Security Architecture Lead
Remote • Foster City, CA • FullTime
Posted 5mo ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Replit is seeking a Security Architecture Lead to be the primary technical authority for the company's security blueprint. In this player-coach role, you will guide a team of security architects and engineers, ensuring the platform is secure by design. You will lead high-impact technical initiatives and provide deep subject matter expertise to both the engineering organization and executive leadership, steering the architectural direction for security.
Responsibilities
- Define the long-term vision and ensure consistency for security architecture across complex infrastructure and product projects.
- Provide high-level guidance and mentorship to security engineers, fostering technical excellence and rigorous security design.
- Lead cross-functional squads through complex security implementations from design to production deployment.
- Define and maintain the authoritative 'Source of Truth' for Replit’s secure architecture.
- Drive the design for secure bootstrapping and multi-layered trust, enforcing isolation principles at all levels.
- Actively identify, document, and quantify architectural security risks and translate them into actionable risk profiles for executives.
- Oversee and conduct deep-dive security reviews for core product features and infrastructure.
- Own the architectural strategy for Availability and defense against DoS threats.
- Partner with GRC teams to translate architectural designs into audit-ready documentation and control frameworks.
- Act as the technical bridge for the Sales team, addressing complex security inquiries from enterprise customers.
Requirements
- 8+ years of experience in security engineering or security architecture.
- Proven experience as a Technical Lead, steering large-scale projects and guiding senior engineers.
- Experience writing and maintaining architecture documents.
- Deep expertise in cloud-native security architecture for multi-tenant SaaS products (GCP experience is a plus).
- Experience designing secure boot, hardware/Cloud-KMS-rooted trust, and multi-layered defense systems.
- Strong understanding of isolation technologies and DDoS mitigation.
- Exceptional ability to communicate technical risk to engineering and executive audiences.
- Strong track record of contributing to Cybersecurity Risk Register.
- Systems Thinking: Ability to see the 'big picture' and understand security impacts across the entire stack.
- Technical Influence: Ability to drive technical alignment through expertise and collaboration.
- Autonomy: Comfortable leading major technical initiatives with minimal oversight.
- Problem-Solving Mindset: Passion for breaking down complex security challenges into scalable engineering solutions.
Benefits
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)