Product Security Engineer (PSIRT - Product Security Incident Response Team)
ReplitFoster City, CA · Remote · full time · Mid
$180,000 – $325,000
Listed on Replit’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
Replit seeks a security professional to manage their vulnerability response program, handling everything from bug bounty intake and triage through coordinated disclosure and CVE publication. This role suits someone with hands-on vulnerability assessment experience and the ability to work across technical and program management dimensions.
Our summary, not Replit’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- Experience running or triaging bug bounty programs
- Independently triage, validate, and reproduce vulnerabilities
- Deep understanding of web, app, and cloud vulnerability classes
- Familiarity with cloud platforms, preferably GCP
- Understanding of CI/CD workflows and software engineering fundamentals
Nice to have
- Python, Go, or Bash scripting and automation
- Pentesting or offensive security background
- SOC 2 and ISO 27001 compliance knowledge
- Experience writing public security advisories or CVE documentation
- Hands-on experience with SIEM and cloud logging tools