SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Software Engineer, Sandbox Platforms

Roblox - San Mateo, CA, United States - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 269,170 - 326,060 / annual

Roblox is seeking a Senior Security Software Engineer to design, build, and harden process sandboxes that contain untrusted and semi-trusted code across Linux, macOS, and Windows platforms. This is a deep systems role focused on isolation layers and the boundary between trusted and untrusted execution environments. You will be responsible for designing and implementing sandboxes using platform-specific primitives: nsjail, seccomp-bpf, namespaces, cgroups, and Landlock on Linux; Seatbelt (sandbox_init / SBPL) on macOS; and AppContainer, job objects, restricted tokens, and integrity levels on Windows. You will define and lock down every communication path in and out of the sandbox—syscalls, IPC, shared memory, file descriptors, sockets, and brokers—minimizing exposure at each interface. Key responsibilities include enumerating and reducing attack surface (kernel syscall surface, broker interfaces, device access, side channels), making deliberate engineering tradeoffs between isolation strength, performance, compatibility, and maintainability, and writing threat models and reviewing designs. You will respond to sandbox escapes and hardening findings, treating the code inside the sandbox as potentially hostile. This role is ideal for someone who thinks in terms of attack surface, threat models, and the exact boundary between trusted and untrusted code. You will be working on one of the last lines of defense when something inside a sandbox goes wrong, protecting tens of millions of users on the Roblox platform. Roblox offers a hybrid work arrangement with office presence required Tuesday, Wednesday, and Thursday at the San Mateo headquarters, with optional presence on Monday and Friday. REQUIREMENTS: - Deep, hands-on knowledge of OS security model on at least one of Linux, macOS, or Windows, and the sandboxing primitives that platform provides - Strong grasp of attack surface analysis: how sandboxes are escaped and how to shrink the ways in - Fluency in the boundary between sandbox and host (brokers, IPC, syscall filtering, privilege separation) and ability to design a minimal, well-audited interface - Systems programming in C, C++, or Rust; comfort at the syscall and kernel-interface level - Sound judgment on tradeoffs: knowing when tighter isolation is worth the cost and when it isn't - Security mindset: default to least privilege and distrust every input crossing the boundary NICE TO HAVE: - Experience across more than one of the three platforms - Kernel, hypervisor, or low-level OS internals work - Fuzzing, exploit development, or red-team experience against isolation boundaries

Similar roles