Sobre este puesto de Senior Privacy Engineer en Roblox
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
As a Senior Privacy Engineer on the Security and Privacy GRC team, you will shepherd and grow Roblox's Privacy Review Program, the technical and process backbone that ensures privacy is engineered into every product before it ships. You will join the Security and Privacy GRC team, reporting to the Sr Engineering Manager for Privacy Governance and Operations. This is a hands-on privacy engineering role: you'll set standards for privacy-enhancing technologies, act as the go-to SME for policy-as-code, and partner closely with Product teams, Trust & Safety, Legal, and Regulatory Compliance as part of Roblox's broader cross-functional privacy program.
You will:
- Shepherd and evolve the Privacy Review Program, designing consistent intake workflows, evaluation criteria, and documentation to systematically assess privacy risk across new products, features, and infrastructure changes.
- Develop standards and guidelines that enable product teams to adopt privacy-enhancing technologies (PETs) such as differential privacy, k-anonymity, data minimization, and secure computation, with clear guidance on trade-offs and implementation patterns.
- Act as the Privacy SME for policy-as-code, translating privacy requirements and regulatory obligations into automated, enforceable controls embedded directly into engineering workflows and infrastructure.
- Partner cross-functionally with Regulatory Compliance, Trust & Safety, and Legal to align Privacy Review Program outcomes with broader compliance obligations and evolving global privacy frameworks.
- Drive privacy-by-design adoption across product and engineering organizations through self-service tooling, consultation, and scalable enablement programs.
- Communicate privacy risk posture and program health to product stakeholders and cross-functional partners, turning complex technical findings into clear, actionable guidance.
You have:
- 5+ years of relevant professional experience in privacy engineering, privacy program management, or a related security/compliance discipline.
- Experience owning or significantly shaping a privacy review process, privacy governance function, or equivalent, including designing review workflows, managing stakeholder intake, and driving decisions to closure.
- Deep expertise in privacy-enhancing technologies (PETs), such as differential privacy, homomorphic encryption, k-anonymity, federated learning, and secure multi-party computation; and sound judgment about their real-world trade-offs in production environments.
- Experience identifying and mitigating privacy vulnerabilities in data systems, including identifiability risks such as inference, linkage, and homogeneity attacks, and other privacy risks more broadly.
- Hands-on experience with policy-as-code tooling for automating compliance enforcement in engineering pipelines (e.g., OPA/Rego, Cedar, or similar policy engines).
- Strong understanding of global data protection regulations, including GDPR, CCPA/CPRA, COPPA, and LGPD; and the technical implications of each for product and infrastructure design.
- Demonstrated ability to drive alignment across engineering, legal, policy, and compliance stakeholders without direct management authority.
- Bachelor's degree or equivalent experience in Computer Science, Information Security, or a similar technical field.
You are:
- A skilled translator: You articulate technical privacy trade-offs to legal and compliance audiences, and unpack regulatory requirements clearly for engineering teams.
- Organized and process-oriented: You manage multiple concurrent program tracks with precision and accountability in a fast-moving environment.
- Comfortable with ambiguity: You build structure and rigor where little exists, take ownership of outcomes, and know when to drive autonomously versus escalate.
- Collaborative: You move work forward across teams you don't directly manage and build trust quickly with diverse stakeholders.
- Genuinely invested in user privacy: You see it as a core product and platform value, not a compliance formality, and you make the case for it compellingly.
For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.
Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).
Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.
For US based roles only, please note the Company may not be able to employ candidates for this role who have United States work authorization related to certain U.S. visa categories, or support future H-1B sponsorship at this time.