Security Engineer - Vuln Management (Code)
Core
Mid-level AppSec Vulnerability Management Engineer bridging security, compliance, and engineering to identify vulnerabilities, maintain supply chain security, and ensure regulatory compliance.
Role type
Mid-level IC Application Security Engineer (Vulnerability Management)
Builds
Production security posture, SBOMs, and compliance evidence for Replit's agentic software platform
Domain
SaaS / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Application Security, DevSecOps, Software Engineering, JavaScript/TypeScript, Python, Go, Build Systems, SAST, SCA, Secret Scanning, SOC 2, ISO 27001, NIST
Preferred skills
Systems Thinking, Technical Influence, Autonomy, Problem-Solving
Technologies
Snyk, Socket, Wiz Code, Semgrep, Checkmarx, CI/CD pipelines
Responsibilities
Perform application security scanning and triage based on CVSS scores; Track and manage vulnerabilities per compliance SLAs (SOC 2, ISO 27001, PCI-DSS); Escalate critical exposures to leadership and maintain risk dashboards; Own SBOM inventory and SLSA maturity; Patch code directly to resolve security flaws; Configure security tools in CI/CD pipelines; Support incident response with immediate countermeasures
Seniority
Mid-level, hands-on IC