Security Engineer - Vuln Management (code)

Replit Replit · Enterprise · Foster City, CA · IT

Security Engineer focused on vulnerability management, software supply chain security, and compliance within a software development platform.

What you'd actually do

  1. Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.
  2. Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
  3. Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security.
  4. Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
  5. Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.

Skills

Required

  • Application Security
  • DevSecOps
  • Software Engineering
  • JavaScript/TypeScript
  • Python
  • Go
  • build systems
  • package managers
  • SAST
  • SCA
  • Secret Scanning tools
  • SOC 2
  • ISO 27001
  • NIST

Nice to have

  • Snyk
  • Socket
  • Wiz Code
  • Semgrep
  • Checkmarx

What the JD emphasized

  • strict regulatory compliance frameworks
  • strict compliance SLAs
  • modern regulatory requirements