Replit

Replit

Security Operations Lead

Foster City, CA · Full-time

Sponsorship not specifiedDetected 12 days ago
PythonGoBashGitAWSGCPAzureCloud PlatformsKubernetesCI/CDLinuxSite Reliability EngineeringPlatform EngineeringOAuthMachine LearningLLMsCybersecuritySIEMSOARUEBASOC OperationsDetection EngineeringComplianceLeadership

About the role

  • You will oversee monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads.
  • This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting.

Responsibilities

  • Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation.
  • Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments.
  • Own the entire SIEM ecosystem-ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics.
  • Develop high-fidelity detections for:
  • Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases.
  • Lead day-to-day triage and threat analysis activities, ensuring accurate categorization and prioritization.
  • Drive complex investigations involving correlated events across cloud, SaaS, endpoints, and developer platforms.

Requirements

  • 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity.

Nice to have

  • Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems.
  • Previous experience at a high-growth tech company.
  • Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.).
  • Analytical rigor: Capable of making sense of large, complex, multi-source telemetry.
  • Leadership: Mentorship and guidance of analysts and engineers.
  • Adaptability: Comfortable evaluating and integrating next-gen AI-based SOC tools.
  • Clear communication: Able to articulate risk, incidents, and recommendations to both technical and executive audiences.
  • Automation mindset: Focused on reducing manual toil via SOAR, scripting, and AI augmentation.

Skills

  • Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP).
  • Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.).
  • With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
  • Cloud infrastructure (GCP, AWS, Azure)
  • Kubernetes/GKE/EKS/AKS clusters
  • SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.)
  • Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry

Compensation

  • 💰 Competitive Salary & Equity

Benefits

  • Use MITRE ATT&CK, MITRE Cloud Matrix, and threat intel to drive detection coverage.

Company info

  • Replit Blog https://blog.replit.com/
  • Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
  • Operating Principles https://blog.replit.com/operating-principles
  • Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit

This listing is sourced directly from Replit's careers page and normalized into a canonical job model.