Product Security Engineer (PSIRT - Product Security Incident Response Team)

Replit
United States
Workplace: HybridFull timeUSD 180,000 - 325,000 annuallyFunction: CybersecuritySkills: ["Communication","Problem-solving","Collaboration","Attention to detail"]

Lead the vulnerability response program for Replit’s cloud-native AI platform, owning the lifecycle of security vulnerabilities—from intake to validation, remediation coordination, and public disclosure. Collaborate with Engineering, Cloud Security, SecOps, SRE, and IT to ensure vulnerabilities are fixed quickly and communicated responsibly.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Replit
Replit
3 months ago

Product Security Engineer (PSIRT - Product Security Incident Response Team)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Lead the vulnerability response program for Replit’s cloud-native AI platform, owning the lifecycle of security vulnerabilities—from intake to validation, remediation coordination, and public disclosure. Collaborate with Engineering, Cloud Security, SecOps, SRE, and IT to ensure vulnerabilities are fixed quickly and communicated responsibly.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Manage vulnerability intake from bug bounty platforms, customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
  • •Independently validate, reproduce, severity-score, and document findings.
  • •Identify duplicates and maintain a clean vulnerability records pipeline.
  • •Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).
  • •Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
  • •Provide detailed reproduction steps, proof-of-concepts, and technical analyses.
  • •Track SLAs, remediation progress, regression testing, and systemic improvements.
  • •Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.
  • •Design and evolve the bug bounty program, including scope, rules, and reward structures.
  • •Manage platform selection, private vs. public launches, and community engagement.
  • •Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.
  • •Determine reward payouts, bonus decisions, and recognition for top contributors.
  • •Lead the coordinated vulnerability disclosure process for internal and external findings.
  • •Negotiate disclosure timelines with researchers and partners.
  • •Coordinate CVE assignments and publications, and prepare customer/public advisories.

Pay and Benefits

Salary: USD 180,000 - 325,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVisionLife Insurance401kEquityCommuter BenefitsWellness StipendRemote WorkIn Office

Key Requirements

  • •Experience running or triaging for bug bounty programs (HackerOne ideally).
  • •Strong ability to triage, validate, and reproduce vulnerabilities independently.
  • •Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
  • •Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
  • •Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.
Experience:CloudSecuritySaaSAI
Skills:CommunicationProblem-solvingCollaborationAttention to detail
Languages:English
Tech Stack:HackerOneOWASPGCPSaaSCI/CDCloud LoggingSIEM

Company Brief

Replit
Provides a browser-based integrated development environment (IDE) and collaborative coding platform that lets developers write, run, and deploy code instantly across many languages and frameworks.
Industry: Developer Tools
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2016
WebsiteLinkedIn