Security Engineer - Vuln Management (Infra)

Security Engineer ยท Mid ยท Full Time

Foster City, CAUSD 210k โ€“ 270k2mo ago
Apply for this role

Opens Replit's application page

Role

What you'll do.

Replit seeks a mid-level Security Engineer specializing in infrastructure vulnerability management to bridge security, compliance, DevOps, and platform engineering teams. You will manage continuous vulnerability lifecycles across multi-cloud environments, containers, and Kubernetes workloads while ensuring compliance with SOC 2, ISO 27001, and PCI-DSS frameworks. This role requires 5+ years of cloud security and DevSecOps expertise with deep GCP knowledge, hands-on experience with CSPM/KSPM tools, and strong proficiency in Infrastructure-as-Code scanning and container security orchestration.

Responsibilities

  • Infrastructure Scanning and Vulnerability Triage: Perform continuous security scanning across cloud posture and workloads using industry-leading tools. Review, validate, and prioritize vulnerabilities and misconfigurations based on CVSS scores, real-world exploitability analysis, and infrastructure network exposure to determine remediation urgency and impact.
  • Cloud Security Posture Management: Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools across multi-cloud environments. Maintain uniform compliance baselines, prevent data leakage, and ensure consistent security hardening across all infrastructure resources.
  • Infrastructure-as-Code Security Implementation: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines using solutions like Checkov, Tfsec, or KICS. Identify architectural risks including overly permissive IAM policies, public cloud storage buckets, and misconfigurations before production deployment.
  • Container and Workload Security Management: Manage continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines. Partner with SRE and Platform teams to design and implement automated base-image patching, rolling upgrade pipelines, and runtime security controls for Kubernetes environments.
  • Compliance Tracking and Audit Documentation: Track, document, and manage infrastructure vulnerabilities according to strict compliance SLAs including SOC 2, ISO 27001, and PCI-DSS requirements. Maintain audit-ready evidence of infrastructure remediation timelines, exception approvals, and compliance artifact management.
  • Executive Risk Reporting and Dashboard Maintenance: Escalate critical production exposures directly to the CISO and senior leadership with clear risk context and remediation recommendations. Maintain dashboards, alerting mechanisms, and executive reporting that visualize infrastructure risk trends and cloud compliance posture evolution.
  • Remediation Collaboration and Technical Guidance: Partner with SRE, DevOps, and Platform teams to provide clear infrastructure mitigation paths and technical solutions. Directly assist in writing, reviewing, and modifying cloud configuration templates, Infrastructure-as-Code, and deployment pipelines to resolve security flaws.
  • Incident Response and Threat Containment: Assist Incident Response teams during active cloud or host-level security breaches. Develop and implement immediate, real-time cloud infrastructure, network, and IAM configuration countermeasures to contain threats and limit blast radius during security incidents.

Qualifications

What we look for.

Technical

  • Multi-Cloud Platform Expertise

    Deep hands-on experience with Google Cloud Platform (GCP) as primary platform with working knowledge of AWS or Azure. Proficiency with cloud infrastructure services including Compute Engine, GKE, Cloud Storage, IAM, VPC networking, and cross-cloud security architecture patterns.

  • Cloud Security Posture Management Tools

    Hands-on operational experience with modern CSPM and infrastructure security platforms such as Wiz, Orca Security, Prisma Cloud, Lacework, or native cloud security solutions like GCP Security Command Center, AWS Security Hub, or Azure Security Center.

  • Infrastructure-as-Code and Scanning

    Strong proficiency with Infrastructure-as-Code platforms including Terraform and Pulumi. Ability to evaluate, configure, and integrate IaC security scanning tools like Checkov, Tfsec, and KICS into CI/CD pipelines for automated policy enforcement.

  • Container and Kubernetes Security

    Deep understanding of Docker containerization, container registry security, and Kubernetes architectures including GKE, EKS, and AKS. Knowledge of runtime security, network policies, RBAC, workload identity, pod security policies, and container image vulnerability scanning.

  • Compliance Framework Mapping

    Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks including SOC 2 Type II, ISO 27001, CIS Benchmarks, NIST Cybersecurity Framework, and PCI-DSS requirements specific to cloud infrastructure.

  • GitOps and CI/CD Pipeline Integration

    Experience with GitOps deployment workflows, CI/CD pipeline architecture, and version control systems. Ability to embed security scanning and policy enforcement throughout the deployment lifecycle from code commit through production release.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Computer Science, Cybersecurity, Computer Engineering, Information Systems, or equivalent professional experience demonstrating strong technical foundation in systems and security concepts.

  • Security Certifications (Preferred)

    Relevant certifications such as Certified Kubernetes Administrator (CKA), Google Cloud Professional Cloud Security Engineer, AWS Certified Security - Specialty, or GIAC Security Essentials (GSEC) demonstrate commitment to security expertise.

Experience

  • Cloud Security Engineering

    5+ years of professional experience in Cloud Security, DevSecOps, infrastructure security, or related Systems Engineering roles. Track record of building scalable vulnerability management programs and managing security posture across production cloud environments.

  • Multi-Cloud Infrastructure Management

    Proven experience architecting, deploying, and securing applications across multiple cloud platforms. Hands-on experience managing production workloads, troubleshooting cloud infrastructure issues, and implementing cloud security best practices.

  • Vulnerability and Risk Management

    Demonstrated experience managing vulnerability assessment programs, prioritizing remediation efforts using CVSS scoring and risk analysis, and tracking metrics across large infrastructure environments. Experience with automation of vulnerability scanning and response workflows.

Skills

Required

  • Cloud Infrastructure Security

    Expertise in securing cloud infrastructure including IAM policy design, network segmentation, encryption at rest and in transit, secure API gateway configuration, and cloud-native threat detection and prevention.

  • Vulnerability Assessment and Prioritization

    Proficiency in vulnerability scanning tools, CVSS scoring methodology, vulnerability lifecycle management, and risk-based prioritization to balance security urgency with business impact.

  • Infrastructure-as-Code Security

    Ability to identify security misconfigurations in Terraform, Pulumi, CloudFormation, and Kubernetes manifests. Skilled in implementing policy-as-code, automated compliance checking, and infrastructure template remediation.

  • Container Security

    Knowledge of container image scanning, registry security, runtime threat detection, supply chain security (software bill of materials), and container orchestration platform hardening.

  • Cloud Native DevSecOps

    Experience integrating security controls throughout CI/CD pipelines, implementing shift-left security practices, automating infrastructure testing, and enabling development teams to build secure-by-default applications.

  • Compliance and Audit

    Understanding of security compliance frameworks and ability to map infrastructure controls to compliance requirements, maintain audit evidence, and manage compliance reporting and remediation workflows.

Preferred

  • Incident Response Experience

    Nice to have

    Experience responding to security incidents, implementing containment measures, performing forensic analysis, and developing post-incident remediation strategies in cloud environments.

  • Cloud Cost Optimization Security

    Nice to have

    Knowledge of how security configuration choices impact cloud infrastructure costs and ability to design cost-efficient security architectures without compromising protection posture.

  • Network Security and Microsegmentation

    Nice to have

    Understanding of network security principles, VPC architecture, firewall configuration, network policies, and microsegmentation strategies for reducing attack surface in containerized environments.

  • Custom Automation and Scripting

    Nice to have

    Proficiency in Python, Go, or Bash for building custom security automation, developing custom scanning integrations, and automating infrastructure remediation workflows.

  • Open Source Security Tools

    Nice to have

    Familiarity with open source security and compliance tools including Falco for runtime security, OPA/Conftest for policy enforcement, and community-driven vulnerability databases.

  • Machine Learning and Anomaly Detection

    Nice to have

    Understanding of how machine learning and behavioral analytics improve threat detection in cloud environments and experience with AI-assisted vulnerability prioritization tools.

Tech stack

Languages

PythonGoBash/Shell ScriptingHCL (HashiCorp Configuration Language)

Frameworks

TerraformKubernetesPulumiDocker

Databases

Cloud-Native Data Services

Tools

WizPrisma CloudLaceworkGCP Security Command CenterCheckovTfsecKICS (Keeping Infrastructure as Code Secure)ArgoCD or FluxGitHub/GitLab CI/CD

Other

Cloud CLI ToolsCVSS Scoring and Vulnerability DatabasesCompliance Framework StandardsInfrastructure Logging and MonitoringNetwork and IAM Security

Compensation

Pay and benefits.

BaseยทUSD 210,000 โ€“ 270,000

EquityยทStock options

Full posting

Original listing.

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks. You will also serve as a technical infrastructure responder during security incidents, deploying real-time cloud or network countermeasures to protect our production ecosystem.

What You'll Do

Core Responsibilities

  • Infrastructure Scanning & Triage: Perform continuous security scanning across our cloud posture and workloads. Review, validate, and prioritize flaws and misconfigurations based on CVSS scores, real-world exploitability, and infrastructure network exposure.

  • Posture Management & Visibility: Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools to ensure uniform compliance, prevent data leakage, and maintain hardened baselines.

  • Infrastructure-as-Code (IaC) Security: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines to identify architectural risks (e.g., overly permissive IAM, public S3 buckets/Cloud Storage) before they are deployed to production.

  • Workload & Container Security: Manage the continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines (VMs), partnering with SRE and Platform teams to build automated base-image patching and rolling upgrade pipelines.

  • Compliance-Driven Tracking: Track, document, and manage infrastructure vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of infrastructure remediation timelines and exception approvals.

  • Executive Reporting & Alerting: Escalate and report critical production exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize infrastructure risk trends and cloud compliance posture.

  • Remediation Collaboration: Partner with SRE, DevOps, and Platform teams to provide clear infrastructure mitigation paths. Assist in writing, reviewing, or modifying cloud configuration templates directly when necessary to resolve security flaws.

  • Incident Response Support: Assist Incident Response teams during active cloud or host-level breaches. Help develop and implement immediate, real-time cloud, network, or IAM configuration countermeasures to contain threats.

Required Skills & Experience

  • Experience: 5 years of experience in Cloud Security, DevSecOps, or Systems Engineering roles.

  • Cloud Infrastructure Depth: Strong foundational experience working with multi-cloud environments (Deep GCP expertise preferred, with working knowledge of AWS or Azure).

  • Posture Management & Scanning Tooling: Hands-on experience operating modern infrastructure security platforms such as Wiz, Orca, Prisma Cloud, Lacework, or cloud-native options (GCP Security Command Center).

  • IaC and Automation Fluency: Strong proficiency with Infrastructure as Code platforms (Terraform, Pulumi) and GitOps deployment workflows. Ability to evaluate and configure IaC scanners like Checkov, Tfsec, or KICS.

  • Containerization & Orchestration: Deep understanding of Docker/container security and Kubernetes architectures (e.g., GKE, EKS), including runtime security, network policies, and workload identity.

  • Compliance Awareness: Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks like SOC 2, ISO 27001, CIS Benchmarks, or NIST.

What We Value

  • Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.

  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.

  • Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.

  • Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:

๐Ÿ’ฐ Competitive Salary & Equity

๐Ÿ’น 401(k) Program with a 4% match (US Only)

โš•๏ธ Health, Dental, Vision and Life Insurance

๐Ÿฉผ Short Term and Long Term Disability

๐Ÿšผ Paid Parental, Medical, Caregiver Leave

๐Ÿ Flexible Time Off (FTO) + Holidays

๐Ÿš— Commuter Benefits (In-Office Only)

๐Ÿ“ฑ Monthly Wellness Stipend

๐Ÿง‘โ€๐Ÿ’ป Autonomous Work Environment

๐Ÿ–ฅ In Office Set-Up Reimbursement (In-Office Only)

๐Ÿš€ Quarterly Team Gatherings

โ˜• In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Redirects to Replit's application page.

Other roles

More at Replit.

View all 29 roles