← Back to job listings
RE
Product Security Engineer (PSIRT - Product Security Incident Response Team)
Replit · United States
About The Role
Join Replit, a cloud-native AI platform, as a Product Security Engineer. In this role, you will lead the vulnerability response program, manage the lifecycle of security vulnerabilities, and work closely with various teams to ensure quick remediation and responsible communication. You will also design and evolve the bug bounty program, manage the coordinated vulnerability disclosure process, and support compliance frameworks. This is a remote-first position with flexible work hours and a comprehensive benefits package.
- Lead the vulnerability response program for Replit’s cloud-native AI platform, managing the lifecycle of security vulnerabilities from intake to public disclosure.
- Work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly, coordinating remediation efforts.
- Design and evolve the bug bounty program, including scope, rules, and reward structures, and manage platform selection, private vs. public launches, and community engagement.
- This role requires strong technical ability to reproduce vulnerabilities, deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs
- Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc
- Familiarity with cloud platforms (GCP preferred) and SaaS architectures
- Strong ability to triage, validate, and reproduce vulnerabilities independently
- Experience running or triaging for bug bounty programs (HackerOne ideally)
- Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals
- Scripting or automation experience (Python, Go, Bash)
- Pentesting background or exposure to offensive security work
- Familiarity with compliance frameworks such as SOC 2 and ISO 27001
- Experience authoring public advisories or CVE writeups
- Hands-on experience with SIEM, Cloud Logging, and investigative tooling
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring