Replit
Security Engineer - Vuln Management (Code)
Foster City, CA · Senior · Full-time
Sponsorship not specifiedDetected 62 days ago
JavaScriptTypeScriptPythonCI/CDCybersecurityIncident ResponseComplianceSupply ChainCollaborationProblem Solving
About the role
- We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background.
- In this role, you will bridge the gap between security, compliance, and engineering teams.
- You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem.
Responsibilities
- Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.
- Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
- Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.
- Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
- Incident Response Support: Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.
- Build System Expertise: Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.
- Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
Requirements
- 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
- Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
- The ability to see the "big picture" and understand how security decisions impact the entire stack.
Skills
- Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.
- Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).
- Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.
Compensation
- 💰 Competitive Salary & Equity
Benefits
- Full-Time Employee Benefits Include:
- ⚕️ Health, Dental, Vision and Life Insurance
- 🩼 Short Term and Long Term Disability
- 🚼 Paid Parental, Medical, Caregiver Leave
- 🏝 Flexible Time Off (FTO) + Holidays
- 🚗 Commuter Benefits (In-Office Only)
- 📱 Monthly Wellness Stipend
- 🖥 In Office Set-Up Reimbursement (In-Office Only)
Company info
- Replit Blog https://blog.replit.com/
- Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
- Operating Principles https://blog.replit.com/operating-principles
- Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit
This listing is sourced directly from Replit's careers page and normalized into a canonical job model.