Security Engineer - Vuln Management (Code)

Replit

California (MO)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
Equity
401k Match
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Parental Leave
Flexible PTO
Commuter Benefits
Wellness Stipend
Office Setup Reimbursement
Team Gatherings

Job summary

Replit is seeking a mid-level AppSec Vulnerability Management Engineer to bridge security, compliance, and engineering. You will identify vulnerabilities, manage SBOMs, and drive remediation across CI/CD.

You will serve as a technical responder during incidents and help mature supply chain security across multiple languages. The role requires strong development background and 5 years in AppSec/DevSecOps or similar.

Qualifications

  • 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
  • Development Background: Solid foundational experience working in a software development capacity.
  • Code literacy: read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
  • Build System Expertise: strong familiarity with build systems, package managers, and compilation workflows.
  • AppSec Tooling Expertise: hands-on experience with SAST, SCA, and Secret Scanning tools (Snyk, Socket, Wiz Code, Semgrep, Checkmarx).
  • Compliance Awareness: understanding of vulnerability management in SOC 2, ISO 27001, NIST contexts.

Responsibilities

  • Vulnerability Scanning & Triage: perform periodic application security scanning; prioritize flaws by CVSS, exploitability, and exposure.
  • Compliance-Driven Tracking: track and document vulnerabilities to meet strict SLAs (SOC 2, ISO 27001, PCI-DSS) with audit-ready evidence.
  • Executive Reporting & Alerting: escalate exposures to CISO and leadership; maintain dashboards for risk trends and compliance posture.
  • Software Supply Chain Security: own SBOM inventories; ensure SBOM accuracy and support SLSA maturity.
  • Remediation Collaboration: partner with dev teams to provide mitigation paths and patch code when needed.
  • Tooling Integration: tune automated security testing tools within CI/CD to reduce false positives.
  • Incident Response Support: assist IR teams during breaches with real-time countermeasures.

Skills

AppSec
DevSecOps
Software Engineering
Code Literacy
JavaScript/TypeScript
Python
Go
Build Systems
SAST
SCA
Secret Scanning
Regulatory Compliance

Tools

Snyk
Socket
Wiz Code
Semgrep
Checkmarx

Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem.

What You'll Do
Core Responsibilities

Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.

  • Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
  • Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.
  • Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security.
  • Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
  • Tooling Integration: Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.
  • Incident Response Support: Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.
Required Skills & Experience
  • Experience: 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
  • Development Background: Solid foundational experience working in a software development capacity.
  • Code Literacy: Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
  • Build System Expertise: Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.
  • AppSec Tooling Expertise: Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).
  • Compliance Awareness: Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.
What We Value
  • Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack
  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
  • Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
  • Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:
  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office & US Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
  • Self-driving Company
  • Replit Agent at Scale
  • AI Adoption
  • Build Open-Source Apps
Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vuln Management (Code)
Security Engineer - Vuln Management (Code)

Replit, Inc. • Foster City (CA)

On-site
USD 110,000 - 130,000
Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Insurance
+4
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Product Security Engineer (PSIRT - Product Security Incident Response Team)

Replit • California (MO)

On-site
USD 150,000 - 210,000
Competitive Salary & Equity
401(k) Program with 4% match (US Only)
Health, Dental, Vision and Life Ins.
+9
Security Engineer - Vuln Management (Infra)
Security Engineer - Vuln Management (Infra)

Replit • California (MO)

On-site
USD 150,000 - 190,000
Competitive Salary & Equity
401(k) with 4% match (US)
Health, Dental, Vision and Life
+8
Senior Technical Program Manager, Security Replit Foster City, CA
Senior Technical Program Manager, Security Replit Foster City, CA

Neura Market • Foster City (CA)

Hybrid
USD 140,000 - 180,000
Health Insurance
401(k) Program with match
Paid Parental Leave
+1
Senior Technical Program Manager, Security
Senior Technical Program Manager, Security

Replit • United States

Hybrid
USD 140,000 - 200,000
401(k) Match (US)
Health, Dental, Vision
Parental and Caregiver Leave
+3
Risk and Compliance Lead
Risk and Compliance Lead

Replit • California (MO)

On-site
USD 180,000 - 240,000
401(k) match
Health insurance
Dental insurance
+9
GRC Engineer
GRC Engineer

Replit • California (MO)

On-site
USD 140,000 - 190,000
Competitive salary & equity
Health, dental, vision
Security Engineer - Vuln Management (Infra)
Security Engineer - Vuln Management (Infra)

Replit, Inc. • Foster City (CA)

On-site
USD 120,000 - 150,000
Competitive Salary & Equity
Health, Dental, Vision Insurance
Flexible Time Off (FTO)
+1
Staff Software Engineer, Enterprise Platform
Staff Software Engineer, Enterprise Platform

Replit • California (MO)

On-site
USD 180,000 - 240,000
401(k) match
Health, Dental, Vision
Paid parental leave
+7
Software Engineer, Enterprise Platform
Software Engineer, Enterprise Platform

Replit • California (MO)

On-site
USD 180,000 - 240,000
Health insurance
Dental insurance
Vision insurance
+3