Replit

Replit

Product Security Architect

Foster City, CA · Full-time

Sponsorship not specifiedDetected 69 days ago
JavaScriptPythonGoCode ReviewAPI DevelopmentOAuthCybersecurityProduct StrategySalesCollaborationProblem SolvingMentoring

About the role

  • We are looking for a Product Security Architect to serve as the subject matter expert for Replit's secure product blueprint.
  • You will be a key technical contributor-leading high-impact security initiatives and providing deep subject matter expertise to both the engineering organization and executive leadership.

Responsibilities

  • Security Mentorship: Serve as the primary security mentor and subject matter expert for engineering teams, fostering a culture of technical excellence and rigorous security design.
  • Project Execution: Lead the security implementation of new product features from initial design to final production deployment.
  • Application Security Design: Define and enforce best practices around application security, including audit/application logging, configuration, tenant separation, encryption, customer BYOK, RBAC design, API design, and Session/cookie/token management.
  • Identity & Access: Define and implement secure Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) for multi-tenant SaaS products.
  • Code Review: Apply a strong programming background (Python/Go/JavaScript) to perform hands-on code reviews when needed to validate security controls.
  • Maintain the Source of Truth: Define and maintain (document) the authoritative "Source of Truth" for Replit's secure architecture, ensuring these patterns are consistently adopted across all engineering teams.
  • Contribution to Risk Register: Actively identify, document, and quantify architectural security risks. You will be responsible for ensuring these are accurately reflected in the Cybersecurity Risk Register.
  • Security Team Support: Support other security teams like GRC, Pentesting, Vulnerability Management, and PSIRT.
  • Compliance & Documentation: Partner with GRC teams to translate complex architectural designs into clear, audit-ready documentation and control frameworks.

Requirements

  • The ability to see the "big picture" and understand how security decisions impact the entire stack.

Skills

  • 8+ years of experience in product security engineering or architecture, specifically with Multi-tenant SaaS products.
  • Experience with AI Agent-based Saas products is a plus.
  • Expertise in Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) in a multi-tenant SaaS environment.
  • Strong programming background (Python/Go/JavaScript) with proven ability to conduct code review.
  • Experience writing and maintaining Architecture documents.
  • Exceptional ability to communicate technical risk to both engineering and executive audiences.
  • Strong track record of contributing to Cybersecurity Risk Register.

Compensation

  • 💰 Competitive Salary & Equity

Benefits

  • Define the product security vision, ensuring consistency across complex application architecture projects.

Company info

  • Replit Blog https://blog.replit.com/
  • Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
  • Operating Principles https://blog.replit.com/operating-principles
  • Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit
  • GTM & Sales Support: Act as the technical bridge for the Sales team, addressing complex security inquiries from enterprise customers regarding Replit's architectural integrity.

This listing is sourced directly from Replit's careers page and normalized into a canonical job model.