11h ago
Product Security Engineer
Foster City, CA
$180k-$325k / year
full-timesenior Hybridsoftware
๐ Tech Stack
๐ผ About This Role
You'll lead the vulnerability response program for Replit's cloud-native AI platform, owning the lifecycle of security vulnerabilities from intake to disclosure. You'll work closely with Engineering, Cloud Security, and SRE to ensure vulnerabilities are fixed quickly and communicated responsibly. This role offers the chance to manage bug bounty programs and coordinate CVE assignments.
๐ฏ What You'll Do
- Manage intake from bug bounty platforms and validate findings
- Work with engineering teams to drive remediation and track SLAs
- Design and evolve the bug bounty program scope and rewards
- Coordinate CVE assignments and publish customer advisories
๐ Requirements
- Experience running or triaging for bug bounty programs (HackerOne)
- Ability to independently triage, validate, and reproduce vulnerabilities
- Deep understanding of web/app/cloud vulnerability classes and OWASP Top 10
- Familiarity with cloud platforms (GCP preferred) and SaaS architectures
โจ Nice to Have
- Scripting or automation experience in Python, Go, or Bash
- Pentesting background or exposure to offensive security work
- Experience authoring public advisories or CVE writeups
๐ Benefits & Perks
- ๐ฐ Competitive Salary & Equity
- ๐ฑ Monthly Wellness Stipend
- ๐ Flexible Time Off + Holidays
- ๐ผ Paid Parental, Medical, Caregiver Leave
- ๐ฅ In Office Set-Up Reimbursement
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Phone Screenยท 30 min
- 2Technical Interviewยท 60 min
- 3Onsite Interviewยท 120 min
0 0 0