ROBLOX Corporation

Principal Security Software Engineer, IAM

ROBLOX Corporation$326K — $385K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in scalable, distributed backend systems and architecture
  • Expertise in identity and access management (IAM) including RBAC, ABAC, and risk-based models
  • Hands-on experience with PKI, mTLS, SPIFFE/SPIRE, and privileged access management
  • Proficient in systems programming languages like Go, Rust, Java, C++, Python, or C# .NET
  • Experience leading technical teams and mentoring senior engineers
  • Familiarity with AI tools and understanding of LLM capabilities
  • Bachelor's degree in Computer Science or related field

Responsibilities

  • Architect and design production identity and access systems across cloud and on-prem environments
  • Implement mTLS and enforce workload identity in production environments
  • Develop just-in-time, least-privilege access strategies for engineers
  • Enhance centralized authorization engine and access-control models
  • Define credentialing and session management for AI agents
  • Collaborate with teams to produce roadmaps, RFCs, and mentor fellow engineers
  • Elevate technical standards through design reviews and hiring processes

Benefits

  • Equity compensation
  • Flexible onsite presence options
  • Comprehensive health benefits
  • Professional development opportunities
  • Collaborative work environment
Full Job Description
As a Principal Security Software Engineer on the Production IAM team, you will set the technical direction for how identity and access work across Roblox's production infrastructure, from the mTLS-based identity that services use to authenticate to one another, to the privileged access controls that govern how engineers reach production. The team is accountable for Roblox's machine and workload identity platform, its centralized authorization engine, its production access management platform, production PKI and certificate lifecycle, and just-in-time privileged access for engineers. As an individual contributor in Production IAM, you will define multi-year strategy, drive alignment across Roblox Platform, mentor senior and staff engineers, and personally build the hardest parts of these systems. As AI agents become first-class actors in production, you will also help pioneer how they get identity, prove who they are, and receive safely-scoped access. You will • Lead the architecture for production identity and access. Define and evolve the end-to-end design for machine, workload, human, and AI-agent identity across our hybrid on-prem and cloud fleet, making secure access invisible when it can be and intuitive when it needs attention. • Drive mTLS and workload identity to full production enforcement. Lead the technical strategy for our SPIFFE/SPIRE-based identity platform, service-mesh integration, managed service accounts, and certificate issuance, storage, and rotation. • Advance just-in-time, least-privilege access for engineers. Architect just-in-time, least-privilege, and break-glass access to production, replacing static, long-lived credentials with short-lived, auditable access that stays reliable even during dependency or identity-provider outages. • Evolve the centralized authorization engine and a secure golden path. Mature our centralized authorization engine and the access-control models behind it (RBAC/ABAC and risk-based access) so decisions are consistent, fine-grained, and testable. • Pioneer identity and access for AI agents. Define how agents obtain credentials, receive scoped permissions, and have their sessions managed across their lifecycle, setting the patterns for agentic identity at Roblox.. • Lead across the org and raise the bar. Author RFCs and multi-year roadmaps, align stakeholders across Roblox Platform, mentor senior and staff engineers, and raise the technical bar through design review, on-call ownership, and hiring. You have • 8+ years of relevant professional experience building scalable, distributed backend systems, with a track record of driving architecture end to end. • Deep expertise in identity and access management - authentication, authorization, and access-control models such as RBAC, ABAC, or risk-based access control. • Hands-on experience with several of: PKI and certificate/key lifecycle management, mTLS, SPIFFE/SPIRE or comparable workload-identity systems, service mesh, secret management (e.g., Vault), and privileged access management (PAM). • Proficiency in at least one systems language such as Go, Rust, Java, C++, Python, or C# .NET, and a habit of building systems rather than only configuring vendor tools. • Experience leading the technical work of other engineers - setting direction across teams, writing influential design docs, and mentoring senior talent. • AI fluency: you use AI tools in your daily workflow, understand LLM capabilities and limitations, and can reason about what it means to give an AI agent an identity and permissions. • A Bachelor's degree or equivalent experience in Computer Science, Computer Engineering, or a similar technical field. You are • A systems thinker. You reason about failure modes, blast radius, and reliability, and you design access that stays secure and available even when dependencies fail. • Security-minded and pragmatic. You are passionate about least privilege and zero trust, but you optimize for the Builder experience and adoption, not controls for their own sake. • A force multiplier. You make the engineers and teams around you better through mentorship, clear writing, and high-quality technical leadership. • A strong communicator. You translate deep technical tradeoffs for both engineers and executives, and you build alignment across organizational boundaries. • Bar-raising and hands-on. You still love to build, and you set the standard for engineering quality on the hardest problems. For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page. Annual Salary Range $326,060-$385,050 USD Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).

About ROBLOX Corporation

Roblox Corporation is a video game company that operates a massively multiplayer online game platform. The platform allows users to create and play games in a virtual world, with a focus on user-generated content. Roblox was founded in 2004 and is headquartered in San Mateo, California. The company has grown rapidly in recent years, and now has over 100 million monthly active users. In 2021, Roblox went public through a direct listing on the New York Stock Exchange.
Learn more about ROBLOX Corporation
Size
960 employees
Market Cap
$15.6 billion
Industry
Net Income
-$242.8 million
Founded
2004
Revenue
$727 million
NASDAQ

Similar Jobs

More Jobs at ROBLOX Corporation

More Information Technology Jobs

Find similar Principal Security Software Engineer, IAM jobs: