Senior Security Auditor (Vendor/General)
24 days ago
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
About the role:
As a Senior Security Auditor in the Internal Audit team, you will build the development of a comprehensive vendor audit program and assess vendors to assure Roblox's security and compliance requirements are met. You will also perform IT risk evaluations, audits, and readiness exercises around Roblox's internal technology environment supporting Information Security Compliance objectives. We are looking for a qualified security auditor with demonstrated technical skills. You will report to the IT Audit Manager, and partner with the Engineering, Information Security, Legal, and Trust & Safety teams at Roblox.
- Focus on building the Vendor [Third-party/BPO(business processing outsourcing)] Security Audit program, and develop repeatable methods to ensure consistency in results and help develop an internal knowledge base.
- Conduct technical security and privacy audits in areas including vendor security, production engineering security, cloud security, data security and privacy, vulnerability management, end-point security and network security
- Guide the identification and implementation of new processes/controls required by regulatory compliance frameworks, and the remediation of corrective action plans relating to audit findings
- Work with XFN teams (including engineering, security, legal, trust and safety, product management) to perform security audits and help create integrated security requirements for Roblox
- Conceive and lead ad hoc analyses of IT & Information Security data to assist other areas of the internal audit responsibility
- Work on internal tool implementation, such as Auditboard
- Bachelor's degree in Information Technology, Information Systems, Computer Science or a related technical field of study
- 5+ years professional IT audit/security compliance experience
- 2+ years experience in assessing vendor (Third-party/BPO) risks and controls
- Solid technical knowledge in multiple security and privacy compliance frameworks including: GDPR, NIST, ISO 27001, SOC 2, PCI DSS
- Compliance and risk management skills, CISSP, CISM, CIPP, CISA Certification
- Beginner to intermediate knowledge of scripting languages such as structured query language, Python, Shell scripting etc.)
- Proficient in GRC tools and Auditboard
- Bonus: software development tools (e.g. GitHub, Jenkins, Chef, Puppet, Nagios) and Atlassian products
For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits.
Annual Salary Range
$131,180 — $160,700 USD
Create Your Profile — Game companies can contact you with their relevant job openings.
Roles that are based in our San Mateo, CA Headquarters are in-office Tuesday, Wednesday, and Thursday, with optional in-office on Monday and Friday (unless otherwise noted).
- Industry-leading compensation package
- Excellent medical, dental, and vision coverage
- A rewarding 401k program
- Flexible vacation policy
- Roflex - Flexible and supportive work policy
- Roblox Admin badge for your avatar
- At Roblox HQ:
- Free catered lunches five times a week and several fully stocked kitchens with unlimited snacks
- Onsite fitness center and fitness program credit
- Annual CalTrain Go Pass
Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.