Product Security Engineer (psirt - Product Security Incident Response Team)

Replit Replit · Enterprise · Foster City, CA · Hybrid · IT

Product Security Engineer (PSIRT) responsible for managing the lifecycle of security vulnerabilities within Replit's cloud-native AI platform, including intake, validation, remediation coordination, and public disclosure. Requires strong technical ability to reproduce vulnerabilities and experience with bug bounty programs.

What you'd actually do

  1. Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
  2. Independently validate, reproduce, severity-score, and document findings.
  3. Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
  4. Design and evolve the bug bounty program, including scope, rules, and reward structures.
  5. Lead the coordinated vulnerability disclosure process for internal and external findings.

Skills

Required

  • Experience running or triaging for bug bounty programs (HackerOne ideally).
  • Strong ability to triage, validate, and reproduce vulnerabilities independently.
  • Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
  • Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
  • Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.

Nice to have

  • Scripting or automation experience (Python, Go, Bash).
  • Pentesting background or exposure to offensive security work.
  • Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
  • Experience authoring public advisories or CVE writeups.
  • Hands-on experience with SIEM, Cloud Logging, and investigative tooling.

What the JD emphasized

  • strong technical ability to reproduce vulnerabilities
  • strong understanding of web/app/cloud exploit classes
  • experience operating bug bounty and coordinated disclosure programs