AppSec Engineer: Vulnerability Management & SBOM

Replit

California (MO)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive Salary
Equity
401k Match
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Parental Leave
Flexible PTO
Commuter Benefits
Wellness Stipend
Office Setup Reimbursement
Team Gatherings

Job summary

Replit is seeking a mid-level AppSec Vulnerability Management Engineer to bridge security, compliance, and engineering. You will identify vulnerabilities, manage SBOMs, and drive remediation across CI/CD.

You will serve as a technical responder during incidents and help mature supply chain security across multiple languages. The role requires strong development background and 5 years in AppSec/DevSecOps or similar.

Qualifications

  • 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
  • Development Background: Solid foundational experience working in a software development capacity.
  • Code literacy: read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
  • Build System Expertise: strong familiarity with build systems, package managers, and compilation workflows.
  • AppSec Tooling Expertise: hands-on experience with SAST, SCA, and Secret Scanning tools (Snyk, Socket, Wiz Code, Semgrep, Checkmarx).
  • Compliance Awareness: understanding of vulnerability management in SOC 2, ISO 27001, NIST contexts.

Responsibilities

  • Vulnerability Scanning & Triage: perform periodic application security scanning; prioritize flaws by CVSS, exploitability, and exposure.
  • Compliance-Driven Tracking: track and document vulnerabilities to meet strict SLAs (SOC 2, ISO 27001, PCI-DSS) with audit-ready evidence.
  • Executive Reporting & Alerting: escalate exposures to CISO and leadership; maintain dashboards for risk trends and compliance posture.
  • Software Supply Chain Security: own SBOM inventories; ensure SBOM accuracy and support SLSA maturity.
  • Remediation Collaboration: partner with dev teams to provide mitigation paths and patch code when needed.
  • Tooling Integration: tune automated security testing tools within CI/CD to reduce false positives.
  • Incident Response Support: assist IR teams during breaches with real-time countermeasures.

Skills

AppSec
DevSecOps
Software Engineering
Code Literacy
JavaScript/TypeScript
Python
Go
Build Systems
SAST
SCA
Secret Scanning
Regulatory Compliance

Tools

Snyk
Socket
Wiz Code
Semgrep
Checkmarx

Job description

Replit is seeking a mid-level AppSec Vulnerability Management Engineer to bridge security, compliance, and engineering. You will identify vulnerabilities, manage SBOMs, and drive remediation across CI/CD.

You will serve as a technical responder during incidents and help mature supply chain security across multiple languages. The role requires strong development background and 5 years in AppSec/DevSecOps or similar.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AppSec Engineer: Vulnerability & SBOM Lead
AppSec Engineer: Vulnerability & SBOM Lead

Replit, Inc. • Foster City (CA)

On-site
USD 110,000 - 130,000
Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Insurance
+4
Cloud Security & Vulnerability Engineer
Cloud Security & Vulnerability Engineer

Replit • California (MO)

On-site
USD 150,000 - 190,000
Competitive Salary & Equity
401(k) with 4% match (US)
Health, Dental, Vision and Life
+8
Security Engineer - Vuln Management (Code)
Security Engineer - Vuln Management (Code)

Replit, Inc. • Foster City (CA)

On-site
USD 110,000 - 130,000
Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Insurance
+4
Security Engineer - Vuln Management (Code)
Security Engineer - Vuln Management (Code)

Replit • California (MO)

On-site
USD 120,000 - 180,000
Competitive Salary
Equity
401k Match
+11
Lead Product Security Engineer – Vulnerability Response
Lead Product Security Engineer – Vulnerability Response

Replit • United States

On-site
USD 120,000 - 170,000
Remote‑First environment
Flexible work hours
Health, dental, vision, life insurance
+8
AppSec Engineer: Secure DevOps & Cloud Defense + Equity
AppSec Engineer: Secure DevOps & Cloud Defense + Equity

Make Choteau Home • Montana

Remote
USD 120,000 - 155,000
Medical, dental, vision coverage
401(k)
Paid time off
+2
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior AppSec Engineer: Vulnerability Mastery
Senior AppSec Engineer: Vulnerability Mastery

Bridge Technologies and Solutions • San Francisco (CA)

On-site
USD 120,000 - 160,000
Senior AppSec Engineer - Vulnerability & Secure Coding
Senior AppSec Engineer - Vulnerability & Secure Coding

Bridge Technologies and Solutions • Cherry Hills Village (CO)

On-site
USD 80,000 - 110,000
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000