Security Engineer - Vuln Management (Infra)

Replit

California (MO)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary & Equity
401(k) with 4% match (US)
Health, Dental, Vision and Life
Disability insurance
Parental leave
Flexible Time Off
Commuter Benefits
Wellness stipend
In-office setup reimbursement
Quarterly team gatherings
In-office amenities

Job summary

Replit is seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong Cloud Security, DevSecOps, and IaC background. You will bridge security, compliance, DevOps, and Platform teams, identify misconfigurations, and manage vulnerability lifecycles across cloud workloads, containers, and data repositories to meet strict standards.

You will lead scanning, posture management, and remediation efforts, partnering with SRE and Platform teams, and act as an infrastructure

Qualifications

  • 5+ years in Cloud Security, DevSecOps, or Systems Engineering.
  • Experience with multi-cloud environments (GCP, AWS, Azure).
  • Hands-on with CSPM/KSPM/DSPM tools and cloud-native security.
  • Proficient in IaC tooling (Terraform, Pulumi) and CI/CD pipelines.
  • Familiar with container/security (Docker, Kubernetes) and runtime security.

Responsibilities

  • Perform continuous security scanning across cloud posture and workloads.
  • Own CSPM/KSPM/DSPM tooling to ensure uniform compliance and hardened baselines.
  • Integrate IaC security scans into CI/CD pipelines before production deployment.
  • Manage vulnerability lifecycles for containers, VMs, and data repos.
  • Track vulnerabilities to SOC 2, ISO 27001, PCI-DSS with audit-ready evidence.
  • Escalate critical exposures to CISO with dashboards and alerts.
  • Collaborate with SRE/DevOps/Platform to remediate security flaws.

Skills

Cloud security
DevSecOps
IaC security
Multi-cloud
Vulnerability management
Kubernetes security
CI/CD security
Incident response
Security posture management
Linux/VM security

Tools

Wiz
Orca
Prisma Cloud
Lacework
GCP Security Command Center
Terraform
Pulumi
Checkov
Tfsec
KICS
Docker
Kubernetes

Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks. You will also serve as a technical infrastructure responder during security incidents, deploying real-time cloud or network countermeasures to protect our production ecosystem.

What You'll Do
Core Responsibilities

Infrastructure Scanning & Triage: Perform continuous security scanning across our cloud posture and workloads. Review, validate, and prioritize flaws and misconfigurations based on CVSS scores, real-world exploitability, and infrastructure network exposure.

  • Posture Management & Visibility: Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools to ensure uniform compliance, prevent data leakage, and maintain hardened baselines.
  • Infrastructure-as-Code (IaC) Security: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines to identify architectural risks (e.g., overly permissive IAM, public S3 buckets/Cloud Storage) before they are deployed to production.
  • Workload & Container Security: Manage the continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines (VMs), partnering with SRE and Platform teams to build automated base-image patching and rolling upgrade pipelines.
  • Compliance-Driven Tracking: Track, document, and manage infrastructure vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of infrastructure remediation timelines and exception approvals.
  • Executive Reporting & Alerting: Escalate and report critical production exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize infrastructure risk trends and cloud compliance posture.
  • Remediation Collaboration: Partner with SRE, DevOps, and Platform teams to provide clear infrastructure mitigation paths. Assist in writing, reviewing, or modifying cloud configuration templates directly when necessary to resolve security flaws.
  • Incident Response Support: Assist Incident Response teams during active cloud or host-level breaches. Help develop and implement immediate, real-time cloud, network, or IAM configuration countermeasures to contain threats.
Required Skills & Experience
  • Experience: 5 years of experience in Cloud Security, DevSecOps, or Systems Engineering roles.
  • Cloud Infrastructure Depth: Strong foundational experience working with multi-cloud environments (Deep GCP expertise preferred, with working knowledge of AWS or Azure).
  • Posture Management & Scanning Tooling: Hands-on experience operating modern infrastructure security platforms such as Wiz, Orca, Prisma Cloud, Lacework, or cloud-native options (GCP Security Command Center).
  • IaC and Automation Fluency: Strong proficiency with Infrastructure as Code platforms (Terraform, Pulumi) and GitOps deployment workflows. Ability to evaluate and configure IaC scanners like Checkov, Tfsec, or KICS.
  • Containerization & Orchestration: Deep understanding of Docker/container security and Kubernetes architectures (e.g., GKE, EKS), including runtime security, network policies, and workload identity.
  • Compliance Awareness: Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks like SOC 2, ISO 27001, CIS Benchmarks, or NIST.
What We Value
  • Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.
  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
  • Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
  • Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:
  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office & US Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
  • Self-driving Company
  • Replit Agent at Scale
  • AI Adoption
  • Build Open-Source Apps
Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vuln Management (Code)
Security Engineer - Vuln Management (Code)

Replit, Inc. • Foster City (CA)

On-site
USD 110,000 - 130,000
Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Insurance
+4
Security Engineer - Vuln Management (Code)
Security Engineer - Vuln Management (Code)

Replit • California (MO)

On-site
USD 120,000 - 180,000
Competitive Salary
Equity
401k Match
+11
Security Engineer - Vuln Management (Infra)
Security Engineer - Vuln Management (Infra)

Replit, Inc. • Foster City (CA)

On-site
USD 120,000 - 150,000
Competitive Salary & Equity
Health, Dental, Vision Insurance
Flexible Time Off (FTO)
+1
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Product Security Engineer (PSIRT - Product Security Incident Response Team)

Replit • California (MO)

On-site
USD 150,000 - 210,000
Competitive Salary & Equity
401(k) Program with 4% match (US Only)
Health, Dental, Vision and Life Ins.
+9
Senior Technical Program Manager, Security Replit Foster City, CA
Senior Technical Program Manager, Security Replit Foster City, CA

Neura Market • Foster City (CA)

Hybrid
USD 140,000 - 180,000
Health Insurance
401(k) Program with match
Paid Parental Leave
+1
Security Engineer - Vuln Management (Infra)
Security Engineer - Vuln Management (Infra)

jobr.pro • Foster City (CA)

On-site
USD 90,000 - 120,000
Competitive Salary & Equity
401(k) Program with 4% match
Health, Dental, Vision and Life Insurance
+2
Senior Technical Program Manager, Security
Senior Technical Program Manager, Security

Replit • United States

Hybrid
USD 140,000 - 200,000
401(k) Match (US)
Health, Dental, Vision
Parental and Caregiver Leave
+3
Senior Software Engineer, Enterprise Platform
Senior Software Engineer, Enterprise Platform

Replit, Inc. • Foster City (CA)

On-site
USD 120,000 - 160,000
Competitive Salary & Equity
401(k) Program
Health, Dental, Vision and Life Insurance
+9
Software Engineer, Enterprise Platform
Software Engineer, Enterprise Platform

Replit • California (MO)

On-site
USD 180,000 - 240,000
Health insurance
Dental insurance
Vision insurance
+3
Staff Software Engineer, Enterprise Platform
Staff Software Engineer, Enterprise Platform

Replit • California (MO)

On-site
USD 180,000 - 240,000
401(k) match
Health, Dental, Vision
Paid parental leave
+7