Security Engineer - Vuln Management (Code)

Security Engineer ยท Mid ยท Full Time

Foster City, CAUSD 210k โ€“ 270k3mo ago
Apply for this role

Opens Replit's application page

Role

What you'll do.

Replit seeks a Security Engineer for Vulnerability Management with a strong development background to bridge security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security through SBOM management, drive compliance tracking against SOC 2/ISO 27001/PCI-DSS frameworks, and serve as a technical incident responder. This role requires 5+ years in AppSec/DevSecOps with proficiency in JavaScript/TypeScript, Python, and Go, combined with expertise in SAST/SCA tooling and build system fundamentals.

Responsibilities

  • Vulnerability Scanning and Triage: Conduct periodic application security scanning activities using SAST, SCA, and secret scanning tools. Analyze scan results and prioritize identified vulnerabilities based on CVSS scores, real-world exploitability context, system exposure levels, and business impact to ensure efficient remediation efforts.
  • Compliance-Driven Vulnerability Tracking: Track, document, and manage all discovered vulnerabilities in accordance with strict compliance Service Level Agreements aligned with SOC 2, ISO 27001, and PCI-DSS frameworks. Maintain comprehensive audit-ready evidence of remediation timelines, exception approvals, and compliance sign-offs for regulatory requirements.
  • Executive Security Reporting and Risk Dashboarding: Escalate critical security exposures and high-risk vulnerabilities directly to the Chief Information Security Officer and senior leadership. Develop and maintain real-time security dashboards and alerting mechanisms that visualize vulnerability status, emerging risk trends, and overall security compliance posture.
  • Software Bill of Materials (SBOM) and Supply Chain Security Management: Own the organization's Software Bill of Materials inventory and take full responsibility for maintaining accurate, up-to-date SBOM records. Continuously update dependency inventories to ensure compliance with evolving regulatory requirements. Collaborate on advancing Replit's SLSA maturity levels to strengthen software supply chain security practices.
  • Remediation Collaboration and Code Patching: Work directly with development teams to provide clear, actionable mitigation strategies for identified vulnerabilities. Review security findings in application code, write patches, and implement fixes directly when necessary to resolve security flaws efficiently and reduce overall security debt.
  • AppSec Tooling Integration and CI/CD Pipeline Configuration: Configure, tune, and integrate automated security testing tools within CI/CD pipelines to detect vulnerabilities early in the development lifecycle. Optimize tool configurations to minimize false positives while maintaining comprehensive coverage, enabling engineering teams to work effectively without alert fatigue.
  • Incident Response Support and Rapid Countermeasure Implementation: Provide technical assistance to Incident Response teams during active security breaches or critical incidents. Develop and rapidly implement real-time code and infrastructure countermeasures to contain security threats, minimize exposure, and protect the software ecosystem from further compromise.

Qualifications

What we look for.

Technical

  • Application Security and Vulnerability Management Expertise

    Demonstrate advanced proficiency in identifying, analyzing, and remediating application-layer vulnerabilities. Strong understanding of common vulnerability classes (OWASP Top 10, CWE), vulnerability scoring methodologies (CVSS), and modern attack vectors in web and cloud applications.

  • Multi-Language Code Literacy

    Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go. Comfortable reviewing code for security issues, understanding control flow, identifying injection points, and implementing secure coding fixes across different programming paradigms.

  • SAST, SCA, and Secret Scanning Tools Proficiency

    Hands-on operational experience with industry-leading static application security testing (SAST), software composition analysis (SCA), and secret scanning tools such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx. Ability to configure, customize, and optimize these tools for organizational needs.

  • Build Systems and Package Manager Knowledge

    Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks. Understanding of dependency resolution, transitive dependency risks, supply chain attack surfaces, and tooling like npm, pip, go modules, Maven, and Gradle.

  • Compliance Frameworks and Security Standards Alignment

    Comprehensive understanding of how vulnerability management and remediation requirements map to security compliance frameworks including SOC 2 Type II, ISO 27001, NIST Cybersecurity Framework, PCI-DSS, and other regulatory standards relevant to software security.

Education

  • Bachelor's Degree in Computer Science, Cybersecurity, or Related Field

    Preferred educational foundation in Computer Science, Cybersecurity, Information Security, Computer Engineering, or equivalent practical experience demonstrating deep technical foundation and problem-solving capabilities.

Experience

  • Application Security and DevSecOps Experience

    Minimum 5 years of professional experience in Application Security (AppSec), DevSecOps, or closely related Security Engineering roles. Track record of designing and implementing vulnerability management programs, security testing pipelines, and compliance tracking systems.

  • Software Development Background

    Solid foundational experience working in a software development capacity, whether as a developer, engineer, or technical architect. This background enables effective collaboration with engineering teams and ensures deep understanding of development practices, build processes, and deployment methodologies.

  • Cross-Functional Security Leadership

    Demonstrated ability to drive technical alignment and influence across multiple organizational teams (development, infrastructure, security, compliance) through expertise and collaborative problem-solving rather than direct authority. Experience bridging security and engineering perspectives.

Skills

Required

  • Vulnerability Assessment and Prioritization

    Ability to identify, analyze, and prioritize security vulnerabilities using CVSS scoring, exploitability analysis, and business context. Understanding of vulnerability lifecycle management and remediation tracking.

  • JavaScript/TypeScript Code Analysis

    Proficiency reading and reviewing JavaScript and TypeScript code for security issues. Understanding of Node.js ecosystem, npm dependencies, async patterns, and common web application vulnerabilities in these languages.

  • Python Code Review and Security Analysis

    Ability to review Python code for security flaws, understand pip/poetry dependency management, and identify issues common to Python applications including injection attacks and insecure deserialization.

  • Go Programming Language Security Analysis

    Competency in reading Go code, understanding goroutine safety patterns, memory management, and identifying security issues specific to compiled Go applications and microservices.

  • SAST Tool Expertise

    Hands-on experience configuring and operating Static Application Security Testing (SAST) tools. Ability to analyze findings, tune detection rules, reduce false positives, and integrate SAST into development workflows.

  • SCA and Dependency Risk Management

    Proficiency with Software Composition Analysis (SCA) tools for tracking open-source dependencies, identifying vulnerable components, and managing supply chain risk. Understanding of transitive dependencies and their security implications.

  • Secret Scanning and Credential Management

    Experience implementing and tuning secret scanning tools to detect hardcoded credentials, API keys, and sensitive data in code repositories. Understanding of secure credential management practices in CI/CD environments.

  • CI/CD Pipeline Security Integration

    Ability to configure security tools within continuous integration and continuous deployment pipelines. Experience optimizing security scanning for developer experience and rapid feedback loops.

  • SOC 2 and ISO 27001 Compliance Knowledge

    Understanding of SOC 2 Type II audit requirements, ISO 27001 security controls, and how vulnerability management and remediation requirements map to these frameworks. Knowledge of audit evidence collection and documentation.

  • Software Bill of Materials (SBOM) Management

    Experience creating, maintaining, and updating Software Bill of Materials inventories. Understanding of SBOM standards, formats, and their role in supply chain security and regulatory compliance.

Preferred

  • PCI-DSS Compliance Experience

    Nice to have

    Familiarity with Payment Card Industry Data Security Standard requirements, particularly those related to vulnerability scanning, patching, and secure coding practices in payment-handling systems.

  • SLSA Framework and Supply Chain Security

    Nice to have

    Experience with SLSA (Supply chain Levels for Software Artifacts) framework or similar supply chain security maturity models. Understanding of secure artifact production, provenance, and integrity verification.

  • Snyk Platform Advanced Usage

    Nice to have

    Advanced proficiency with Snyk for dependency vulnerability tracking, container image scanning, and infrastructure-as-code security. Experience with Snyk API integration and custom reporting.

  • Semgrep Custom Rule Development

    Nice to have

    Experience writing custom Semgrep rules for organization-specific vulnerability detection patterns. Ability to extend Semgrep's detection capabilities for proprietary frameworks or custom vulnerabilities.

  • npm and JavaScript Ecosystem Security

    Nice to have

    Deep knowledge of npm supply chain security, lockfile management, monorepo security scanning, and JavaScript framework-specific vulnerabilities. Experience with package provenance verification and typosquatting detection.

  • Python Security Ecosystem

    Nice to have

    Expertise in Python security tooling, pip/poetry security practices, and common vulnerabilities in Python web frameworks like Django and FastAPI. Understanding of Python-specific dependency resolution challenges.

  • Go Microservices and Cloud-Native Security

    Nice to have

    Experience securing Go-based microservices and cloud-native applications. Understanding of container security, Kubernetes security scanning, and vulnerabilities common to modern infrastructure-as-code deployments.

  • Incident Response and Rapid Remediation

    Nice to have

    Background participating in security incident response, including vulnerability triage during active breaches, emergency patching, and implementing real-time countermeasures under time pressure.

  • Security Metrics and Dashboarding

    Nice to have

    Experience developing security metrics, building vulnerability dashboards, and creating executive-level security reporting. Familiarity with tools like Grafana, Tableau, or custom analytics platforms for security visibility.

  • Infrastructure-as-Code Security

    Nice to have

    Knowledge of scanning Infrastructure-as-Code (Terraform, CloudFormation, Kubernetes manifests) for security misconfigurations. Experience with tools like Wiz, Checkov, or similar IaC scanning solutions.

Tech stack

Languages

JavaScript/TypeScriptPythonGo

Frameworks

Node.jsReact

Databases

PostgreSQLRedis

Tools

SnykSemgrepWiz CodeSocket.devCheckmarxGitHub ActionsDocker and Container Scanning

Other

SBOM (Software Bill of Materials) StandardsSLSA FrameworkCVSS Scoring MethodologyBuild Systems and Package Managers

Compensation

Pay and benefits.

BaseยทUSD 210,000 โ€“ 270,000

Full posting

Original listing.

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem.

What You'll Do

Core Responsibilities

  • Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.

  • Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.

  • Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.

  • Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security.

  • Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.

  • Tooling Integration: Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.

  • Incident Response Support: Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.

Required Skills & Experience

  • Experience: 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.

  • Development Background: Solid foundational experience working in a software development capacity.

  • Code Literacy: Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.

  • Build System Expertise: Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.

  • AppSec Tooling Expertise: Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).

  • Compliance Awareness: Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.

What We Value

  • Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.

  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.

  • Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.

  • Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:

๐Ÿ’ฐ Competitive Salary & Equity

๐Ÿ’น 401(k) Program with a 4% match (US Only)

โš•๏ธ Health, Dental, Vision and Life Insurance

๐Ÿฉผ Short Term and Long Term Disability

๐Ÿšผ Paid Parental, Medical, Caregiver Leave

๐Ÿ Flexible Time Off (FTO) + Holidays

๐Ÿš— Commuter Benefits (In-Office Only)

๐Ÿ“ฑ Monthly Wellness Stipend

๐Ÿง‘โ€๐Ÿ’ป Autonomous Work Environment

๐Ÿ–ฅ In Office Set-Up Reimbursement (In-Office Only)

๐Ÿš€ Quarterly Team Gatherings

โ˜• In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Redirects to Replit's application page.

Other roles

More at Replit.

View all 29 roles