Security Engineer - Vuln Management (Infra)
Security Engineer ยท Mid ยท Full Time
Opens Replit's application page
Role
What you'll do.
Replit seeks a mid-level Security Engineer specializing in infrastructure vulnerability management to bridge security, compliance, DevOps, and platform engineering teams. You will manage continuous vulnerability lifecycles across multi-cloud environments, containers, and Kubernetes workloads while ensuring compliance with SOC 2, ISO 27001, and PCI-DSS frameworks. This role requires 5+ years of cloud security and DevSecOps expertise with deep GCP knowledge, hands-on experience with CSPM/KSPM tools, and strong proficiency in Infrastructure-as-Code scanning and container security orchestration.
Responsibilities
- Infrastructure Scanning and Vulnerability Triage: Perform continuous security scanning across cloud posture and workloads using industry-leading tools. Review, validate, and prioritize vulnerabilities and misconfigurations based on CVSS scores, real-world exploitability analysis, and infrastructure network exposure to determine remediation urgency and impact.
- Cloud Security Posture Management: Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools across multi-cloud environments. Maintain uniform compliance baselines, prevent data leakage, and ensure consistent security hardening across all infrastructure resources.
- Infrastructure-as-Code Security Implementation: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines using solutions like Checkov, Tfsec, or KICS. Identify architectural risks including overly permissive IAM policies, public cloud storage buckets, and misconfigurations before production deployment.
- Container and Workload Security Management: Manage continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines. Partner with SRE and Platform teams to design and implement automated base-image patching, rolling upgrade pipelines, and runtime security controls for Kubernetes environments.
- Compliance Tracking and Audit Documentation: Track, document, and manage infrastructure vulnerabilities according to strict compliance SLAs including SOC 2, ISO 27001, and PCI-DSS requirements. Maintain audit-ready evidence of infrastructure remediation timelines, exception approvals, and compliance artifact management.
- Executive Risk Reporting and Dashboard Maintenance: Escalate critical production exposures directly to the CISO and senior leadership with clear risk context and remediation recommendations. Maintain dashboards, alerting mechanisms, and executive reporting that visualize infrastructure risk trends and cloud compliance posture evolution.
- Remediation Collaboration and Technical Guidance: Partner with SRE, DevOps, and Platform teams to provide clear infrastructure mitigation paths and technical solutions. Directly assist in writing, reviewing, and modifying cloud configuration templates, Infrastructure-as-Code, and deployment pipelines to resolve security flaws.
- Incident Response and Threat Containment: Assist Incident Response teams during active cloud or host-level security breaches. Develop and implement immediate, real-time cloud infrastructure, network, and IAM configuration countermeasures to contain threats and limit blast radius during security incidents.
Qualifications
What we look for.
Technical
Multi-Cloud Platform Expertise
Deep hands-on experience with Google Cloud Platform (GCP) as primary platform with working knowledge of AWS or Azure. Proficiency with cloud infrastructure services including Compute Engine, GKE, Cloud Storage, IAM, VPC networking, and cross-cloud security architecture patterns.
Cloud Security Posture Management Tools
Hands-on operational experience with modern CSPM and infrastructure security platforms such as Wiz, Orca Security, Prisma Cloud, Lacework, or native cloud security solutions like GCP Security Command Center, AWS Security Hub, or Azure Security Center.
Infrastructure-as-Code and Scanning
Strong proficiency with Infrastructure-as-Code platforms including Terraform and Pulumi. Ability to evaluate, configure, and integrate IaC security scanning tools like Checkov, Tfsec, and KICS into CI/CD pipelines for automated policy enforcement.
Container and Kubernetes Security
Deep understanding of Docker containerization, container registry security, and Kubernetes architectures including GKE, EKS, and AKS. Knowledge of runtime security, network policies, RBAC, workload identity, pod security policies, and container image vulnerability scanning.
Compliance Framework Mapping
Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks including SOC 2 Type II, ISO 27001, CIS Benchmarks, NIST Cybersecurity Framework, and PCI-DSS requirements specific to cloud infrastructure.
GitOps and CI/CD Pipeline Integration
Experience with GitOps deployment workflows, CI/CD pipeline architecture, and version control systems. Ability to embed security scanning and policy enforcement throughout the deployment lifecycle from code commit through production release.
Education
Bachelor's Degree in Computer Science or Related Field
Computer Science, Cybersecurity, Computer Engineering, Information Systems, or equivalent professional experience demonstrating strong technical foundation in systems and security concepts.
Security Certifications (Preferred)
Relevant certifications such as Certified Kubernetes Administrator (CKA), Google Cloud Professional Cloud Security Engineer, AWS Certified Security - Specialty, or GIAC Security Essentials (GSEC) demonstrate commitment to security expertise.
Experience
Cloud Security Engineering
5+ years of professional experience in Cloud Security, DevSecOps, infrastructure security, or related Systems Engineering roles. Track record of building scalable vulnerability management programs and managing security posture across production cloud environments.
Multi-Cloud Infrastructure Management
Proven experience architecting, deploying, and securing applications across multiple cloud platforms. Hands-on experience managing production workloads, troubleshooting cloud infrastructure issues, and implementing cloud security best practices.
Vulnerability and Risk Management
Demonstrated experience managing vulnerability assessment programs, prioritizing remediation efforts using CVSS scoring and risk analysis, and tracking metrics across large infrastructure environments. Experience with automation of vulnerability scanning and response workflows.
Skills
Required
Cloud Infrastructure Security
Expertise in securing cloud infrastructure including IAM policy design, network segmentation, encryption at rest and in transit, secure API gateway configuration, and cloud-native threat detection and prevention.
Vulnerability Assessment and Prioritization
Proficiency in vulnerability scanning tools, CVSS scoring methodology, vulnerability lifecycle management, and risk-based prioritization to balance security urgency with business impact.
Infrastructure-as-Code Security
Ability to identify security misconfigurations in Terraform, Pulumi, CloudFormation, and Kubernetes manifests. Skilled in implementing policy-as-code, automated compliance checking, and infrastructure template remediation.
Container Security
Knowledge of container image scanning, registry security, runtime threat detection, supply chain security (software bill of materials), and container orchestration platform hardening.
Cloud Native DevSecOps
Experience integrating security controls throughout CI/CD pipelines, implementing shift-left security practices, automating infrastructure testing, and enabling development teams to build secure-by-default applications.
Compliance and Audit
Understanding of security compliance frameworks and ability to map infrastructure controls to compliance requirements, maintain audit evidence, and manage compliance reporting and remediation workflows.
Preferred
Incident Response Experience
Nice to haveExperience responding to security incidents, implementing containment measures, performing forensic analysis, and developing post-incident remediation strategies in cloud environments.
Cloud Cost Optimization Security
Nice to haveKnowledge of how security configuration choices impact cloud infrastructure costs and ability to design cost-efficient security architectures without compromising protection posture.
Network Security and Microsegmentation
Nice to haveUnderstanding of network security principles, VPC architecture, firewall configuration, network policies, and microsegmentation strategies for reducing attack surface in containerized environments.
Custom Automation and Scripting
Nice to haveProficiency in Python, Go, or Bash for building custom security automation, developing custom scanning integrations, and automating infrastructure remediation workflows.
Open Source Security Tools
Nice to haveFamiliarity with open source security and compliance tools including Falco for runtime security, OPA/Conftest for policy enforcement, and community-driven vulnerability databases.
Machine Learning and Anomaly Detection
Nice to haveUnderstanding of how machine learning and behavioral analytics improve threat detection in cloud environments and experience with AI-assisted vulnerability prioritization tools.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
BaseยทUSD 210,000 โ 270,000
EquityยทStock options
Full posting
Original listing.
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks. You will also serve as a technical infrastructure responder during security incidents, deploying real-time cloud or network countermeasures to protect our production ecosystem.
What You'll Do
Core Responsibilities
Infrastructure Scanning & Triage: Perform continuous security scanning across our cloud posture and workloads. Review, validate, and prioritize flaws and misconfigurations based on CVSS scores, real-world exploitability, and infrastructure network exposure.
Posture Management & Visibility: Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools to ensure uniform compliance, prevent data leakage, and maintain hardened baselines.
Infrastructure-as-Code (IaC) Security: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines to identify architectural risks (e.g., overly permissive IAM, public S3 buckets/Cloud Storage) before they are deployed to production.
Workload & Container Security: Manage the continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines (VMs), partnering with SRE and Platform teams to build automated base-image patching and rolling upgrade pipelines.
Compliance-Driven Tracking: Track, document, and manage infrastructure vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of infrastructure remediation timelines and exception approvals.
Executive Reporting & Alerting: Escalate and report critical production exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize infrastructure risk trends and cloud compliance posture.
Remediation Collaboration: Partner with SRE, DevOps, and Platform teams to provide clear infrastructure mitigation paths. Assist in writing, reviewing, or modifying cloud configuration templates directly when necessary to resolve security flaws.
Incident Response Support: Assist Incident Response teams during active cloud or host-level breaches. Help develop and implement immediate, real-time cloud, network, or IAM configuration countermeasures to contain threats.
Required Skills & Experience
Experience: 5 years of experience in Cloud Security, DevSecOps, or Systems Engineering roles.
Cloud Infrastructure Depth: Strong foundational experience working with multi-cloud environments (Deep GCP expertise preferred, with working knowledge of AWS or Azure).
Posture Management & Scanning Tooling: Hands-on experience operating modern infrastructure security platforms such as Wiz, Orca, Prisma Cloud, Lacework, or cloud-native options (GCP Security Command Center).
IaC and Automation Fluency: Strong proficiency with Infrastructure as Code platforms (Terraform, Pulumi) and GitOps deployment workflows. Ability to evaluate and configure IaC scanners like Checkov, Tfsec, or KICS.
Containerization & Orchestration: Deep understanding of Docker/container security and Kubernetes architectures (e.g., GKE, EKS), including runtime security, network policies, and workload identity.
Compliance Awareness: Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks like SOC 2, ISO 27001, CIS Benchmarks, or NIST.
What We Value
Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.
Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
๐ฐ Competitive Salary & Equity
๐น 401(k) Program with a 4% match (US Only)
โ๏ธ Health, Dental, Vision and Life Insurance
๐ฉผ Short Term and Long Term Disability
๐ผ Paid Parental, Medical, Caregiver Leave
๐ Flexible Time Off (FTO) + Holidays
๐ Commuter Benefits (In-Office Only)
๐ฑ Monthly Wellness Stipend
๐งโ๐ป Autonomous Work Environment
๐ฅ In Office Set-Up Reimbursement (In-Office Only)
๐ Quarterly Team Gatherings
โ In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
Interviewing + Culture at Replit
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Redirects to Replit's application page.
Other roles
More at Replit.
Software Engineering Intern (Summer 2027)
Intern
Product Engineer, New Products
Senior
Data Scientist, Trust & Safety
Senior
Product Engineer, Product Platform (Frontend)
Senior
Engineering Manager, Anti-Abuse & Security
Manager