11h ago

Product Security Engineer

Foster City, CA

$180k-$325k / year

full-timesenior Hybridsoftware

๐Ÿ›  Tech Stack

๐Ÿ’ผ About This Role

You'll lead the vulnerability response program for Replit's cloud-native AI platform, owning the lifecycle of security vulnerabilities from intake to disclosure. You'll work closely with Engineering, Cloud Security, and SRE to ensure vulnerabilities are fixed quickly and communicated responsibly. This role offers the chance to manage bug bounty programs and coordinate CVE assignments.

๐ŸŽฏ What You'll Do

  • Manage intake from bug bounty platforms and validate findings
  • Work with engineering teams to drive remediation and track SLAs
  • Design and evolve the bug bounty program scope and rewards
  • Coordinate CVE assignments and publish customer advisories

๐Ÿ“‹ Requirements

  • Experience running or triaging for bug bounty programs (HackerOne)
  • Ability to independently triage, validate, and reproduce vulnerabilities
  • Deep understanding of web/app/cloud vulnerability classes and OWASP Top 10
  • Familiarity with cloud platforms (GCP preferred) and SaaS architectures

โœจ Nice to Have

  • Scripting or automation experience in Python, Go, or Bash
  • Pentesting background or exposure to offensive security work
  • Experience authoring public advisories or CVE writeups

๐ŸŽ Benefits & Perks

  • ๐Ÿ’ฐ Competitive Salary & Equity
  • ๐Ÿ“ฑ Monthly Wellness Stipend
  • ๐Ÿ Flexible Time Off + Holidays
  • ๐Ÿšผ Paid Parental, Medical, Caregiver Leave
  • ๐Ÿ–ฅ In Office Set-Up Reimbursement

๐Ÿ“จ Hiring Process

Estimated timeline: 2-4 weeks ยท AI estimate

  1. 1Phone Screenยท 30 min
  2. 2Technical Interviewยท 60 min
  3. 3Onsite Interviewยท 120 min
0 0 0