Replit

Replit

Senior Technical Program Manager, Security

Foster City, CA · Senior · Full-time

Sponsorship not specifiedDetected 20 hours ago
GitGCPCloud PlatformsSite Reliability EngineeringPlatform EngineeringData VisualizationCybersecuritySOC OperationsComplianceAgileJiraSupply ChainVendor ManagementLeadershipCommunicationCollaboration

> stay_score

odds of building a lasting career here

37Risky
Cap-exempt (no lottery)0
Sponsors this role80
Entry-level history0
PERM / green-card track0
Lottery odds40
Fits your clock70

Thin sponsorship signal and lottery-bound. A low-probability bet with your clock running. Prioritize cap-exempt roles and proven entry-level sponsors first.

Lottery odds assume a STEM candidate.

Personalize to your clock →

> community_outcomes

No reports yet — be the first to help the next applicant.

About the role

  • Code & Supply Chain Security: Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling (Wiz Code, Snyk, Dependabot, code scanning, secret scanning) across engineering repos, including dependency and supply-chain risk.
  • Escalation & Exceptions: Define and enforce escalation paths for overdue or critical/high-severity findings, including risk acceptance and exception processes with appropriate sign-off.
  • Bug Bounty Expertise: Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows.

Responsibilities

  • Program Ownership: Own and continuously improve the vulnerability management program, including intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types.
  • Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure - IAM, networking, Compute/GKE, storage, and logging/monitoring configuration - by partnering with security, cloud, and platform engineering teams.
  • SaaS Vendor Risk: Build and manage the process for assessing and tracking security posture across third-party SaaS applications.
  • Cross-Team Accountability: Partner with engineering managers and tech leads to embed remediation work into sprint planning and hold teams accountable to remediation SLAs.
  • Reporting & Alerting: Establish and maintain a single source of truth for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for engineering leadership, security leadership, and executives.
  • Audit & Compliance Support: Support audit and compliance efforts (SOC 2, ISO 27001, customer security questionnaires) by keeping vulnerability management evidence and metrics audit-ready.
  • Process & Automation: Drive process improvements and automation to reduce manual triage effort and improve time-to-remediation across all vulnerability sources.

Requirements

  • Required Skill & Experience:
  • Cloud Security Knowledge (GCP): Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks.
  • Systems Thinking: The ability to see the "big picture" and understand how vulnerability management decisions impact the entire stack - cloud, code, and vendor ecosystem alike.

Skills

  • Risk Prioritization: Strong grasp of vulnerability scoring frameworks (CVSS) and risk-based prioritization.
  • Compliance Awareness: Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP.

Compensation

  • 💰 Competitive Salary & Equity

Benefits

  • Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends.
  • Reporting Tools: Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) that give leadership real-time visibility into program health.

This listing is sourced directly from Replit's careers page and normalized into a canonical job model.