Replit

About Replit

The coding platform that empowers everyone to learn

🏒 TechπŸ‘₯ 101-200 employeesπŸ“… Founded 2016πŸ“ SoMa, San Francisco, CAπŸ’° $472.2m
B2CB2BArtificial IntelligenceEnterpriseTrainingLearningSaaS

Key Highlights

  • Raised $472.2 million in funding
  • Millions of users, including Google and Facebook employees
  • Supports popular languages like C++, JavaScript, and PHP
  • Remote-first culture with flexible work hours

Replit is a collaborative coding platform that simplifies programming for learners, educators, and developers. Based in SoMa, San Francisco, Replit has attracted millions of users, including employees from major tech companies like Google, Facebook, and Stripe. The company has raised $472.2 million ...

🎁 Benefits

Replit offers a remote-first work environment with flexible hours, equity options, and a home office setup stipend. Employees enjoy comprehensive heal...

🌟 Culture

Replit's culture is centered around accessibility in coding, allowing users to start programming without complex setups. The company values innovation...

Overview

Replit is seeking a Product Security Engineer to lead the vulnerability response program for their cloud-native AI platform. You'll manage security vulnerabilities from intake to remediation, requiring strong technical skills in web and cloud security. This role is based in Foster City, CA.

Job Description

Who you are

You have a strong technical background in security engineering, with experience in managing vulnerability response programs. You understand the lifecycle of security vulnerabilities and have a deep knowledge of web, application, and cloud exploit classes. Your experience includes operating bug bounty and coordinated disclosure programs, and you are familiar with platforms like HackerOne. You are detail-oriented and capable of independently validating and reproducing vulnerabilities, as well as assessing their relevance and exploitability using frameworks like OWASP.

You have a collaborative mindset and enjoy working closely with cross-functional teams, including Engineering, Cloud Security, SecOps, SRE, and IT. You are skilled in managing the intake process from various sources, such as bug bounty platforms, customer reports, and automated scanners. Your ability to document findings and maintain a clean vulnerability records pipeline is crucial to your success in this role.

You are proactive in remediation coordination and SLA management, ensuring that vulnerabilities are addressed quickly and effectively. You have experience assessing identity, authentication, and authorization risks, particularly with protocols like OAuth and OIDC. Your strong communication skills allow you to convey complex security concepts to both technical and non-technical stakeholders.

Desirable

Experience with cloud-native environments and familiarity with security tools and practices in these settings is a plus. You may also have knowledge of security compliance frameworks and best practices, which can enhance your contributions to the team.

What you'll do

In this role, you will lead the vulnerability response program for Replit’s cloud-native AI platform. You will manage the intake of vulnerabilities from various sources, including bug bounty platforms and customer reports, ensuring that each finding is validated and documented accurately. Your responsibilities will include assessing the severity of vulnerabilities and coordinating with engineering and security teams to drive remediation efforts.

You will work closely with the Engineering team to confirm product impact and ensure that vulnerabilities are fixed in a timely manner. Your role will involve maintaining a clean pipeline of vulnerability records and identifying duplicates to streamline the process. You will also be responsible for communicating findings and remediation status to stakeholders, ensuring transparency and accountability throughout the vulnerability management lifecycle.

As part of your duties, you will assess the relevance and exploitability of vulnerabilities using established frameworks and patterns, contributing to the overall security posture of Replit’s products and services. You will collaborate with various teams, including SecOps, SRE, and Cloud Security, to ensure that security practices are integrated into the development lifecycle.

What we offer

Replit is committed to creating an inclusive environment where diverse perspectives are valued. We encourage candidates from all backgrounds to apply, as we believe that a diverse team leads to better products and solutions. You will have the opportunity to work in a dynamic and innovative environment, contributing to a mission that democratizes software development.

We offer competitive compensation and benefits, along with opportunities for professional growth and development. You will be part of a team that is passionate about making programming more accessible and impactful for users around the world. Join us in shaping the future of software creation.

Interested in this role?

Apply now or save it for later. Get alerts for similar jobs at Replit.

✨

Similar Jobs You Might Like

Based on your interests and this role

Chime

Security Engineer

Chimeβ€’πŸ“ San Francisco - On-Site

Chime is seeking an Entry-Level Product Security Engineer to join their Product Security team. You'll contribute to security initiatives, design security controls, and write code for automation. This role requires a builder's mindset and eagerness to learn.

πŸ›οΈ On-SiteEntry-Level
23h ago
Airtable

Security Engineer

Airtableβ€’πŸ“ San Francisco - Remote

Airtable is seeking a Product Security Engineer to enhance the security of their platform as they expand AI offerings. You'll collaborate with engineering teams to develop security frameworks and automated controls. This role requires expertise in security practices and programming languages like Python and Java.

🏠 RemoteMid-Level
3d ago
Delinea

Security Engineer

Delineaβ€’πŸ“ Mexico City

Delinea is hiring a Product Security Engineer to enhance security for human and machine identities. You'll work on a cloud-native Identity Security Platform, focusing on intelligent authorization and threat detection. This role requires expertise in security practices and a passion for innovation.

1 month ago
Aircall

Security Engineer

Aircallβ€’πŸ“ Seattle - On-Site

Aircall is hiring a Security Engineer for Product Security to enhance the security of their products. You'll collaborate with engineering teams to identify risks and improve security practices. This role requires hands-on experience in threat modeling and vulnerability detection.

πŸ›οΈ On-SiteMid-Level
4w ago
WorkOS

Security Engineer

WorkOSβ€’πŸ“ United States - Remote

WorkOS is hiring a Product Security Engineer to define and coordinate security efforts across the company. You'll work with technologies like AWS and implement features such as Single Sign-On and Multi-Factor Auth. This position requires experience in cloud product security and authentication.

🏠 RemoteMid-Level
2 years ago