Principal Security GRC Analyst

Roblox•San Mateo, CA
•$288,020 - $335,580•Onsite

About The Position

As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls programs. You will have the opportunity to shape how GRC operates at scale and contribute to a collaborative, high-performing team culture that supports Roblox and the broader security organization. This position is part of the Information Security team. This role will report to the GRC Manager.

Requirements

  • 10+ years of relevant professional experience in Security Governance, Risk and Compliance
  • Experience interfacing with software engineers to identify risks, map commitments to controls and develop relevant policies
  • Experience assessing adherence to policies and developing mitigation and remediation plans when gaps exist
  • Deep understanding of risk assessment, compliance frameworks, creation of policy, and how to educate organizations on these concepts
  • Understanding of security concepts and a broad range of security risks and controls
  • Experience in tech; however the need to actively code is not required for the role, just the ability to interface with Engineers and quickly establish credibility

Responsibilities

  • Lead one or more program areas in our Governance, Risk, and Compliance team
  • Be a key contributor to the larger Information Security Organization
  • Partner with GRC, Infosec and Engineering colleagues and support the design and implementation of a “risk first” governance function that is “right-sized” for Roblox
  • Identify opportunities to improve efficiency and effectiveness, designing tools and automations along the way to drive security and compliance by design
  • Write, revise, and manage information security policies, standards, and procedures
  • Identify and assess information security risks
  • Work with Information Security and Engineering colleagues to implement appropriate controls to mitigate identified risks
  • Validate control design and effectiveness
  • Support ongoing risk monitoring and reporting
  • Be a subject matter expert in the GRC space, providing education and guidance to others across the Roblox organization
  • Be a part of the Roblox community, living our values and securing the metaverse

Benefits

  • Equity compensation
  • Benefits as described on this page
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service