Product Security Engineer (PSIRT - Product Security Incident Response Team)

Security Engineer · Senior · Full Time

Foster City, CAUSD 180k – 325k4mo ago
Apply for this role

Opens Replit's application page

Role

What you'll do.

Join Replit's Product Security Incident Response Team (PSIRT) as a Security Engineer to lead vulnerability management for our cloud-native AI platform. This role combines offensive security expertise with incident coordination, requiring deep technical ability to reproduce and validate vulnerabilities across web, cloud, and AI-powered development environments. You'll own the complete vulnerability lifecycle from intake through disclosure, manage bug bounty programs, and drive systematic security improvements while working across Engineering, Cloud Security, and SRE teams.

Responsibilities

  • Vulnerability Intake and Triage Management: Manage comprehensive vulnerability intake from multiple channels including HackerOne bug bounty platform, customer security reports, automated scanners, pentest findings, and coordinated disclosure channels. Independently validate, reproduce, and severity-score security findings using industry-standard methodologies. Maintain a clean and accurate vulnerability records pipeline while identifying and deduplicating reports.
  • Technical Vulnerability Analysis and Assessment: Conduct deep technical analysis of reported vulnerabilities assessing exploitability and business impact. Evaluate findings against OWASP Top 10 classifications, cloud misconfiguration patterns, and identity/authentication/authorization risks including OAuth and OIDC implementations. Document detailed technical assessments and proof-of-concepts for engineering teams.
  • Remediation Coordination and SLA Tracking: Collaborate with Engineering, Cloud Security, SecOps, SRE, and IT teams to confirm product impact and drive timely remediation efforts. Provide detailed reproduction steps, technical analyses, and remediation guidance. Track vulnerability remediation SLAs, monitor regression testing, identify systemic improvements, and ensure compliance with SOC 2 and ISO 27001 evidence requirements.
  • Bug Bounty Program Design and Management: Design, launch, and continuously evolve Replit's bug bounty program including scope definition, rules of engagement, and reward structures. Manage platform selection and private/public program launches. Engage with security researchers, provide clarifications on findings, handle researcher feedback and disputes. Determine reward payouts, bonus decisions, and recognize top contributors to maintain program quality and researcher community health.
  • Coordinated Disclosure and CVE Operations: Lead the coordinated vulnerability disclosure process for both internal discoveries and external researcher findings. Negotiate disclosure timelines with security researchers and technology partners. Coordinate CVE assignment requests and publications through appropriate channels. Prepare customer security advisories, public vulnerability disclosures, and post-remediation communication strategies.
  • Cross-Functional Security Team Collaboration: Work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are remediated quickly and communicated responsibly. Provide engineering teams with actionable technical guidance, proof-of-concepts, and reproduction steps. Support compliance and audit processes by maintaining comprehensive vulnerability governance documentation and evidence trails.

Qualifications

What we look for.

Technical

  • Vulnerability Triage and Validation

    Strong independent ability to triage, validate, and reproduce security vulnerabilities across multiple platforms and architectures. Proficiency in identifying duplicates, assessing severity using industry-standard scoring methodologies, and documenting findings comprehensively for engineering teams.

  • Web, Application, and Cloud Security Vulnerability Classes

    Deep understanding of web application vulnerabilities including OWASP Top 10, cloud platform misconfigurations, SaaS architecture security risks, and identity/access control flaws. Knowledge of common attack vectors affecting cloud-native applications and AI-powered platforms.

  • Authentication and Authorization Expertise

    Strong foundational knowledge of authentication and authorization mechanisms including OAuth 2.0, OpenID Connect (OIDC), identity provider integrations, and common implementation vulnerabilities. Ability to identify and assess authN/Z flaws in cloud-native architectures.

  • Cloud Platform Security (GCP Preferred)

    Hands-on familiarity with cloud platforms, particularly Google Cloud Platform (GCP), including cloud security configuration, identity and access management, network security, and SaaS architecture patterns. Understanding of cloud-specific misconfigurations and attack surfaces.

  • CI/CD and Software Engineering Fundamentals

    Strong understanding of continuous integration and continuous deployment workflows, code repository structures, software development practices, and deployment pipelines. Ability to communicate effectively with engineering teams about vulnerability context and remediation strategies.

  • Bug Bounty Program Operations

    Proven experience running, managing, or triaging security findings for bug bounty programs, ideally on platforms like HackerOne. Understanding of responsible disclosure practices, researcher engagement, vulnerability coordination workflows, and program governance.

Education

  • Computer Science or Related Discipline

    Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field, or equivalent professional experience demonstrating comprehensive security engineering knowledge.

Experience

  • Vulnerability Management and PSIRT Operations

    5+ years of professional experience in security vulnerability assessment, incident response, or product security incident response team (PSIRT) operations. Demonstrated track record managing vulnerability lifecycles from intake through remediation and disclosure.

  • Security Research and Bug Bounty Experience

    3+ years of hands-on experience with bug bounty platforms, vulnerability disclosure programs, security research, or offensive security work including penetration testing engagements.

  • Cloud-Native and SaaS Security

    2+ years of professional experience securing cloud-native applications, SaaS platforms, or multi-tenant systems. Familiarity with cloud architecture patterns, cloud security best practices, and platform-specific security controls.

Skills

Required

  • Vulnerability Analysis and Reproduction

    Expert-level ability to independently analyze security reports, reproduce vulnerabilities reliably, validate severity and exploitability, and create detailed technical documentation for engineering teams.

  • OWASP and Vulnerability Classification

    Comprehensive knowledge of OWASP Top 10, OWASP Testing Guide, and industry-standard vulnerability classification methodologies. Ability to map findings to appropriate categories and severity levels.

  • Identity and Access Control Security

    Deep expertise in authentication and authorization vulnerabilities including OAuth 2.0, OIDC, SAML, API authentication mechanisms, and role-based access control (RBAC) flaws.

  • Bug Bounty Program Management

    Operational experience with bug bounty platforms (HackerOne preferred), researcher communication, program governance, vulnerability triage workflows, and coordinated disclosure processes.

  • Cloud Security Fundamentals

    Strong understanding of cloud platform security including infrastructure-as-code security, cloud identity management, network segmentation, and common cloud misconfiguration patterns.

  • CVE and Disclosure Management

    Experience with CVE assignment processes, responsible disclosure coordination, security advisory preparation, and public vulnerability disclosure workflows.

  • Technical Documentation and Communication

    Excellent ability to write clear technical analyses, reproduction steps, proof-of-concepts, and vulnerability reports that facilitate effective remediation by engineering teams.

Preferred

  • Scripting and Automation

    Nice to have

    Experience with automation scripting using Python, Go, Bash, or similar languages to streamline vulnerability validation, duplicate detection, and data analysis workflows.

  • Penetration Testing Background

    Nice to have

    Hands-on experience conducting penetration testing engagements, security assessments, or offensive security work including red team exercises or vulnerability research.

  • Compliance Framework Knowledge

    Nice to have

    Familiarity with SOC 2 Type II, ISO 27001, or similar compliance frameworks and their requirements for vulnerability management and incident response documentation.

  • Security Advisory Authoring

    Nice to have

    Experience writing public security advisories, CVE writeups, vulnerability disclosures, or technical security blog posts for external audiences.

  • SIEM and Cloud Logging

    Nice to have

    Hands-on experience with Security Information and Event Management (SIEM) systems, cloud logging platforms (e.g., GCP Cloud Logging, Stackdriver), and security investigation tooling.

  • AI and Machine Learning Security

    Nice to have

    Understanding of security considerations specific to AI-powered applications, LLM vulnerabilities, prompt injection attacks, and machine learning platform security.

  • Container and Kubernetes Security

    Nice to have

    Knowledge of containerized application security, Docker security, Kubernetes security models, and supply chain security in cloud-native environments.

Tech stack

Languages

PythonGoBash

Frameworks

OWASP Testing FrameworkOWASP Top 10

Tools

HackerOneCVE Databases and Assignment ServicesVulnerability Scanning ToolsGCP Cloud LoggingSIEM Systems

Other

Google Cloud Platform (GCP)CI/CD Pipelines and DevOps PracticesCoordinated Vulnerability DisclosureSOC 2 and ISO 27001 ComplianceCloud-Native and SaaS Architecture

Compensation

Pay and benefits.

Base·USD 180,000 – 325,000

Equity·Stock options

Benefits

  • Competitive Salary and Equity

    Market-competitive salary package combined with meaningful equity ownership in Replit, aligning your financial success with company growth and long-term value creation.

  • 401(k) Retirement Plan with Employer Match

    Qualified retirement savings plan with 4% employer match (US employees only), supporting your long-term financial planning and retirement security.

  • Comprehensive Health Insurance

    Full medical, dental, and vision insurance coverage, plus life insurance to protect your and your family's health and financial security.

  • Disability Coverage

    Short-term and long-term disability insurance providing income protection in case of unexpected health events or disabilities.

  • Paid Leave Programs

    Generous paid parental leave, medical leave, and caregiver leave supporting work-life balance and family needs. Flexible Time Off (FTO) policy plus paid holidays.

  • Commuter and Wellness Benefits

    Commuter benefits for in-office employees and monthly wellness stipend supporting your physical and mental health investments.

  • Home Office Setup Support

    In-office setup reimbursement for employees in the Foster City, CA office to create a comfortable and productive workspace.

  • Flexible Work Environment

    Autonomous work environment promoting ownership and professional independence. In-office requirements limited to Monday, Wednesday, and Friday (Foster City location).

  • Team Engagement and Amenities

    Quarterly team gatherings for connection and collaboration. In-office amenities including collaborative spaces, wellness facilities, and daily perks for Foster City employees.

Full posting

Original listing.

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure.

This role requires strong technical ability to reproduce vulnerabilities, deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly.

What You’ll Do

Vulnerability Intake, Triage & Validation

  • Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.

  • Independently validate, reproduce, severity-score, and document findings.

  • Identify duplicates and maintain a clean vulnerability records pipeline.

  • Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).

Remediation Coordination & SLA Management

  • Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.

  • Provide detailed reproduction steps, proof-of-concepts, and technical analyses.

  • Track SLAs, remediation progress, regression testing, and systemic improvements.

  • Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.

Bug Bounty & Vulnerability Disclosure Program Management

  • Design and evolve the bug bounty program, including scope, rules, and reward structures.

  • Manage platform selection, private vs. public launches, and community engagement.

  • Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.

  • Determine reward payouts, bonus decisions, and recognition for top contributors.

Coordinated Disclosure & CVE Management

  • Lead the coordinated vulnerability disclosure process for internal and external findings.

  • Negotiate disclosure timelines with researchers and partners.

  • Coordinate CVE assignments and publications, and prepare customer/public advisories.

Required Skills

  • Experience running or triaging for bug bounty programs (HackerOne ideally).

  • Strong ability to triage, validate, and reproduce vulnerabilities independently.

  • Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.

  • Familiarity with cloud platforms (GCP preferred) and SaaS architectures.

  • Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.

Nice to Have

  • Scripting or automation experience (Python, Go, Bash).

  • Pentesting background or exposure to offensive security work.

  • Familiarity with compliance frameworks such as SOC 2 and ISO 27001.

  • Experience authoring public advisories or CVE writeups.

  • Hands-on experience with SIEM, Cloud Logging, and investigative tooling.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:

💰 Competitive Salary & Equity

💹 401(k) Program with a 4% match (US Only)

⚕️ Health, Dental, Vision and Life Insurance

🩼 Short Term and Long Term Disability

🚼 Paid Parental, Medical, Caregiver Leave

🏝 Flexible Time Off (FTO) + Holidays

🚗 Commuter Benefits (In-Office Only)

📱 Monthly Wellness Stipend

🧑‍💻 Autonomous Work Environment

🖥 In Office Set-Up Reimbursement (In-Office Only)

🚀 Quarterly Team Gatherings

☕ In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Redirects to Replit's application page.

Other roles

More at Replit.

View all 29 roles