- Company Name
- Roku
- Job Title
- Senior Software Engineer, Application Security
- Job Description
-
Job Title: Senior Software Engineer, Application Security
Role Summary:
Design, build, and maintain secure, scalable cloud infrastructure and application security controls for a global streaming platform. Lead automation, threat modeling, and secure SDLC integration across cross‑functional teams.
Expectations:
- Own end‑to‑end security solutions impacting millions of users.
- Deliver high‑quality, auditable infrastructure-as-code deployments.
- Drive security best practices and continuous improvement.
Key Responsibilities:
- Architect secure cloud deployments using Terraform, Kubernetes, AWS native services, Linux, and embedded C++.
- Automate provisioning and upgrades via IaC; develop Go/Python tooling for consistency and auditability.
- Conduct threat modeling, security reviews, and risk assessments for new and existing services.
- Embed security into application architectures and SDLC workflows; lead secure code/design reviews.
- Evaluate and champion new technologies, methodologies, and automation for secure development.
- Collaborate with infrastructure, platform, and application teams to integrate security into deployment pipelines.
- Leverage AI tools to improve learning and productivity.
- Manage project priorities, schedules, and deliverables autonomously.
Required Skills:
- 5+ years of securing and operating web services and Kubernetes in production.
- Deep expertise in Terraform, Kubernetes, AWS native services, Linux, and secure cloud design.
- Proficient in Go and Python automation; C++/Rust familiarity a plus.
- Strong knowledge of network isolation, least privilege, zero trust, secrets management, and secure architecture patterns.
- Experience with REST, WebSockets, HTTPS, JSON, Protobuf; threat modeling and secure SDLC practices.
- Excellent communication, collaboration, and leadership skills in cross‑functional settings.
Required Education & Certifications:
- Bachelor’s or Master’s degree in Computer Science, Engineering, or equivalent.
- Relevant security certifications (e.g., CISSP, CISM, GSEC) highly desirable but not mandatory.
Manchester, United kingdom
Hybrid
Senior
09-03-2026