Senior Security Software Engineer, IAM
About the role
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
Responsibilities
- Design Identity and Access for AI Agents: Define how AI agents get credentials, receive scoped permissions, and have their sessions managed throughout their lifecycle — pioneering the patterns for agentic identity in production.
- Engineer Hybrid Production IAM at Scale: Design and implement scalable IAM solutions for Roblox's hybrid production environment, spanning on-premises and cloud infrastructure, ensuring secure and efficient access for humans, workloads, and AI agents across the entire ecosystem.
- Develop and Manage Workload Authentication & Authorization: Build robust authentication and authorization mechanisms for workloads and services accessing production environments, enforcing least privilege and secure access controls.
- Establish the Secure Golden Path for Development: Develop and maintain a streamlined, secure "golden path" framework that empowers developers to build tools and services with appropriate IAM controls baked in by default.
Requirements
- 4+ years of relevant professional experience building scalable, distributed backend applications.
- Proficiency in at least one programming language such as Python, Java, Go, C++, or C# .NET.
- AI fluency: Actively use AI tools in your daily workflow, understand LLM capabilities and limitations, and can reason about what it means to give an AI agent an identity and permissions.
- Experience mentoring or leading the technical work of other engineers.
- Familiarity with policy and identity frameworks like OPA, Topaz, SPIFFE/SPIRE, or similar technologies used for policy enforcement, workload attestation, and identity federation in cloud-native environments.
- Experience with Public Key Infrastructure (PKI) — design, implementation, or maintenance of PKI solutions.
- Experience with Privileged Access Management (PAM) — implementing or maintaining PAM solutions to control, monitor, and audit privileged access within production environments.
- Familiarity with access control models such as Role-Based (RBAC), Attribute-Based (ABAC), or Risk-Based Access Control.
Qualifications
The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future.
Skills
- Programming Languages: Python, Java, Go, C++, C# .NET
- AI Tools: Proficient in using AI tools in daily workflow
- Identity and Access Management: Experience with OPA, Topaz, SPIFFE/SPIRE, or similar technologies
- Public Key Infrastructure: Design, implementation, or maintenance of PKI solutions
- Privileged Access Management: Implement or maintain PAM solutions
- Access Control Models: RBAC, ABAC, Risk-Based Access Control
Benefits
All full-time employees are also eligible for equity compensation and for benefits as described on this page.
Pay
Annual Salary Range $269,170—$326,060 USD
Schedule
Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).