Security Engineer - Vuln Management (Infra)

Replit
United States
Workplace: HybridFull timeUSD 210,000 - 270,000 annuallyFunction: CybersecurityExperience: 5+ yearsSkills: ["Security","Cloud","Devsecops","IaC","Terraform","Pulumi","GitOps","Kubernetes","Docker","IAM","Security scanning"]

Mid-level infrastructure security engineer focused on vulnerability management, cloud security, DevSecOps, and IaC. You will scan and triage cloud environments, manage CSPM/KSPM/DSPM posture, implement IaC security within CI/CD, secure workloads and containers, track compliance SLAs, and partner with SRE/Platform teams to remediate flaws and respond to incidents in a multi-cloud production landscape.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Replit
Replit
3 months ago

Security Engineer - Vuln Management (Infra)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Mid-level infrastructure security engineer focused on vulnerability management, cloud security, DevSecOps, and IaC. You will scan and triage cloud environments, manage CSPM/KSPM/DSPM posture, implement IaC security within CI/CD, secure workloads and containers, track compliance SLAs, and partner with SRE/Platform teams to remediate flaws and respond to incidents in a multi-cloud production landscape.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Infrastructure Scanning & Triage: Perform continuous security scanning across cloud posture and workloads, review and prioritize flaws based on CVSS scores, exploitability, and network exposure.
  • •Posture Management & Visibility: Own CSPM, KSPM, and DSPM tooling to ensure compliance, prevent data leakage, and maintain hardened baselines.
  • •Infrastructure-as-Code (IaC) Security: Configure and embed automated IaC security scanning tools into CI/CD pipelines to identify risks before production deployment.
  • •Workload & Container Security: Manage vulnerability lifecycle for container images, registries, and VMs; coordinate base-image patching and rolling upgrades with SRE/Platform teams.
  • •Compliance-Driven Tracking & Reporting: Track vulnerabilities to SOC 2/ISO 27001/PCI-DSS SLAs; maintain audit-ready remediation timelines and approvals.

Pay and Benefits

Salary: USD 210,000 - 270,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kWellness StipendCommuter BenefitsParental Leave

Key Requirements

  • •5 years of experience in Cloud Security, DevSecOps, or Systems Engineering roles
  • •Deep multi-cloud experience (GCP preferred, AWS or Azure knowledge)
  • •Hands-on with posture management and scanning tools (Wiz, Orca, Prisma Cloud, Lacework, or GCP Security Command Center)
  • •Proficiency with Infrastructure as Code (Terraform, Pulumi) and GitOps workflows; experience evaluating IaC scanners like Checkov, Tfsec, or KICS
  • •Docker/container security and Kubernetes architectures (GKE, EKS); runtime security and workload identity
Experience:5+ yearsCloud securityDevsecopsInfrastructure
Skills:SecurityCloudDevsecopsIaCTerraformPulumiGitOpsKubernetesDockerIAMSecurity scanning
Tech Stack:TerraformPulumiGitOpsCheckovTfsecKICSGKEEKSDockerKubernetesGCPAWSAzureCloud Security Posture ManagementCSPMKSPMDSPM

Company Brief

Replit
Provides a browser-based integrated development environment (IDE) and collaborative coding platform that lets developers write, run, and deploy code instantly across many languages and frameworks.
Industry: Developer Tools
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2016
WebsiteLinkedIn