Security Engineer - Incident Response

Replit

United States

A distancia

USD 130.000 - 180.000

Jornada completa

Hace 5 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico — crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Replit is seeking a Security Engineer with deep incident response experience to defend our cloud-native platform. You’ll lead investigations from first signal to root cause, coordinate containment across Security, SRE, and Engineering, and inform stakeholders as incidents unfold.

You’ll build scripts and tooling to speed triage, evidence collection, and containment, and turn findings into stronger detections, playbooks, and platform hardening for future incidents.

Formación

  • Proven experience leading or serving as technical lead on security incidents in a cloud or SaaS environment.
  • Strong hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis.

Responsabilidades

  • Incident Response: Serve as incident commander or technical lead for security incidents, from detection and triage through containment, eradication, recovery, and post-incident review.
  • Coordinate response across Security, SRE, Engineering, Legal, and leadership. Drive decisions under pressure and keep a clear record of actions taken.
  • Communicate incident status, impact, and risk clearly to technical and executive audiences.
  • Participate in and help shape the security on-call rotation.
  • Investigation Forensics: Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, Cloud Logging, telemetry, and host and container artifacts.
  • Determine scope, root cause, attacker behavior, and blast radius for confirmed incidents.
  • Quickly assess whether emerging threats (0-days, active exploitation campaigns, bug bounty findings, customer reports) apply to Replit, and whether we're already affected.
  • IR Automation Tooling: Build scripts, automations, and tools (Python, Go, Bash, or directly on Replit) that speed up response, such as automated enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage.
  • Develop and maintain response playbooks and runbooks, and automate them where possible.
  • Integrate response workflows with SIEM, SOAR, ticketing, and chat tooling to cut time-to-contain.
  • Detection Continuous Improvement: Turn incident findings into new or improved detections, logging coverage, and visibility.
  • Lead blameless post-incident reviews and drive remediation items to completion.
  • Run tabletop exercises and simulations to test readiness and find gaps.

Conocimientos

Incident response leadership
SIEM analysis
Cloud security SaaS

Descripción del empleo

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We're looking for a Security Engineer with deep incident response experience to help defend Replit, a fast-moving, cloud-native AI vibe-coding platform. You'll be the person who takes charge when something goes wrong. You'll lead investigations from first signal to root cause, coordinate containment across Security, SRE, and Engineering, and keep stakeholders informed while the incident is moving fast.This isn't a pure responder role. We want a well-rounded security engineer who has run real incidents and wants to make the next one faster. You'll write the scripts, automations, and tooling that take manual work out of triage, evidence collection, and containment. You'll also turn lessons from each incident into better detections, playbooks, and platform hardening.

Responsibilities
  • Incident Response: Serve as incident commander or technical lead for security incidents, from detection and triage through containment, eradication, recovery, and post-incident review.
  • Coordinate response across Security, SRE, Engineering, Legal, and leadership. Drive decisions under pressure and keep a clear record of actions taken.
  • Communicate incident status, impact, and risk clearly to technical and executive audiences.
  • Participate in and help shape the security on-call rotation.
Investigation Forensics
  • Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, Cloud Logging, telemetry, and host and container artifacts.
  • Determine scope, root cause, attacker behavior, and blast radius for confirmed incidents.
  • Quickly assess whether emerging threats (0-days, active exploitation campaigns, bug bounty findings, customer reports) apply to Replit, and whether we're already affected.
IR Automation Tooling
  • Build scripts, automations, and tools (Python, Go, Bash, or directly on Replit) that speed up response, such as automated enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage.
  • Develop and maintain response playbooks and runbooks, and automate them where possible.
  • Integrate response workflows with SIEM, SOAR, ticketing, and chat tooling to cut time-to-contain.
Detection Continuous Improvement
  • Turn incident findings into new or improved detections, logging coverage, and visibility.
  • Lead blameless post-incident reviews and drive remediation items to completion.
  • Run tabletop exercises and simulations to test readiness and find gaps.
Required Skills Experience
  • Proven experience leading or serving as technical lead on security incidents in a cloud or SaaS environment.
  • Strong hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis. Comfortable working through large datasets under time pre
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Incident-Response Security Engineer: Lead & Automate IR
Incident-Response Security Engineer: Lead & Automate IR

Replit • EE. UU.

A distancia
USD 130.000 - 180.000
Incident Response Security Engineer — IR Automation
Incident Response Security Engineer — IR Automation

Replit • Foster City (CA)

Presencial
USD 170.000 - 250.000
Salary & equity
401(k) match
Health insurance
+6
Security Engineer - Incident Response
Security Engineer - Incident Response

Replit • Foster City (CA)

Presencial
USD 170.000 - 250.000
Salary & equity
401(k) match
Health insurance
+6
Security Engineer, Incident Response
Security Engineer, Incident Response

Meta • Menlo Park (CA)

Presencial
USD 180.000 - 280.000
Senior Security Operations Engineer
Senior Security Operations Engineer

samsara • EE. UU.

A distancia
USD 140.000 - 190.000
Remote work within the United States
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Híbrido
USD 110.000 - 170.000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

Presencial
USD 120.000 - 180.000
Security Engineer
Security Engineer

Atlas Search • New York (NY)

Presencial
USD 140.000 - 190.000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • EE. UU.

Híbrido
USD 120.000 - 170.000
Senior Incident Response Security Engineer - Escalations
Senior Incident Response Security Engineer - Escalations

Intuit • Charlotte (NC)

Presencial
USD 140.000 - 190.000
Cash bonus
Equity rewards
Benefits