Skip to content
← Back to job listings

Security Engineer (Vuln Management, Code)

Replit · United States

External listingfull-time2 months ago

About The Role

Join our team as a mid-level AppSec Vulnerability Management Engineer. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. This is a remote-first position with flexible work hours and a comprehensive benefits package.

  • Identifying application vulnerabilities, maintaining software supply chain security, and driving tracking to satisfy strict regulatory compliance frameworks.
  • Performing periodic application security scanning activities, reviewing results, and prioritizing flaws based on CVSS scores, real-world exploitability, and system exposure.
  • Tracking, documenting, and managing vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS) and maintaining audit-ready evidence of remediation timelines.
  • Experience: 5 years of experience in Application Security, DevSecOps, or Software Engineering roles
  • Build System Expertise: Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks
  • AppSec Tooling Expertise: Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx)
  • Development Background: Solid foundational experience working in a software development capacity
  • Code Literacy: Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go
  • Compliance Awareness: Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST
  • Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight
  • Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack
  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority
  • Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions

This is an external listing. JobSpring does not represent or verify the employer. Report this listing