Replit
Senior Technical Program Manager, Security
Foster City, CA · Senior · Full-time
Sponsorship not specifiedDetected 20 hours ago
GitGCPCloud PlatformsSite Reliability EngineeringPlatform EngineeringData VisualizationCybersecuritySOC OperationsComplianceAgileJiraSupply ChainVendor ManagementLeadershipCommunicationCollaboration
> stay_score
odds of building a lasting career here
37Risky
Cap-exempt (no lottery)0
Sponsors this role80
Entry-level history0
PERM / green-card track0
Lottery odds40
Fits your clock70
Thin sponsorship signal and lottery-bound. A low-probability bet with your clock running. Prioritize cap-exempt roles and proven entry-level sponsors first.
Lottery odds assume a STEM candidate.
Personalize to your clock →> community_outcomes
No reports yet — be the first to help the next applicant.
About the role
- Code & Supply Chain Security: Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling (Wiz Code, Snyk, Dependabot, code scanning, secret scanning) across engineering repos, including dependency and supply-chain risk.
- Escalation & Exceptions: Define and enforce escalation paths for overdue or critical/high-severity findings, including risk acceptance and exception processes with appropriate sign-off.
- Bug Bounty Expertise: Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows.
Responsibilities
- Program Ownership: Own and continuously improve the vulnerability management program, including intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types.
- Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure - IAM, networking, Compute/GKE, storage, and logging/monitoring configuration - by partnering with security, cloud, and platform engineering teams.
- SaaS Vendor Risk: Build and manage the process for assessing and tracking security posture across third-party SaaS applications.
- Cross-Team Accountability: Partner with engineering managers and tech leads to embed remediation work into sprint planning and hold teams accountable to remediation SLAs.
- Reporting & Alerting: Establish and maintain a single source of truth for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for engineering leadership, security leadership, and executives.
- Audit & Compliance Support: Support audit and compliance efforts (SOC 2, ISO 27001, customer security questionnaires) by keeping vulnerability management evidence and metrics audit-ready.
- Process & Automation: Drive process improvements and automation to reduce manual triage effort and improve time-to-remediation across all vulnerability sources.
Requirements
- Required Skill & Experience:
- Cloud Security Knowledge (GCP): Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks.
- Systems Thinking: The ability to see the "big picture" and understand how vulnerability management decisions impact the entire stack - cloud, code, and vendor ecosystem alike.
Skills
- Risk Prioritization: Strong grasp of vulnerability scoring frameworks (CVSS) and risk-based prioritization.
- Compliance Awareness: Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP.
Compensation
- 💰 Competitive Salary & Equity
Benefits
- Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends.
- Reporting Tools: Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) that give leadership real-time visibility into program health.
This listing is sourced directly from Replit's careers page and normalized into a canonical job model.