Principal Detection and Response Engineer

Roblox
San Mateo, CA, United StatesPosted 6 March 2026

Job Description

<div class="content-intro"><p><span style="font-weight: 400;">Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. </span></p> <p><span style="font-weight: 400;">At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device.</span><strong> </strong><span style="font-weight: 400;">We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. </span></p> <p><span style="font-weight: 400;">A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.</span></p></div><p><strong>About the role:</strong></p> <p>As a Principal Security Engineer on the Detection and Response (DR) team at Roblox, you'll play a key role designing and developing effective custom security data pipeline systems, detection strategies and automations for response workflows to defend our critical assets from threat actors. You will also lead real-time incident response, actively investigate events and analyze threat actor techniques to prioritize emerging threats to ensure Roblox is equipped to mitigate and react to critical challenges. You will play a vital part to ensure the safety of our community and enterprise by proactively fostering a high-performing, inclusive security culture. This is a hybrid in-office role.</p> <p><strong>You Will:</strong></p> <ul> <li><strong>Be a DR authority!</strong> You will deliver robust detection response capabilities: build new threat detection systems (keeping false positives low) while also automating processes with scripts, playbooks and orchestration tooling.</li> <li><strong>Implement ETL pipelines</strong>: Design and develop customized data processing pipelines.</li> <li><strong>Conduct security operations</strong>: Actively monitor security events and participate in on-call rotations to lead real-time incident response to contain and mitigate potential security issues.</li> <li><strong>Build positive relationships</strong>: Collaborate with internal teams like InfoSec, Engineering, Product and Safety to design scalable solutions.</li> <li><strong>Help grow the DR team</strong>: Guide and support junior engineer careers and contribute to hiring.</li> </ul> <p><strong>You Have:</strong></p> <ul> <li><strong>8+ years of experience in Detection and/or Response</strong>: with a passion for security engineering, threat detection, threat hunting, and incident management.</li> <li><strong>4+ years of Security Data Engineering experience with streaming pipelines</strong>: You’ve built production grade ETL data processing pipelines end to end using Kafka / PubSub, Spark / Flink, Athena / BigQuery or similar.</li> <li><strong>Software Development (SWE):</strong> Mastery building efficient, reliable, CI/CD deployed, scalable systems using programming languages like C, Golang or Java.</li> <li><strong>Engineering experience with SIEM, EDR, NDR, and SOAR technologies:</strong> You have on-boarded logs in your sleep and built custom detections/automations for complex environments.</li> <li><strong>Conducted incident response: </strong>Structured, mature incident response processes are your vocabulary to swiftly resolve security incidents. Afterwards, you use evidence and data to tell the story and ensure action items are meticulous and complete.</li> <li><strong>Familiarity across multiple domains:</strong> Deep understanding of network protocols, operating systems, cloud environments, virtualized hosts, containers, in order to identify potential threats to each.</li> <li><strong>Core security skills ... (truncated, view full listing at source)
Apply Now

Direct link to company career page

Share this job