Replit
Security Operations Lead
Foster City, CA · Full-time
Sponsorship not specifiedDetected 12 days ago
PythonGoBashGitAWSGCPAzureCloud PlatformsKubernetesCI/CDLinuxSite Reliability EngineeringPlatform EngineeringOAuthMachine LearningLLMsCybersecuritySIEMSOARUEBASOC OperationsDetection EngineeringComplianceLeadership
About the role
- You will oversee monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads.
- This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting.
Responsibilities
- Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation.
- Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments.
- Own the entire SIEM ecosystem-ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics.
- Develop high-fidelity detections for:
- Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases.
- Lead day-to-day triage and threat analysis activities, ensuring accurate categorization and prioritization.
- Drive complex investigations involving correlated events across cloud, SaaS, endpoints, and developer platforms.
Requirements
- 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity.
Nice to have
- Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems.
- Previous experience at a high-growth tech company.
- Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.).
- Analytical rigor: Capable of making sense of large, complex, multi-source telemetry.
- Leadership: Mentorship and guidance of analysts and engineers.
- Adaptability: Comfortable evaluating and integrating next-gen AI-based SOC tools.
- Clear communication: Able to articulate risk, incidents, and recommendations to both technical and executive audiences.
- Automation mindset: Focused on reducing manual toil via SOAR, scripting, and AI augmentation.
Skills
- Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP).
- Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.).
- With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
- Cloud infrastructure (GCP, AWS, Azure)
- Kubernetes/GKE/EKS/AKS clusters
- SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.)
- Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry
Compensation
- 💰 Competitive Salary & Equity
Benefits
- Use MITRE ATT&CK, MITRE Cloud Matrix, and threat intel to drive detection coverage.
Company info
- Replit Blog https://blog.replit.com/
- Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
- Operating Principles https://blog.replit.com/operating-principles
- Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit
This listing is sourced directly from Replit's careers page and normalized into a canonical job model.