- Страна
- Великобритания
Откликайтесь
на вакансии с ИИ

Senior Security Engineer
Roku — лидер рынка с уникальной культурой и интересными техническими задачами. Позиция предлагает работу с передовыми технологиями (AI, Cloud, K8s) и гибридный формат работы в стабильной публичной компании.
Сложность вакансии
Роль требует глубоких знаний в широком спектре дисциплин: от DevSecOps и безопасности Kubernetes до наступательных операций и программирования. Высокий уровень ответственности за глобальную инфраструктуру и необходимость автоматизации сложных процессов делают эту позицию сложной.
Анализ зарплаты
Предлагаемая роль Senior уровня в Манчестере соответствует верхнему сегменту рынка для Великобритании. Крупные технологические компании, такие как Roku, обычно предлагают зарплаты выше среднего по региону, дополняя их значительным пакетом бонусов и акций (RSU).
Сопроводительное письмо
I am writing to express my strong interest in the Senior Security Engineer position at Roku. With a robust background in cloud security and DevSecOps, I have consistently focused on building automated, scalable security solutions that align perfectly with the Trust Cloud team's mission. My experience in designing secure architectures and implementing end-to-end security controls in multi-cloud environments (AWS/GCP) has prepared me to tackle the complex challenges of protecting a global user base.
Throughout my career, I have prioritized the integration of security into the SSDLC, leveraging Infrastructure as Code and automated vulnerability management to enhance engineering workflows. I am particularly drawn to Roku's pragmatic approach to innovation and its culture of high autonomy. I am confident that my technical expertise in Kubernetes security, IAM, and offensive cyber operations will allow me to make a significant contribution to the Trust Engineering team from day one.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в roku уже сейчас
Присоединяйтесь к команде Roku в Манчестере и защищайте стриминговую платформу №1 в мире!
Описание вакансии
Teamwork makes the stream work.
Roku is changing how the world watches TV
Roku is the #1 TV streaming platform in the U.S., Canada, and Mexico, and we've set our sights on powering every television in the world. Roku pioneered streaming to the TV. Our mission is to be the TV streaming platform that connects the entire TV ecosystem. We connect consumers to the content they love, enable content publishers to build and monetize large audiences, and provide advertisers unique capabilities to engage consumers.
From your first day at Roku, you'll make a valuable - and valued - contribution. We're a fast-growing public company where no one is a bystander. We offer you the opportunity to delight millions of TV streamers around the world while gaining meaningful experience across a variety of disciplines.
About The Team
The Roku trust engineering team is a close knit group of professionals with a passion for information security. Our mission is to protect our customers, partners, devices, services, infrastructure, and data. We work collaboratively, sharing insights and expertise to stay ahead of the curve. Join us, and you’ll be part of a dynamic team that thrives on challenges and celebrates victories together.
About The Role
As a Senior Security Engineer on the Trust Cloud team, your role involves evaluating, architecting, designing, and implementing end-to-end security controls to impact the global user base. A key focus is on developing automated, scalable security solutions to enhance efficiency and protect Roku. This position requires a broad breadth of security expertise across all disciplines of security, including networking, DevSecOps, security tooling implementation, policy and procedure, risk evaluation, etc.
What You Will Be Doing
- Conducting enterprise, network, and application level security reviews.
- Conducting threat modelling for infrastructure, platform, and application initiatives.
- Planning and overseeing execution of security initiatives and projects
- Partnering with infrastructure, platform, and application teams to embed security into application architectures and deployment workflows as part of a robust Secure Software Development Lifecycle (SSDLC).
- Improving IAM policies, network configurations, DNS security, and cloud resource management practices.
- Designing and implementing integrations with third-party security platforms to automate vulnerability management, secure secret handling, and cloud posture monitoring, ensuring findings are actionable and seamlessly integrated into engineering workflows.
- Responding to security incidents to triage, contain, remediate, and report.
- Leveraging AI to accelerate your learning and enhance your work products.
- Driving security initiatives end-to-end — from identifying risks to delivering solutions — with high autonomy in a fast-moving environment.
- Automating vulnerability detection, misconfiguration checks, and compliance validation across cloud and containerised environments.
- Creating reusable security automation modules, templates, and patterns for engineering teams to adopt.
We're Excited If You Have
- Experience doing security consulting and have balanced experience doing hands on implementation
- Experience supporting/leading DevSecOps initiatives and assisting teams in utilising and onboarding onto DSO platforms
- Designing, building, operating, and maintaining DSO platforms through IaC
- Offensive cyber operations such as application, system, and network level penetration testing
- Software Engineering experience with at least one general purpose programming language (ex. Python, Golang, C, Rust, etc.)
- Developed and/or implemented data tagging, data catalogs, or other data protection related activities
- Experience designing and administering enterprise identity and access management solutions at scale (ex: AD, EntraID, Okta, etc)
- Experience securely running and operating web applications, web services, and service-oriented architecture in production environments.
- A proven track record of deploying and operating Kubernetes clusters in production.
- Experience deploying and operating infrastructure in multiple cloud providers (AWS, GCP, Azure)
- Fleet administration of Linux workstations and servers
- Defensive cyber operations such as operating a SEIM, managing a SOC, or leading cyber investigations
#LI-AM3
Our Hybrid Work Approach
Roku fosters an inclusive and collaborative environment where teams work in the office Monday through Thursday. Fridays are flexible for remote work except for employees whose roles are required to be in the office five days a week or employees who are in offices with a five day in office policy.
Benefits
Roku is committed to offering a diverse range of benefits as part of our compensation package to support our employees and their families. Our comprehensive benefits include global access to mental health and financial wellness support and resources. Local benefits include statutory and voluntary benefits which may include healthcare (medical, dental, and vision), life, accident, disability, commuter, and retirement options (401(k)/pension). Our employees can take time off work for vacation and other personal reasons to balance their evolving work and life needs. It's important to note that not every benefit is available in all locations or for every role. For details specific to your location, please consult with your recruiter.
Accommodations
Roku welcomes applicants of all backgrounds and provides reasonable accommodations and adjustments in accordance with applicable law. If you require reasonable accommodation at any point in the hiring process, please direct your inquiries to EmployeeRelations@Roku.com.
The Roku Culture
Roku is a great place for people who want to work in a fast-paced environment where everyone is focused on the company's success rather than their own. We try to surround ourselves with people who are great at their jobs, who are easy to work with, and who keep their egos in check. We appreciate a sense of humor. We believe a fewer number of very talented folks can do more for less cost than a larger number of less talented teams. We're independent thinkers with big ideas who act boldly, move fast and accomplish extraordinary things through collaboration and trust. In short, at Roku you'll be part of a company that's changing how the world watches TV.
We have a unique culture that we are proud of. We think of ourselves primarily as problem-solvers, which itself is a two-part idea. We come up with the solution, but the solution isn't real until it is built and delivered to the customer. That penchant for action gives us a pragmatic approach to innovation, one that has served us well since 2002.
To learn more about Roku, our global footprint, and how we've grown, visit https://www.weareroku.com/factsheet.
By providing your information, you acknowledge that you want Roku to contact you about job roles, that you have read Roku's Applicant Privacy Notice, and understand that Roku will use your information as described in that notice. If you do not wish to receive any communications from Roku regarding this role or similar roles in the future, you may unsubscribe at any time by emailing WorkforcePrivacy@Roku.com.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Python
- Golang
- Rust
- C++
- Kubernetes
- AWS
- Google Cloud Platform
- Azure
- DevSecOps
- Infrastructure as Code
- IAM
- Active Directory
- Okta
- Linux
- SIEM
- DNS Security
- Vulnerability Management
Возможные вопросы на собеседовании
Проверка опыта интеграции безопасности в процессы разработки.
Расскажите о вашем опыте внедрения практик SSDLC в крупномасштабных облачных средах. С какими основными трудностями вы столкнулись?
Оценка навыков работы с современными контейнерными технологиями.
Какие основные векторы атак на кластеры Kubernetes вы выделяете и какие механизмы контроля (например, Network Policies, Admission Controllers) вы считаете наиболее эффективными?
Проверка способности автоматизировать задачи безопасности.
Опишите случай, когда вы автоматизировали процесс управления уязвимостями или секретами. Какие инструменты (IaC, языки программирования) вы использовали?
Оценка навыков реагирования на инциденты.
Как вы подходите к триажу и сдерживанию инцидента в мультиоблачной инфраструктуре (AWS/Azure/GCP)?
Проверка умения работать с IAM в масштабе.
Каковы лучшие практики проектирования политик IAM для обеспечения принципа наименьших привилегий в организации с тысячами сотрудников и сервисов?
Похожие вакансии
Senior Security Engineer
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security
Staff Incident Response Specialist
Senior Software Engineer, Infrastructure Security
(Senior) Information Security Professional (f/m/d)
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Великобритания