Senior Security Auditor
San Mateo, CA, United States
Roblox
Roblox is the ultimate virtual universe that lets you create, share experiences with friends, and be anything you can imagine. Join millions of people and discover an infinite variety of immersive experiences created by a global community!Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
Roblox is looking for a Senior Security Auditor to join the Internal Audit team to perform risk assessments, audits, and readiness exercises around Roblox's technology environment supporting Information Security Compliance goals. We are looking for a qualified security auditor with demonstrated technical skills. You will test and maintain security controls protecting Roblox's environment and provide feedback to control owners on the design, implementation and efficacy of those controls. In this role, you will also have the opportunity to work on internal tool implementations and configure systems. In addition, part of this role will include evaluating new systems and products and supporting business partners to ensure their areas are operationally efficient and compliant with regulatory frameworks. You will report into Internal Audit and partner with the Engineering, Information Security, IT and Legal teams at Roblox.
You will:
- Interact extensively with engineering teams and implement technical security and privacy audits in areas including but not limited to production engineering security, cloud security, data security, vulnerability management, end-point security, and network security.
- Support the identification, validation and remediation of controls required by regulatory compliance frameworks
- Support and drive business process automation and automation of controls testing by configuring and integrating systems using available tools
- Conceive and lead ad hoc analyses of IT & Information Security data to assist other areas of the internal audit function; develop repeatable methods to ensure consistent results and help develop an internal knowledge base
- Participate in the development and oversight of required corrective action plans relating to security audit findings
- Work with cross-functional teams (including engineering, security, product management, and finance) to help create integrated system requirements and provide security controls expertise
- Prepare work papers, write reports or other deliverables in a timely manner to adequately and clearly document testing, support conclusions, communicate findings and recommendations
- Manage multiple priorities/projects for on-time delivery.
You have:
- Bachelor's degree or equivalent work experience
- 5+ years professional IT audit/security compliance experience
- Strong technical knowledge in multiple security and privacy compliance frameworks including: GDPR, NIST, ISO 27001, SOC 2, PCI DSS
- Strong compliance and risk management skills, CISA, CISM, or CISSP Certification
- Beginner to intermediate knowledge of scripting languages (i.e. SQL, Python, Shell scripting etc.)
- Proficient with open source software tools (e.g. GitHub, Jenkins, Chef, Puppet, Nagios) Atlassian products and GRC tools
#LI-Hybrid
For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits.Annual Salary Range$131,180—$160,700 USDYou’ll Love:
- Industry-leading compensation package
- Excellent medical, dental, and vision coverage
- A rewarding 401k program
- Flexible vacation policy
- Roflex - Flexible and supportive work policy
- Roblox Admin badge for your avatar
- At Roblox HQ:
- Free catered lunches five times a week and several fully stocked kitchens with unlimited snacks
- Onsite fitness center and fitness program credit
- Annual CalTrain Go Pass
Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Tags: Audits Automation CISA CISM CISSP Cloud Compliance Finance GDPR GitHub ISO 27001 Nagios Network security NIST Open Source PCI DSS Privacy Puppet Python Risk assessment Risk management Scripting SOC SOC 2 SQL Vulnerability management
Perks/benefits: Career development Equity Flex hours Flex vacation Health care Unlimited paid time off
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Information Security Specialist jobs
- Open Cyber Security Specialist jobs
- Open Manager Pentest H/F jobs
- Open Cyber Security Architect jobs
- Open Senior Cyber Security Engineer jobs
- Open Product Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Staff Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Security Specialist jobs
- Open Senior Information Security Engineer jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open IT Security Engineer jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Application security-related jobs
- Open Pentesting-related jobs
- Open Agile-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open SaaS-related jobs
- Open Analytics-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open Malware-related jobs
- Open EDR-related jobs
- Open Kubernetes-related jobs
- Open CEH-related jobs
- Open Forensics-related jobs