Replit

Replit

Engineering Manager, Anti-Abuse & Security

Foster City, CA · Full-time

Sponsorship not specifiedDetected 56 days ago
Machine LearningData EngineeringLLMsAgentic AICommunication

About the role

  • This is a foundational 0-to-1 role: you'll define the anti-abuse roadmap, hire a small team of engineers and data analysts, and ship the systems that protect Replit's platform, users, and economics from adversarial actors.
  • Replit sits at the frontier of AI-native abuse.
  • Our platform is a target for phishing and scam hosting, cryptomining, LLM token farming, card and coupon fraud, and increasingly, abuse driven by AI agents themselves.

Responsibilities

  • Build the anti-abuse roadmap from scratch: Define the threat model, prioritize across abuse vectors (phishing/scam hosting, cryptomining, token farming, payment fraud, AI agent exploitation), and translate it into a shipping plan with clear sequencing and tradeoffs.
  • Design progressive verification and identity infrastructure: Build the "ladder of trust" that gates increasing platform capabilities (referrals, additional credits, access to powerful agent features, Missions) behind escalating verification.
  • Use the latest AI coding tools (including Replit Agent) to prototype detections, build internal tooling, and unblock your team.
  • Define the metrics that matter: Establish the measurement foundation for anti-abuse at Replit (abuse rate, fraud loss, false positive rate, time-to-detect, time-to-mitigate, verification step-up conversion) and build the data pipelines and dashboards to track them.
  • Build a culture where engineers use AI agents as force multipliers and ship fast without cutting corners on quality.
  • Operate cross-functionally: Partner with Support on abuse escalations and triage workflows, with Legal on compliance and takedown processes, with Security on overlapping threat surfaces, with Infrastructure on detection and enforcement primitives, and with the Money and Growth teams on the fraud-vs-conversion tradeoffs that sit at the heart of this work.
  • Make abuse economically unviable: Design adaptive friction systems that escalate verification only when risk signals warrant it. The goal isn't elimination
  • Experience building detection and enforcement systems at scale: rules engines, ML-based risk scoring, reputation systems, identity and device signals, or similar.

Requirements

  • 6 to 10+ years of engineering experience with 2+ years managing teams, ideally in anti-abuse, trust and safety engineering, fraud, or an adjacent adversarial domain.

Nice to have

  • Experience with AI-native abuse vectors (prompt injection, LLM token farming, agent-driven abuse) or a track record of adapting quickly to novel threat categories.
  • Familiarity with payment fraud, card testing, coupon abuse, referral abuse, or promotional abuse.
  • Experience integrating KYC and identity verification providers (Prove, Persona, Socure, Stripe Identity, or similar).
  • Experience at a consumer platform, developer tool, or cloud provider with meaningful abuse surface area.
  • Background in security, trust and safety, or fraud prevention at a hypergrowth company.
  • This is a full-time role that can be held from our Foster City, CA office.
  • The role has an in-office requirement of Monday, Wednesday, and Friday.
  • 💹 401(k) Program with a 4% match (US Only)

Skills

  • Stay in the code.

Compensation

  • 💰 Competitive Salary & Equity

Company info

  • Replit Blog https://blog.replit.com/
  • Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
  • Operating Principles https://blog.replit.com/operating-principles
  • Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit
  • A hands-on orientation: you still write code, review PRs, and prototype. Comfort using AI coding tools (Claude Code, Cursor, Replit Agent, or similar) as part of your daily workflow.

This listing is sourced directly from Replit's careers page and normalized into a canonical job model.