Engineering Manager, Anti-Abuse & Security
Engineering Manager ยท Manager ยท Full Time
Opens Replit's application page
Role
What you'll do.
Replit is seeking an experienced Engineering Manager to build and lead their Anti-Abuse team from the ground up. This critical role involves developing comprehensive anti-abuse strategies, designing progressive verification systems, and protecting the platform from emerging AI-driven abuse vectors while maintaining a seamless user experience.
Responsibilities
- Anti-Abuse Strategy: Define comprehensive threat model and prioritize abuse vectors including phishing, scam hosting, cryptomining, token farming, and payment fraud
- Verification Infrastructure: Design and implement a progressive 'ladder of trust' system with escalating verification levels and policy engines
- Metrics and Measurement: Establish key anti-abuse metrics such as abuse rate, fraud loss, false positive rate, time-to-detect, and time-to-mitigate
- Team Development: Hire and grow a high-performance team of software engineers and data analysts specializing in anti-abuse technologies
- Cross-Functional Collaboration: Partner with Support, Legal, Security, Infrastructure, and Growth teams to develop comprehensive anti-abuse strategies
Qualifications
What we look for.
Technical
Detection Systems
Experience building detection and enforcement systems including rules engines, ML-based risk scoring, and reputation systems
Identity Verification
Knowledge of KYC, progressive verification systems, and identity signal integration
AI Technologies
Proficiency with AI coding tools and understanding of AI-native abuse vectors
Education
Technical Degree
Bachelor's or Master's degree in Computer Science, Software Engineering, or related technical field preferred
Experience
Management Experience
6-10+ years of engineering experience with 2+ years of team management
Anti-Abuse Domain
Prior experience in trust and safety, fraud prevention, or adversarial engineering domains
Skills
Required
Cross-Functional Communication
Ability to translate technical concepts across different organizational teams
Hands-On Coding
Continued technical skills including code writing, PR reviews, and prototyping
Metrics Design
Capability to define success metrics for complex, ambiguous problems
Preferred
AI Abuse Expertise
Nice to haveExperience with emerging AI-driven abuse mechanisms like prompt injection and token farming
Payment Fraud Knowledge
Nice to haveFamiliarity with payment fraud, card testing, and promotional abuse prevention
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
BaseยทUSD 210,000 โ 275,000
Benefits
Competitive Compensation
Competitive salary with equity compensation package
Retirement Planning
401(k) program with 4% company match for US employees
Healthcare
Comprehensive health, dental, vision, and life insurance coverage
Leave Policies
Paid parental, medical, and caregiver leave
Flexible Work
Flexible Time Off (FTO) policy with additional holidays
Process
Interview steps.
- 01
Initial Screening
Review of resume and initial qualifications
- 02
Technical Phone Screen
Discussion of anti-abuse experience and technical capabilities
- 03
Hiring Manager Interview
Detailed discussion of strategic approach to anti-abuse challenges
- 04
Technical Assessment
Practical evaluation of coding and system design skills
- 05
Team Interview
Meetings with potential team members to assess cultural fit
- 06
Final Leadership Interview
Comprehensive review with senior leadership
Full posting
Original listing.
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We're hiring a hands-on Engineering Manager to build and lead Replit's Anti-Abuse team from the ground up. This is a foundational 0-to-1 role: you'll define the anti-abuse roadmap, hire a small team of engineers and data analysts, and ship the systems that protect Replit's platform, users, and economics from adversarial actors. You'll partner across Support, Legal, Security, Infrastructure, and the Money and Growth teams to make abuse economically unviable while keeping friction low for legitimate users.
Replit sits at the frontier of AI-native abuse. Our platform is a target for phishing and scam hosting, cryptomining, LLM token farming, card and coupon fraud, and increasingly, abuse driven by AI agents themselves. The team you build will define how Replit defends against all of it.
What You'll Do
Build the anti-abuse roadmap from scratch: Define the threat model, prioritize across abuse vectors (phishing/scam hosting, cryptomining, token farming, payment fraud, AI agent exploitation), and translate it into a shipping plan with clear sequencing and tradeoffs.
Design progressive verification and identity infrastructure: Build the "ladder of trust" that gates increasing platform capabilities (referrals, additional credits, access to powerful agent features, Missions) behind escalating verification. This includes a humanity/identity layer that's distinct from user accounts, integrations with KYC-grade verification providers, and the policy engine that decides what level of trust unlocks what behavior. This infrastructure is core not just to promo integrity but to how Replit safely expands agent capabilities over time.
Ship as a hands-on EM: Stay in the code. Use the latest AI coding tools (including Replit Agent) to prototype detections, build internal tooling, and unblock your team. This role is for someone who multiplies their output with AI rather than stepping away from the craft.
Define the metrics that matter: Establish the measurement foundation for anti-abuse at Replit (abuse rate, fraud loss, false positive rate, time-to-detect, time-to-mitigate, verification step-up conversion) and build the data pipelines and dashboards to track them. Figure out what "good" looks like when no one has measured it before.
Hire and grow a small, high-leverage team: Start with a couple of software engineers and data analysts and scale from there. Hire for ownership, adversarial thinking, and AI-native execution. Build a culture where engineers use AI agents as force multipliers and ship fast without cutting corners on quality.
Operate cross-functionally: Partner with Support on abuse escalations and triage workflows, with Legal on compliance and takedown processes, with Security on overlapping threat surfaces, with Infrastructure on detection and enforcement primitives, and with the Money and Growth teams on the fraud-vs-conversion tradeoffs that sit at the heart of this work.
Make abuse economically unviable: Design adaptive friction systems that escalate verification only when risk signals warrant it. The goal isn't elimination; it's making Replit an unprofitable target while keeping the path clear for legitimate users.
What You'll Bring
6 to 10+ years of engineering experience with 2+ years managing teams, ideally in anti-abuse, trust and safety engineering, fraud, or an adjacent adversarial domain.
A hands-on orientation: you still write code, review PRs, and prototype. Comfort using AI coding tools (Claude Code, Cursor, Replit Agent, or similar) as part of your daily workflow.
Experience building detection and enforcement systems at scale: rules engines, ML-based risk scoring, reputation systems, identity and device signals, or similar.
Experience with identity, KYC, or progressive verification systems is a significant plus. You've thought about how to layer trust signals and gate capabilities without wrecking conversion.
Strong product and metrics intuition. You've defined success metrics for ambiguous problems and built the data infrastructure to measure them.
Experience operating cross-functionally with Support, Legal, Security, and Growth teams. Comfort translating between technical detections and business impact.
Crisp written communication and the ability to build clarity in an ambiguous, 0-to-1 environment.
Nice to Have
Experience with AI-native abuse vectors (prompt injection, LLM token farming, agent-driven abuse) or a track record of adapting quickly to novel threat categories.
Familiarity with payment fraud, card testing, coupon abuse, referral abuse, or promotional abuse.
Experience integrating KYC and identity verification providers (Prove, Persona, Socure, Stripe Identity, or similar).
Experience at a consumer platform, developer tool, or cloud provider with meaningful abuse surface area.
Background in security, trust and safety, or fraud prevention at a hypergrowth company.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
๐ฐ Competitive Salary & Equity
๐น 401(k) Program with a 4% match (US Only)
โ๏ธ Health, Dental, Vision and Life Insurance
๐ฉผ Short Term and Long Term Disability
๐ผ Paid Parental, Medical, Caregiver Leave
๐ Flexible Time Off (FTO) + Holidays
๐ Commuter Benefits (In-Office Only)
๐ฑ Monthly Wellness Stipend
๐งโ๐ป Autonomous Work Environment
๐ฅ In Office Set-Up Reimbursement (In-Office Only)
๐ Quarterly Team Gatherings
โ In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
Interviewing + Culture at Replit
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Redirects to Replit's application page.
Other roles
More at Replit.
Forward Deployed Engineer
Senior
Product Engineer, New Products
Senior
Data Scientist, Trust & Safety
Senior
Product Engineer, Product Platform (Frontend)
Senior
Security Engineer - Vuln Management (Infra)
Mid