Roblox11 days ago

Principal Security Software Engineer, IAM

RUB 27,172–32,088per month · before tax
MARKET
14,583median for this role
Backend Developer · 47 jobs with disclosed pay
5,092half of the offers: 11,042–19,804308,000
Above market · above 89% of offers
San Mateo

Responsibilities

  • 01Lead the architecture for production identity and access
  • 02Define and evolve the end-to-end design for machine, workload, human, and AI-agent identity across our hybrid on-prem and cloud fleet, making secure access invisible when it can be and intuitive when it needs attention
  • 03Drive mTLS and workload identity to full production enforcement
  • 04Lead the technical strategy for our SPIFFE/SPIRE-based identity platform, service-mesh integration, managed service accounts, and certificate issuance, storage, and rotation
  • 05Advance just-in-time, least-privilege access for engineers
  • 06Architect just-in-time, least-privilege, and break-glass access to production, replacing static, long-lived credentials with short-lived, auditable access that stays reliable even during dependency or identity-provider outages
  • 07Evolve the centralized authorization engine and a secure golden path
  • 08Mature our centralized authorization engine and the access-control models behind it (RBAC/ABAC and risk-based access) so decisions are consistent, fine-grained, and testable
  • 09Pioneer identity and access for AI agents
  • 10Define how agents obtain credentials, receive scoped permissions, and have their sessions managed across their lifecycle, setting the patterns for agentic identity at Roblox
  • 11Lead across the org and raise the bar
  • 12Author RFCs and multi-year roadmaps, align stakeholders across Roblox Platform, mentor senior and staff engineers, and raise the technical bar through design review, on-call ownership, and hiring

Requirements

  • 018+ years of relevant professional experience building scalable, distributed backend systems, with a track record of driving architecture end to end
  • 02Deep expertise in identity and access management — authentication, authorization, and access-control models such as RBAC, ABAC, or risk-based access control
  • 03Hands-on experience with several of: PKI and certificate/key lifecycle management, mTLS, SPIFFE/SPIRE or comparable workload-identity systems, service mesh, secret management (e.g., Vault), and privileged access management (PAM)
  • 04Proficiency in at least one systems language such as Go, Rust, Java, C++, Python, or C# .NET, and a habit of building systems rather than only configuring vendor tools
  • 05Experience leading the technical work of other engineers — setting direction across teams, writing influential design docs, and mentoring senior talent
  • 06AI fluency: you use AI tools in your daily workflow, understand LLM capabilities and limitations, and can reason about what it means to give an AI agent an identity and permissions
  • 07A Bachelor's degree or equivalent experience in Computer Science, Computer Engineering, or a similar technical field

What we offer

  • 01Annual Salary Range $326,060 – $385,050 USD
  • 02Equity compensation
  • 03Benefits as described
  • 04Onsite Tuesday, Wednesday, Thursday with optional presence on Monday and Friday
  • 05Based at headquarters in San Mateo, CA