ROBLOX Corporation

Senior Security Software Engineer, Sandbox Platforms

ROBLOX Corporation$269K — $326K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years experience in OS security models for Linux, macOS, or Windows.
  • Hands-on knowledge of sandboxing primitives on at least one platform.
  • Strong understanding of attack surface analysis and sandbox escapes.
  • Fluency in designing interfaces between sandbox and host.
  • Proficient in systems programming using C, C++, or Rust.
  • Ability to make engineering tradeoffs with sound judgment.
  • Security-focused mindset prioritizing least privilege.

Responsibilities

  • Design and build sandbox environments using specific platform primitives.
  • Lock down all communication paths in and out of the sandbox.
  • Analyze and minimize attack surfaces in the system.
  • Make informed engineering tradeoffs between isolation and performance.
  • Document threat models and respond to security findings.
  • Review designs to mitigate sandbox escape risks.

Benefits

  • Equity compensation for all full-time employees.
  • Flexible onsite work schedule, with optional presence on Monday and Friday.
Full Job Description
About the role

We build the isolation layers that contain untrusted and semi-trusted code. You will design, build, and harden process sandboxes across one or more of Linux, macOS, and Windows, the last line of defense when something inside goes wrong. This is a deep systems role for someone who thinks in terms of attack surface, threat models, and the exact boundary between trusted and untrusted.
You Will:
  • Design and implement sandboxes using platform primitives: nsjail, seccomp-bpf, namespaces, cgroups, and Landlock on Linux; the Seatbelt (sandbox_init / SBPL) and related mechanisms on macOS; AppContainer, job objects, restricted tokens, and integrity levels on Windows.
  • Define and lock down every communication path in and out of the sandbox: syscalls, IPC, shared memory, file descriptors, sockets, brokers, and minimize what each one exposes.
  • Enumerate and reduce attack surface: kernel syscall surface, broker interfaces, device access, and side channels. Assume the code inside is hostile.
  • Make deliberate engineering tradeoffs between isolation strength, performance, compatibility, and maintainability, and document the reasoning.
  • Write threat models, review designs, and respond to sandbox escapes and hardening findings.
You Have:
  • Deep, hands-on knowledge of the OS security model on at least one of Linux, macOS, or Windows, and the sandboxing primitives that platform provides.
  • Strong grasp of attack surface analysis: how sandboxes are escaped and how to shrink the ways in.
  • Fluency in the boundary between sandbox and host (brokers, IPC, syscall filtering, privilege separation) and how to design a minimal, well-audited interface.
  • Systems programming in C, C++, or Rust; comfort at the syscall and kernel-interface level.
  • Sound judgment on tradeoffs: knowing when tighter isolation is worth the cost and when it isn't.
  • A security mindset: you default to least privilege and distrust every input crossing the boundary.
Nice to have
  • Experience across more than one of the three platforms.
  • Kernel, hypervisor, or low-level OS internals work.
  • Fuzzing, exploit development, or red-team experience against isolation boundaries.


For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.

Annual Salary Range

$269,170-$326,060 USD

Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).

About ROBLOX Corporation

Roblox Corporation is a video game company that operates a massively multiplayer online game platform. The platform allows users to create and play games in a virtual world, with a focus on user-generated content. Roblox was founded in 2004 and is headquartered in San Mateo, California. The company has grown rapidly in recent years, and now has over 100 million monthly active users. In 2021, Roblox went public through a direct listing on the New York Stock Exchange.
Learn more about ROBLOX Corporation
Size
960 employees
Market Cap
$15.6 billion
Industry
Net Income
-$242.8 million
Founded
2004
Revenue
$727 million
NASDAQ

Similar Jobs

More Jobs at ROBLOX Corporation

More Information Technology Jobs

Find similar Senior Security Software Engineer, Sandbox Platforms jobs: