4 open positions available
Design and operate authorization interfaces and security token services to protect platform interactions and partner with teams to evolve access controls. | Experience shipping and operating security-sensitive backend or distributed systems with deep knowledge of authentication and authorization protocols and fluency in at least one backend stack. | Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Team Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly. Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services. Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls. We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here. About the Role As a Software Engineer, you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity. The work is guided by a few simple questions: Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf? Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services? Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions? Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials? Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them? What you'll do Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives Research and develop new innovative approaches to Authx in the Agentic world Areas you might work in Authorization policy: evolve Replit's central policy decision point and migrate fragmented authorization checks to its typed contract. Agent delegation: extend the current delegation foundation so the user is the subject and Agent is the authenticated actor, with continuous validation and dynamic permission envelopes as work runs. Enterprise access control: evolve roles, groups, workspace policy, and app-level grants for both simple collaboration and complex organizations. Agent and service identity and reliability: operate the token and workload-identity systems that protect service-to-service traffic. Required skills and experience Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability Depth in authentication, authorization, or identity systems, such as OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines. You do not need prior experience with every item Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling Experience migrating security-sensitive systems without breaking callers. Approaches can include typed contracts, shadow evaluation, and staged enforcement Fluent in at least one production backend stack. Our systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate Able to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability If you're excited about this role but don't meet every requirement, we still encourage you to apply. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program with a 4% match (US Only) ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🏝 Flexible Time Off (FTO) + Holidays 🚗 Commuter Benefits (In-Office & US Only) 📱 Monthly Wellness Stipend 🧑💻 Autonomous Work Environment 🖥 In Office Set-Up Reimbursement (In-Office Only) 🚀 Quarterly Team Gatherings ☕ In Office Amenities (In-Office Only) Want to learn more about what we are up to? Self-driving Company Replit Agent at Scale AI Adoption Build Open-Source Apps Interviewing + Culture at Replit Operating Principles Reasons not to work at Replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Lead and manage enterprise-level information security and compliance programs with team leadership and cross-functional coordination. | Over 10 years of cybersecurity leadership experience including compliance management and security program development but no explicit vulnerability management or GCP bug bounty experience. | Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role: We are seeking a Senior Technical Program Manager to own our vulnerability management program end to end. In this role, you will drive vulnerability intake, triage, remediation, and reporting across our bug bounty program, our Google Cloud Platform (GCP) infrastructure, source code hosted on GitHub, and a broad portfolio of third-party SaaS services. You will partner closely with platform engineering, product engineering, SRE, security, IT, legal, and vendor management to make sure vulnerabilities are found fast, triaged accurately, and closed within SLA — and that leadership always has a clear, current picture of the organization's risk posture.The ideal candidate uses AI and automation aggressively to scale themselves, but understands that the core value is clarity, tradeoffs, and execution, not just tooling. What you'll do: Program Ownership: Own and continuously improve the vulnerability management program, including intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types. Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends. Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure — IAM, networking, Compute/GKE, storage, and logging/monitoring configuration — by partnering with security, cloud, and platform engineering teams. Code & Supply Chain Security: Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling (Wiz Code, Snyk, Dependabot, code scanning, secret scanning) across engineering repos, including dependency and supply-chain risk. SaaS Vendor Risk: Build and manage the process for assessing and tracking security posture across third-party SaaS applications. Escalation & Exceptions: Define and enforce escalation paths for overdue or critical/high-severity findings, including risk acceptance and exception processes with appropriate sign-off. Cross-Team Accountability: Partner with engineering managers and tech leads to embed remediation work into sprint planning and hold teams accountable to remediation SLAs. Reporting & Alerting: Establish and maintain a single source of truth for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for engineering leadership, security leadership, and executives. Audit & Compliance Support: Support audit and compliance efforts (SOC 2, ISO 27001, customer security questionnaires) by keeping vulnerability management evidence and metrics audit-ready. Process & Automation: Drive process improvements and automation to reduce manual triage effort and improve time-to-remediation across all vulnerability sources. Required Skill & Experience: Experience: 4–6+ years of experience in technical program management, security program management, or security operations, with direct ownership of a vulnerability management or application security program. Bug Bounty Expertise: Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows. Cloud Security Knowledge (GCP): Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks. Code Security Familiarity: Familiarity with GitHub-based development workflows and code security tooling (Wiz Code, Dependabot, SAST/DAST/SCA tools such as Snyk, Semgrep, or CodeQL). Risk Prioritization: Strong grasp of vulnerability scoring frameworks (CVSS) and risk-based prioritization. Communication: Excellent cross-functional communication skills — able to translate technical vulnerability data into business risk for executive audiences and hold engineering teams accountable without owning the code themselves. Reporting Tools: Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) that give leadership real-time visibility into program health. Compliance Awareness: Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP. What we value: Systems Thinking: The ability to see the “big picture” and understand how vulnerability management decisions impact the entire stack — cloud, code, and vendor ecosystem alike. Technical Influence: The ability to drive alignment across engineering and security through expertise and collaboration rather than direct authority. Autonomy: Comfortable owning a program end to end and driving outcomes with minimal oversight. Bias for Action: A track record of closing the gap between finding a vulnerability and actually getting it fixed. This is a full-time role that can be held from our Foster City, CA office. The hybrid role has an in-office requirement of Monday, Wednesday, and Friday. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program with a 4% match (US Only) ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🏝 Flexible Time Off (FTO) + Holidays 🚗 Commuter Benefits (In-Office Only) 📱 Monthly Wellness Stipend 🧑💻 Autonomous Work Environment 🖥 In Office Set-Up Reimbursement (In-Office Only) 🚀 Quarterly Team Gatherings ☕ In Office Amenities (In-Office Only) Want to learn more about what we are up to? Meet the Replit Agent Replit: Make an app for that Replit Blog Amjad TED Talk Interviewing + Culture at Replit Operating Principles Reasons not to work at Replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Lead and scale a global 24/7 SOC function focusing on detection, triage, and response across multi-cloud and AI-driven environments. | 7+ years in Security Operations with 3+ years leadership and expertise in GCP, SIEM, and cloud-native detection engineering. | Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. We are looking for a Security Operations Lead (SOC Lead) to build, mature, and operate our 24/7 detection and response capabilities across a modern cloud-native and AI-driven environment. This role leads the global SOC function—monitoring, SIEM ownership, detection engineering, alert triage, and operational readiness—while also evaluating and integrating emerging AI-based SOC products and autonomous response platforms. You will oversee monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads. You’ll collaborate closely with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure to ensure our detection strategy scales and stays ahead of evolving threats. This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting. What You’ll Do SOC Leadership & 24/7 Monitoring Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation. Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments. Cover monitoring across: Cloud infrastructure (GCP, AWS, Azure) Kubernetes/GKE/EKS/AKS clusters SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.) Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry Developer platforms + CI/CD pipelines AI/ML systems and model-serving workflows AI-Based SOC Integration & Innovation Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation Identify opportunities to automate triage, investigations, enrichment, and reporting. Serve as the internal expert on the capabilities and limitations of AI-based SOC tooling. SIEM & Telemetry Ownership Own the entire SIEM ecosystem—ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics. Expand telemetry across: Cloud logs, API logs, system events SaaS audit logs and admin events Identity providers (Okta, Google, Azure AD) Endpoint EDR/XDR event streams Standardize data schemas and improve detection signal quality across sources. Detection Engineering Develop high-fidelity detections for: Cloud-native attacks Identity threats and lateral movement SaaS misconfigurations and privilege abuse Endpoint malware/behavior anomalies Insider threats and account takeover patterns Use MITRE ATT&CK, MITRE Cloud Matrix, and threat intel to drive detection coverage. Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases. Triage, Threat Analysis & Escalation Lead day-to-day triage and threat analysis activities, ensuring accurate categorization and prioritization. Drive complex investigations involving correlated events across cloud, SaaS, endpoints, and developer platforms. Guide root cause analysis and work with owners to drive remediation and architectural improvements. Continuously refine logic, reduce false positives, and improve signal quality. Cross-Functional Collaboration Partner with Cloud Security on cloud posture and preventative controls. Work with Compliance/GRC to support SOC 2, ISO 27001, and audit readiness. Collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks. Coordinate with IT / Endpoint teams to ensure full endpoint telemetry and EDR response readiness. Communicate threats, gaps, and trends to leadership and engineering stakeholders. Required Skills & Experience 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity. Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP). Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.). Deep understanding of: Cloud security monitoring (GCP required; AWS/Azure preferred) SaaS security monitoring (Okta, Google Workspace, GitHub, Slack, etc.) Endpoint security telemetry (EDR/XDR tools such as CrowdStrike, SentinelOne, or Defender) Kubernetes and container detection Hands-on detection engineering skills, event correlation, threat hunting, and log analysis. Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools. Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns. Experience with SOAR and scripting (Python, Go, Bash). Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management. Preferred Qualifications Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems. Previous experience at a high-growth tech company. Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.). What We Value Operational excellence: Building reliable, scalable SOC systems. Analytical rigor: Capable of making sense of large, complex, multi-source telemetry. Leadership: Mentorship and guidance of analysts and engineers. Adaptability: Comfortable evaluating and integrating next-gen AI-based SOC tools. Clear communication: Able to articulate risk, incidents, and recommendations to both technical and executive audiences. Automation mindset: Focused on reducing manual toil via SOAR, scripting, and AI augmentation. Curiosity: Passion for learning, experimenting, and staying ahead of evolving threats—especially those targeting cloud-native and AI systems. This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program with a 4% match (US Only) ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🏝 Flexible Time Off (FTO) + Holidays 🚗 Commuter Benefits (In-Office Only) 📱 Monthly Wellness Stipend 🧑💻 Autonomous Work Environment 🖥 In Office Set-Up Reimbursement (In-Office Only) 🚀 Quarterly Team Gatherings ☕ In Office Amenities (In-Office Only) Want to learn more about what we are up to? Meet the Replit Agent Replit: Make an app for that Replit Blog Amjad TED Talk Interviewing + Culture at Replit Operating Principles Reasons not to work at Replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Lead and mature a global 24/7 SOC function with detection engineering, AI integration, and cross-functional collaboration. | 7+ years in security operations with 3+ years in senior roles, strong SIEM and cloud security experience, hands-on detection engineering, and familiarity with AI-based SOC tools. | Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. We are looking for a Security Operations Lead (SOC Lead) to build, mature, and operate our 24/7 detection and response capabilities across a modern cloud-native and AI-driven environment. This role leads the global SOC function—monitoring, SIEM ownership, detection engineering, alert triage, and operational readiness—while also evaluating and integrating emerging AI-based SOC products and autonomous response platforms. You will oversee monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads. You’ll collaborate closely with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure to ensure our detection strategy scales and stays ahead of evolving threats. This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting. What You’ll Do SOC Leadership & 24/7 Monitoring • Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation. • Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments. • Cover monitoring across: • Cloud infrastructure (GCP, AWS, Azure) • Kubernetes/GKE/EKS/AKS clusters • SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.) • Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry • Developer platforms + CI/CD pipelines • AI/ML systems and model-serving workflows AI-Based SOC Integration & Innovation • Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation • Identify opportunities to automate triage, investigations, enrichment, and reporting. • Serve as the internal expert on the capabilities and limitations of AI-based SOC tooling. SIEM & Telemetry Ownership • Own the entire SIEM ecosystem—ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics. • Expand telemetry across: • Cloud logs, API logs, system events • SaaS audit logs and admin events • Identity providers (Okta, Google, Azure AD) • Endpoint EDR/XDR event streams • Standardize data schemas and improve detection signal quality across sources. Detection Engineering • Develop high-fidelity detections for: • Cloud-native attacks • Identity threats and lateral movement • SaaS misconfigurations and privilege abuse • Endpoint malware/behavior anomalies • Insider threats and account takeover patterns • Use MITRE ATT&CK, MITRE Cloud Matrix, and threat intel to drive detection coverage. • Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases. Triage, Threat Analysis & Escalation • Lead day-to-day triage and threat analysis activities, ensuring accurate categorization and prioritization. • Drive complex investigations involving correlated events across cloud, SaaS, endpoints, and developer platforms. • Guide root cause analysis and work with owners to drive remediation and architectural improvements. • Continuously refine logic, reduce false positives, and improve signal quality. Cross-Functional Collaboration • Partner with Cloud Security on cloud posture and preventative controls. • Work with Compliance/GRC to support SOC 2, ISO 27001, and audit readiness. • Collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks. • Coordinate with IT / Endpoint teams to ensure full endpoint telemetry and EDR response readiness. • Communicate threats, gaps, and trends to leadership and engineering stakeholders. Required Skills & Experience • 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity. • Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP). • Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.). • Deep understanding of: • Cloud security monitoring (GCP required; AWS/Azure preferred) • SaaS security monitoring (Okta, Google Workspace, GitHub, Slack, etc.) • Endpoint security telemetry (EDR/XDR tools such as CrowdStrike, SentinelOne, or Defender) • Kubernetes and container detection • Hands-on detection engineering skills, event correlation, threat hunting, and log analysis. • Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools. • Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns. • Experience with SOAR and scripting (Python, Go, Bash). • Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management. Preferred Qualifications • Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems. • Previous experience at a high-growth tech company. • Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.). What We Value • Operational excellence: Building reliable, scalable SOC systems. • Analytical rigor: Capable of making sense of large, complex, multi-source telemetry. • Leadership: Mentorship and guidance of analysts and engineers. • Adaptability: Comfortable evaluating and integrating next-gen AI-based SOC tools. • Clear communication: Able to articulate risk, incidents, and recommendations to both technical and executive audiences. • Automation mindset: Focused on reducing manual toil via SOAR, scripting, and AI augmentation. Curiosity: Passion for learning, experimenting, and staying ahead of evolving threats—especially those targeting cloud-native and AI systems. This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program with a 4% match (US Only) ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🏝 Flexible Time Off (FTO) + Holidays 🚗 Commuter Benefits (In-Office Only) 📱 Monthly Wellness Stipend 🧑💻 Autonomous Work Environment 🖥 In Office Set-Up Reimbursement (In-Office Only) 🚀 Quarterly Team Gatherings ☕ In Office Amenities (In-Office Only) Want to learn more about what we are up to? • Meet the Replit Agent • Replit: Make an app for that • Replit Blog • Amjad TED Talk Interviewing + Culture at Replit • Operating Principles • Reasons not to work at Replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Create tailored applications specifically for Replit with our AI-powered resume builder
Get Started for Free