SlipstreamJobsFresh Startup & VC-Backed Jobs

Privacy & Security Counsel

Roblox - San Mateo, CA, United States - Hybrid - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 168,100 - 211,760 / annual

Roblox is seeking a Privacy & Security Counsel to join its Privacy & Security Legal team. This role focuses on legal security matters and provides guidance on evolving global security and privacy regulations, incident response, and compliance initiatives. Key Responsibilities: • Subject Matter Expertise: Serve as an SME on global security and privacy legal landscape, including legislation, regulations, enforcement actions, and best practices. Translate complex analysis into clear, actionable guidance for legal and security teams. • Incident Response: Engage with Detection and Response and Global Security teams during security incidents. Provide legal guidance throughout the incident lifecycle—from verification and triage through containment, remediation, post-mortems, and regulatory reporting. Counsel internal stakeholders and manage customer notifications to meet global obligations. • Security Compliance: Own and deliver complex, cross-functional cybersecurity legal initiatives end-to-end, including AI and agentic-AI governance, new regulatory regimes, and major incident response improvements. Develop and continuously improve incident response policies and playbooks aligned with applicable global data privacy and security laws. • Security Team Partnership: Embed within security pods as a trusted legal resource for Application Security, GRC, Privacy Engineering, Global Security, and Infrastructure/Platform teams. Develop working understanding of Roblox's architecture, data flows, and operational constraints. • Cross-Functional Legal Support: Provide privacy and security expertise to corporate, employment, compliance, policy, regulatory, product, and commercial legal teams. The role is based in San Mateo, CA on a hybrid model (Tuesday–Thursday in office). Requirements: • 4+ years of data security, data privacy, data protection, and governance experience • Expertise in US and global data security and protection laws and regulations • Knowledge of security regulations and frameworks: GDPR, NIS2, CRA, CCPA, COPPA, CA SB 553, NIST CSF, PCI • Experience working with Information Security teams (Incident Response, Application Security, Governance) • Experience with security incidents, breaches, breach reporting to regulators, and customer notifications • Experience implementing global data protection and security requirements • Training at a major national law firm; in-house experience preferred • Active membership in at least one U.S. state bar; California Bar admission preferred • Excellent business-oriented judgment • Experience as a senior individual contributor in fast-paced technology companies, driving complex cross-functional programs • Proven track record taking ambiguous, cross-functional projects from concept to delivery with strong project management skills • Exceptional written and verbal communication skills; ability to tailor messaging to executives, engineers, and operations teams • Working familiarity with large-scale modern infrastructure (cloud platforms, microservices, observability, incident management tooling) sufficient to understand how technical architectures influence legal risk and incident response

Similar roles