Security Engineer - Vuln Management (Code)

Remote Foster City, CA FullTime

Posted 2mo ago

Job Location

Foster City, CA

Tech Stack

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Replit is seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. This role bridges the gap between security, compliance, and engineering teams by identifying application vulnerabilities, maintaining software supply chain security, and driving tracking to satisfy strict regulatory compliance frameworks. The engineer will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect the software ecosystem.

Responsibilities

  • Perform application security scanning and triage vulnerabilities based on CVSS scores, exploitability, and system exposure.
  • Track, document, and manage vulnerabilities according to compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS) and maintain audit-ready evidence.
  • Escalate and report critical exposures to CISO and senior leadership, and maintain dashboards for vulnerability status and risk trends.
  • Own and update the Software Bill of Materials (SBOM) to ensure compliance with regulatory requirements and dependency tracking, and mature SLSA levels for supply chain security.
  • Collaborate with development teams on mitigation strategies and patch code directly when necessary.
  • Configure and tune automated security testing tools within CI/CD pipelines.
  • Assist Incident Response teams during security incidents by developing and implementing real-time countermeasures.

Requirements

  • 5 years of experience in Application Security, DevSecOps, or Software Engineering.
  • Solid foundational experience in software development.
  • Ability to read, understand, and patch security flaws in JavaScript/TypeScript, Python, and Go.
  • Strong familiarity with build systems, package managers, and compilation workflows.
  • Hands-on experience with SAST, SCA, and Secret Scanning tools (e.g., Snyk, Socket, Wiz Code, Semgrep, Checkmarx).
  • Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.
  • Systems thinking ability to understand the impact of security decisions on the entire stack.
  • Ability to drive technical alignment through expertise and collaboration.
  • Comfortable leading technical initiatives with minimal oversight.
  • Problem-solving mindset for complex security challenges.

Benefits

  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.