Skip to content
← Back to job listings

Staff Software Engineer (Risk)

Replit · United States

External listingfull-time2 months ago

About The Role

Join Replit, a leading AI-native platform, as a Staff Software Engineer in the Risk team. In this role, you will be at the forefront of defending the platform from exploitation, detecting and shutting down phishing deployments, preventing cryptomining, and stopping LLM token farming. You will work on unique problems related to AI-generated code and use LLMs as a defensive tool against abuse. This is a hands-on role where you will own problems end-to-end, from identifying emerging abuse patterns to shipping the systems that stop them at scale.

  • Concevoir et mettre en œuvre des garde-fous pour les LLM qui détectent les scénarios d'abus dans le code généré par l'IA et les interactions des agents.
  • Construire des systèmes de détection alimentés par l'IA qui utilisent les LLM pour identifier les modèles malveillants, classifier les menaces et automatiser les décisions de réponse.
  • Posséder l'ensemble du cycle de vie de la réponse aux abus : détection, enquête, application et traitement des appels en collaboration avec le support et le juridique.
  • Familiarity with prompt injection, jailbreaking, and other LLM-specific attack vectors
  • Experience building or fine-tuning ML/LLM-based classifiers for security or abuse detection
  • Strong programming skills in Python and/or TypeScript for building detection systems and automation
  • Ability to investigate complex abuse patterns and translate findings into automated defenses
  • Familiarity with common attack patterns: phishing infrastructure, account takeover, credential stuffing, resource abuse
  • 8+ years of experience in security engineering, anti-abuse, trust & safety, or fraud detection
  • Clear communication skills for working across Security, Support, Legal, and Engineering teams
  • Experience with SQL and data analysis at scale (BigQuery, Snowflake, or similar)
  • Experience at a platform company dealing with user-generated content or compute abuse (hosting providers, cloud platforms, developer tools)
  • Background in fraud detection, payment abuse, or financial crime
  • Familiarity with device fingerprinting, IP reputation, and email validation services
  • Experience with CI/CD security tooling (SAST, SCA, Dependabot, Snyk)
  • Prior work with abuse reporting pipelines, trust & safety tooling, or content moderation systems
  • Knowledge of container security, Linux internals, or cloud infrastructure (GCP preferred)

This is an external listing. JobSpring does not represent or verify the employer. Report this listing