Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
Roblox provides a platform and tools for a global community to create immersive 3D digital experiences. Its vision is to bring people together through shared experiences and connect a billion people with optimism and civility.
задачи
Design, write, and maintain production-quality detections, automations, integrations, SOAR playbooks, and data and enrichment pipelines to scale monitoring and reduce manual toil
Develop and improve global SIRT/SOC tooling for alert quality, enrichment, case-management integrations, automation, and reliable follow-the-sun hand-offs
Act as the primary Incident Commander for the European time zone, making critical, time-sensitive decisions independently and serving as the senior-most security engineering contact in the region
Shape the technical direction of detection and response engineering and architect optimized, automated global hand-offs and follow-the-sun models
Lead serious security incident responses end-to-end, mitigate impacts, capture lessons learned, and turn them into durable, automated detections
Investigate complex threats and proactively hunt for anomalous activity, distinguishing outliers from threats
Collaborate with Security and Engineering to lead responses to major vulnerabilities and platform-wide events
Work with Legal, HR, executive teams, external partners, developers, and customers
Travel semi-regularly to the USA to visit headquarters and align with central engineering and security leadership
требования
10+ Years across security engineering, InfoSec, IT, infrastructure/SRE, and/or incident response
7+ Years specifically in detection or response, with a track record of building and writing detections, automation, or security tooling; experience must extend beyond operating tools
Ability to write and review production-quality code and build automations, integrations, and data pipelines
Proven ability to work independently in satellite offices or distributed teams and make business-impacting decisions
Extensive experience as an incident commander, coordinating responders and communicating status to leadership
Expert-level threat investigation experience in enterprise and production environments, taking ownership from identification to resolution
Deep understanding of SIEM, EDR, IDS/IPS, NDR, and SOAR tooling, and experience extending or building these tools
Proficiency applying NIST IR Lifecycle, Cyber Kill Chain, and MITRE ATT&CK to real-world scenarios
Extensive expertise across public cloud, operating systems, virtualization, containerization, networking, build/development infrastructure, and hardware
Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent experience
Comfortable taking ownership, identifying coverage gaps, handling complex issues, and making calculated decisions under pressure
Будет плюсом: an advanced degree
условия
Work from a dedicated, private space within a shared office environment
Office-based roles are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday, unless otherwise noted
Semi-regular travel to the USA to visit headquarters