Senior Security GRC Analyst

Roblox

San Mateo (CA)

On-site

USD 224,310 - 271,710

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Roblox is headquartered in San Mateo, CA, and seeks an experienced Information Security professional to join the GRC team. You will help shape a risk-first governance program across engineering and product, ensuring controls are designed and implemented with security by design.

This role reports to the GRC Manager and emphasizes collaboration, risk assessment, policy lifecycle management, and ongoing risk monitoring across Roblox.

Qualifications

  • 4+ years of relevant professional experience in Security Governance, Risk and Compliance.
  • Experience interfacing with software engineers to identify risks, map commitments to controls and develop relevant policies.
  • Experience assessing adherence to policies and developing mitigation and remediation plans when gaps exist.
  • Deep understanding of risk assessment, compliance frameworks, creation of policy, and how to educate organizations on these concepts.
  • Understanding of security concepts and a broad range of security risks and controls.
  • Experience in tech; however the need to actively code is not required for the role, just the ability to interface with Engineers and quickly establish credibility.

Responsibilities

  • Be a key contributor to the Governance, Risk, and Compliance team within the larger Information Security Organization.
  • Partner with your GRC, Infosec and Engineering colleagues and support the design and implementation of a "risk first" governance function that is "right-sized" for Roblox.
  • Identify opportunities to improve efficiency and effectiveness, designing tools and automations along the way to drive security and compliance by design.
  • Write, revise, and manage our information security policies, standards, and procedures.
  • Identify and assess information security risks. You will work with Information Security and Engineering colleagues to implement appropriate controls to mitigate identified risks. You will validate control design and effectiveness. You will support ongoing risk monitoring and reporting.
  • Be a subject matter expert in the GRC space, providing education and guidance to others across the Roblox organization.
  • Be a part of the Roblox community, living our values and securing the metaverse.

Skills

Security GRC
Policy development
Risk assessment
Engineer collaboration
Compliance frameworks
Security concepts

Job description

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.

At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.

A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.

As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization—empowering every builder to make risk‑informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox.

Our program takes a balanced, "right-sized" approach to security governance—combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership—including providing regular reporting to the Board of Directors and the Audit & Compliance Committee—to ensure that security risk is visible, well‑understood, and actioned appropriately.

The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls programs. You will have the opportunity to shape how GRC operates at scale and contribute to a collaborative, high‑performing team culture that supports Roblox and the broader security organization.

This position is part of the Information Security team. This role will report to the GRC Manager.

You will:
  • Be a key contributor to the Governance, Risk, and Compliance team within the larger Information Security Organization.
  • Partner with your GRC, Infosec and Engineering colleagues and support the design and implementation of a "risk first" governance function that is "right-sized" for Roblox.
  • Identify opportunities to improve efficiency and effectiveness, designing tools and automations along the way to drive security and compliance by design.
  • Write, revise, and manage our information security policies, standards, and procedures.
  • Identify and assess information security risks. You will work with Information Security and Engineering colleagues to implement appropriate controls to mitigate identified risks. You will validate control design and effectiveness. You will support ongoing risk monitoring and reporting.
  • Be a subject matter expert in the GRC space, providing education and guidance to others across the Roblox organization.
  • Be a part of the Roblox community, living our values and securing the metaverse.
You have:
  • 4+ years of relevant professional experience in Security Governance, Risk and Compliance.
  • Experience interfacing with software engineers to identify risks, map commitments to controls and develop relevant policies.
  • Experience assessing adherence to policies and developing mitigation and remediation plans when gaps exist.
  • Deep understanding of risk assessment, compliance frameworks, creation of policy, and how to educate organizations on these concepts.
  • Understanding of security concepts and a broad range of security risks and controls.
  • Experience in tech; however the need to actively code is not required for the role, just the ability to interface with Engineers and quickly establish credibility.

For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job‑related factors such as professional background, training, work experience, location, business needs, and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full‑time employees are also eligible for equity compensation and for benefits as described on this page.

Annual Salary Range$224,310—$271,710 USD

Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).

Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.

For US based roles only, please note the Company may not be able to employ candidates for this role who have United States work authorization related to certain U.S. visa categories, or support future H‑1B sponsorship at this time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

OneClick Smart Resume • San Mateo (CA)

On-site
USD 209,000 - 272,000
Senior Security Software Engineer, Infrastructure Security
Senior Security Software Engineer, Infrastructure Security

Roblox • San Mateo (CA)

On-site
USD 269,000 - 327,000
Senior Enterprise Security Engineer
Senior Enterprise Security Engineer

Roblox • San Mateo (CA)

On-site
USD 243,000 - 296,000
Equity compensation
Comprehensive benefits package
Engineering Manager, Application Security
Engineering Manager, Application Security

Roblox • San Mateo (CA)

On-site
USD 295,000 - 346,000
Principal Security Software Engineer, Enterprise IAM
Principal Security Software Engineer, Enterprise IAM

OneClick Smart Resume • San Mateo (CA)

On-site
USD 385,000 - 444,000
Equity compensation
Benefits package
Global Security Manager, Campus Security
Global Security Manager, Campus Security

Roblox • San Mateo (CA)

On-site
USD 157,000 - 193,000
Equity compensation
Benefits
Senior Privacy Engineer
Senior Privacy Engineer

Roblox • San Mateo (CA)

On-site
USD 181,000 - 224,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Roblox • San Mateo (CA)

Hybrid
USD 216,000 - 270,000
Equity compensation
Health benefits
Senior Manager, Security Systems and Technology
Senior Manager, Security Systems and Technology

Roblox • San Mateo (CA)

Hybrid
USD 192,000 - 237,000
Equity compensation
Comprehensive benefits package
Senior Security Software Engineer, Vulnerability Management
Senior Security Software Engineer, Vulnerability Management

Roblox • San Mateo (CA)

On-site
USD 216,000 - 270,000