead and participate in proactive threat hunting initiatives, using intelligence to hypothesis-test our environment against advanced adversaries.
You have:
- Experience: 8+ years of experience across Infosec, IT, Infra/SRE, and/or Incident Response.
- Specialization: 5+ years of experience specifically in Security Incident Response roles.
- Program Building: Demonstrated experience not just running incidents, but building the program capabilities that support them. You have created IRPs, defined and maintained severity matrices, and influenced IR policy to meet the latest and best standards.
- Incident Command: Proven ability to exist in and manage chaos. You have led enterprise-wide incidents and can confidently brief executive leadership during crises.
- Technical Proficiency: Deep hands-on experience with security stack components (SIEM, EDR, IDS/IPS, SOAR). You know how o tune these tools to reduce noise and increase signal.
- Framework Knowledge: Proficiency with Incident Response frameworks (NIST, SANS, Cyber Kill Chain, MITRE ATT&CK) and the ability to operationalize them.
- Education: Bachelor's degree in Computer Science, Cybersecurity, or a related technical field; advanced degree preferred or equivalent experience.
For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.
Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).
Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.
