Replit
Senior Software Engineer, Risk
Foster City, CA · Senior · Full-time
Sponsorship not specifiedDetected 56 days ago
TypeScriptPythonGoSQLBigQuerySnowflakeGCPCloud PlatformsKubernetesCI/CDLinuxMachine LearningData AnalysisLLMsCybersecurityDetection EngineeringZendeskResearchCommunicationCollaboration
About the role
- The Risk team is the front line defending Replit's platform from exploitation.
- We detect and shut down phishing deployments, prevent cryptomining on free-tier infrastructure, stop LLM token farming, and keep bad actors from weaponizing the platform against our users.
- What makes this role unique is the AI-native nature of Replit's platform.
Responsibilities
- attackers adapt constantly, and we build the detection systems, heuristics, and automated responses that stay ahead of them.
- Design and implement LLM guardrails that detect abuse scenarios in AI-generated code and agent interactions
- Build AI-powered detection systems that use LLMs to identify malicious patterns, classify threats, and automate response decisions
- Build and operate abuse detection systems that identify phishing, cryptomining, account takeover, and financial fraud across millions of daily user actions
- Design automated response mechanisms that enforce platform policies without manual intervention
- This is adversarial work: attackers adapt constantly, and we build the detection systems, heuristics, and automated responses that stay ahead of them.
- You'll own problems end-to-end, from identifying emerging abuse patterns to shipping the systems that stop them at scale.
- Own the full abuse response lifecycle: detection, investigation, enforcement, and handling appeals alongside Support and Legal
- You prefer deep security research over building operational detection systems
- You prefer working in isolation rather than partnering closely with Support, Legal, and cross-functional teams
Requirements
- Required skills and experience:
- Familiarity with common attack patterns: phishing infrastructure, account takeover, credential stuffing, resource abuse
Nice to have
- Experience at a platform company dealing with user-generated content or compute abuse (hosting providers, cloud platforms, developer tools)
- Background in fraud detection, payment abuse, or financial crime
- Familiarity with device fingerprinting, IP reputation, and email validation services
- Experience with CI/CD security tooling (SAST, SCA, Dependabot, Snyk)
- Knowledge of container security, Linux internals, or cloud infrastructure (GCP preferred)
- Prior work with abuse reporting pipelines, trust & safety tooling, or content moderation systems
- Tools + Tech Stack for this role
- Languages: Python, TypeScript, Go, SQL
Skills
- 4+ years of experience in security engineering, anti-abuse, trust & safety, or fraud detection
- Experience with SQL and data analysis at scale (BigQuery, Snowflake, or similar)
- Familiarity with prompt injection, jailbreaking, and other LLM-specific attack vectors
- Ability to investigate complex abuse patterns and translate findings into automated defenses
- Slurper, Netwatch, Stytch (device fingerprint); ClearOut (email reputation)
- Analyze attack patterns using BigQuery and Hex, turning investigation findings into new detection rules
- Integrate and tune security scanners (SAST, SCA) in CI pipelines with tight performance SLAs
- Track abuse trends, measure detection effectiveness, and adapt defenses as attack patterns evolve
Compensation
- 💰 Competitive Salary & Equity
Company info
- Replit Blog https://blog.replit.com/
- Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
- Operating Principles https://blog.replit.com/operating-principles
- Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit
- Replit is the agentic software creation platform that enables anyone to build applications using natural language.
This listing is sourced directly from Replit's careers page and normalized into a canonical job model.