×
Register Here to Apply for Jobs or Post Jobs. X

Senior Offensive Security Engineer

Job in San Mateo, San Mateo County, California, 94409, USA
Listing for: OneClick Smart Resume
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer
Salary/Wage Range or Industry Benchmark: 197000 - 243000 USD Yearly USD 197000.00 243000.00 YEAR
Job Description & How to Apply Below

Senior Offensive Security Engineer

Roblox San Mateo, CA, United States

Job Description

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device.

We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.

You Have
  • 4+ years: of relevant professional experience in offensive security, with demonstrated experience in purple team exercises, breach attack simulation, and detection engineering collaboration.
  • Development experience: proficiency in Python or Go for building security tooling and automation, including experience with SOAR platforms and configuration management.
  • Security assessment expertise: performing full-stack security assessments of web applications, APIs, cloud infrastructure, and backend systems.
  • Platform expertise: implementing and managing breach attack simulation platforms while working with detection engineering teams to validate and improve detection coverage.
  • Deep understanding: of OWASP Top 10 vulnerabilities; common attack techniques; exploit development; post-exploitation methodologies; security assessment frameworks (MITRE ATT&CK, PTES); BAS methodologies; and modern detection stack components (EDR, SIEM, XDR).
  • Knowledge: of security concepts including reverse engineering, cloud security (AWS/Azure/GCP), container security, CI/CD pipeline security, API security, and security metrics development.
  • Certifications:

    such as OSCP, OSCE, GXPN, or equivalent practical experience.
  • Organizational skills: strong analytical and problem-solving abilities; excellent technical writing for detailed reports; ability to clearly communicate complex technical concepts; self-motivated with a passion for offensive security and detection engineering.
You Will
  • Perform offensive security assessments: conducting full-stack security assessments across our entire technology stack, including web applications, APIs, cloud infrastructure, and backend systems.
  • Drive detection engineering partnerships: collaborating with detection engineers through purple team exercises, attack simulations, and threat emulation to validate and improve detection coverage.
  • Develop custom tools and frameworks: creating and maintaining security testing tools, BAS frameworks, and automation scripts that enable repeatable testing and quantifiable security improvements.
  • Build security metrics: designing and implementing frameworks to measure security control effectiveness, detection coverage, and improvement over time through consistent testing methodologies.
  • Research and innovate: staying current with latest attack techniques, tools, and methodologies while contributing to both offensive and defensive security improvements.
  • Broadly collaborate: sharing knowledge across security teams and fostering a culture of continuous security improvement.
You Are
  • Collaborative:
    You thrive working with your direct team and cross-functional partners, especially in bridging the gap between offensive operations and detection engineering.
  • Thoughtful of build vs. buy decisions:
    Comfortable with deploying and configuring Open Source software, but you also review what tools are available in the market to make informed decisions about tool selection and development.
  • Comfortable with ambiguity:
    You can gather data and make informed decisions when there is no clear answer, especially when dealing with novel attack scenarios or detection challenges.
  • Security-minded educator:
    You excel at translating complex technical findings into actionable insights for various stakeholders across the organization.
  • Metrics-driven:
    You…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary