Overview
As a founding member of Roblox’s EMEA Security Operations, you design and operationalize detections, automations, and tooling to protect players, developers, and the platform at global scale. You act as primary Incident Commander for the region, autonomously guiding 24/7/365 monitoring and response. You shape the security engineering direction and drive hands-on investigations, threat hunting, and durable, automated detections. This role blends deep engineering with executive leadership in a fast-moving, mission-driven environment.
Responsibilities
- Design, write, and maintain production-quality detections, automations, and integrations (detections-as-code, SOAR playbooks, data/enrichment pipelines)
- Develop and improve tooling and platform support for alert quality, enrichment, case management, and cross-timezone hand-offs (follow-the-sun)
- Serve as the primary Incident Commander for Europe, making time-critical decisions independently
- Shape technical direction for detection and response, optimizing global hand-offs and automation
- Lead security incident responses end-to-end, mitigating threats and translating learnings into durable detections
- Conduct forensic investigations and threat hunting to identify and respond to anomalies
- Lead high-profile responses in collaboration with Security and Engineering
- Collaborate with Legal, HR, Executives and external partners; travel to the US HQ as needed
Key requirements
- 10+ years in security engineering, Infosec, IT, Infra/SRE, or Incident Response
- 7+ years in Detection or Response with a track record of building or writing detections, automation, or tooling
- Proficiency in production-quality scripting and building automations/data pipelines
- Experience leading autonomous, distributed teams and acting as incident commander
- Extensive incident command experience and ability to coordinate responders and communicate with leadership
- Expertise in investigations and threat hunting in enterprise and production environments
- Deep understanding of security tooling (SIEM, EDR, IDS/IPS, NDR, SOAR) and applying IR frameworks (NIST IR Lifecycle, MITRE ATT&CK)
- Bachelor’s degree in Computer Science, Cybersecurity, or related field; advanced degree preferred or equivalent experience
- Autonomous leadership
- Strategic self-starter
- Detailed thinker
- Detection engineering and automation
- SOAR and orchestration
- Data pipelines and enrichments
…
