Product Security Engineer (PSIRT - Product Security Incident Response Team)

Remote Foster City, CA FullTime

Posted 3mo ago

Job Location

Foster City, CA

Tech Stack

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Replit is seeking a skilled PSIRT Engineer to lead its vulnerability response program for its cloud-native AI platform. This role involves managing the entire lifecycle of security vulnerabilities, from intake and validation to remediation coordination and public disclosure. The ideal candidate will possess strong technical skills to reproduce vulnerabilities, a deep understanding of web, application, and cloud exploit classes, and experience with bug bounty and coordinated disclosure programs. You will collaborate closely with various engineering and security teams to ensure timely fixes and responsible communication.

Responsibilities

  • Manage vulnerability intake from bug bounty platforms, customer reports, scanners, pentests, and disclosure channels.
  • Independently validate, reproduce, score severity, and document security findings.
  • Assess vulnerability relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks.
  • Drive remediation by working with engineering and security teams, providing detailed reproduction steps and technical analyses.
  • Track remediation progress, SLAs, regression testing, and systemic improvements.
  • Support compliance needs for SOC 2, ISO 27001, and pentests.
  • Design and evolve the bug bounty program, including scope, rules, and reward structures.
  • Manage platform selection, program launches, and community engagement with researchers.
  • Communicate with researchers, handle feedback, and determine reward payouts.
  • Lead coordinated vulnerability disclosure processes for internal and external findings.
  • Negotiate disclosure timelines and coordinate CVE assignments and publications.
  • Prepare customer and public advisories.

Requirements

  • Experience running or triaging for bug bounty programs (HackerOne preferred).
  • Strong ability to triage, validate, and reproduce vulnerabilities independently.
  • Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, and authN/Z issues.
  • Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
  • Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.
  • Experience authoring public advisories or CVE writeups.
  • Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
  • Scripting or automation experience (Python, Go, Bash).
  • Pentesting background or exposure to offensive security work.
  • Hands-on experience with SIEM, Cloud Logging, and investigative tooling.

Benefits

  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.