Replit

Replit

Security Engineer - Vuln Management (Code)

Foster City, CA · Senior · Full-time

Sponsorship not specifiedDetected 62 days ago
JavaScriptTypeScriptPythonCI/CDCybersecurityIncident ResponseComplianceSupply ChainCollaborationProblem Solving

About the role

  • We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background.
  • In this role, you will bridge the gap between security, compliance, and engineering teams.
  • You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem.

Responsibilities

  • Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.
  • Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
  • Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.
  • Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
  • Incident Response Support: Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.
  • Build System Expertise: Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.
  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.

Requirements

  • 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
  • Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
  • The ability to see the "big picture" and understand how security decisions impact the entire stack.

Skills

  • Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.
  • Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).
  • Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.

Compensation

  • 💰 Competitive Salary & Equity

Benefits

  • Full-Time Employee Benefits Include:
  • ⚕️ Health, Dental, Vision and Life Insurance
  • 🩼 Short Term and Long Term Disability
  • 🚼 Paid Parental, Medical, Caregiver Leave
  • 🏝 Flexible Time Off (FTO) + Holidays
  • 🚗 Commuter Benefits (In-Office Only)
  • 📱 Monthly Wellness Stipend
  • 🖥 In Office Set-Up Reimbursement (In-Office Only)

Company info

  • Replit Blog https://blog.replit.com/
  • Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
  • Operating Principles https://blog.replit.com/operating-principles
  • Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit

This listing is sourced directly from Replit's careers page and normalized into a canonical job model.