Senior Offensive Security Engineer
Roblox
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
31 open offensive roles across 18 companies are on ApplySarthi right now, most of them in Bengaluru (1).
- Offensive Security EngineerStripe
- Manager, Offensive SecurityPfizer
- Senior Offensive Security ResearcherSentinelOne
- AI Security Engineer / Offensive Security Engineer - TechnologyJobgether
- Senior Offensive Cybersecurity Test AnalystBoeing
What offensive roles keep asking for: Python (52%), Penetration testing (32%), AWS (29%), Azure (26%), C++ (23%), GCP (23%), SIEM (23%), LLMs (19%) — counted across their open postings here.
AWS jobs · Azure jobs · CI/CD jobs · Excel jobs
Roblox has 257 open roles listed here.
- Law Enforcement Liaison, Kansas
- Director of Product, Payments and Wallet
- Distinguished Engineer, Machine Learning - Discovery
- Principal Software Engineer - Object Store
- Senior Frontend Engineer, Discovery UX
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for offensive roles keep coming back to Python, Penetration testing, AWS, Azure. Practise those questions before you sit with Roblox.
Questions you are likely to be asked
- Why do you want to join Roblox?
- What is your experience with AWS? Tell me one thing you learned the hard way.
- Tell me about an outage you handled. What did you learn from it?
- How do you decide what to monitor, and what should wake someone up at night?
- How would you cut the cloud bill of a system without hurting it?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Senior Offensive Security Engineer at Roblox interview free →Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working closely with the larger InfoSec team, detection engineers, and external engineering partners, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements.
You Have:
- 4+ years: of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration.
- Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management.
- Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems.
- Platform expertise: implementing and managing breach attack simulation platforms while working with detection engineering teams to validate and improve detection coverage.
- Deep understanding: of OWASP Top 10 vulnerabilities; common attack techniques; exploit development; post-exploitation methodologies; security assessment frameworks (MITRE ATT&CK, PTES); BAS methodologies; and modern detection stack components (EDR, SIEM, XDR).
- Knowledge: of security concepts including reverse engineering, cloud security (AWS/Azure/GCP), container security, CI/CD pipeline security, API security, and security metrics development.
- Certifications: such as OSCP, OSCE, GXPN, or equivalent practical experience.
- Organizational skills: strong analytical and problem-solving abilities; excellent technical writing for detailed reports; ability to clearly communicate complex technical concepts; self-motivated with a passion for offensive security and detection engineering.
You Will:
- Perform offensive security assessments: conducting full-stack security assessments across our entire technology stack, including web applications, APIs, cloud infrastructure, and backend systems.
- Drive detection engineering partnerships: collaborating with detection engineers through purple team exercises, attack simulations, and threat emulation to validate and improve detection coverage.
- Develop custom tools and frameworks: creating and maintaining security testing tools, BAS frameworks, and automation scripts that enable repeatable testing and quantifiable security improvements.
- Build security metrics: designing and implementing frameworks to measure security control effectiveness, detection coverage, and improvement over time through consistent testing methodologies.
- Research and innovate: staying current with latest attack techniques, tools, and methodologies while contributing to both offensive and defensive security improvements.
- Broadly collaborate: sharing knowledge across security teams and fostering a culture of continuous security improvement.
You Are:
- Collaborative: You thrive working with your direct team and cross-functional partners, especially in bridging the gap between offensive operations and detection engineering.
- Thoughtful of build vs. buy decisions: Comfortable with deploying and configuring Open Source software, but you also review what tools are available in the market to make informed decisions about tool selection and development.
- Comfortable with ambiguity: You can gather data and make informed decisions when there is no clear answer, especially when dealing with novel attack scenarios or detection challenges.
- Security-minded educator: You excel at translating complex technical findings into actionable insights for various stakeholders across the organization.
- Metrics-driven: You understand the importance of measuring security improvements and can develop frameworks to quantify the effectiveness of security controls and detection capabilities.
- Improvement-oriented: You actively seek opportunities to enhance both offensive capabilities and detection coverage, always thinking about the bigger security picture.
- Adaptable: You stay current with evolving threats and defense mechanisms, adjusting your approach as the security landscape changes.
For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.
Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).
Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.
For US based roles only, please note the Company may not be able to employ candidates for this role who have United States work authorization related to certain U.S. visa categories, or support future H-1B sponsorship at this time.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Data Analyst, Operations (IP & Legal Compliance)Roblox · delhi ncr
- Developer Engagement Representative - ANZ (Australia / New Zealand) (Part-Time Contract)Roblox
- Developer Engagement Representative - LATAM (Part-Time Contract)Roblox
- Developer Engagement Representative - Malaysia (Part-Time Contract)Roblox
- Developer Engagement Representative - Philippines (Part-Time Contract)Roblox
- Developer Engagement Representative - Thailand (Part-Time Contract)Roblox
- Director of Public Policy, UAE/Middle EastRoblox
- Global Developer Engagement Representative, Part-Time, ContractorRoblox
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-07-23. ApplySarthi collects openings and links to application pages; the role is advertised by Roblox, not by us.