Replit

Security Engineer - Incident Response

Replit
Apply
5 hours ago
Foster City, CA, USASenior
H1B sponsor

Base Salary

$230k - $360k/yr

Responsibilities

  • Lead security incidents from detection and triage through containment, eradication, recovery, and post-incident review.
  • Coordinate incident response across Security, SRE, Engineering, Legal, and leadership while communicating status, impact, and risk.
  • Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, cloud logs, telemetry, and host or container artifacts.
  • Determine incident scope, root cause, attacker behavior, and blast radius, including assessing emerging threats and active exploitation.
  • Build scripts, automations, and tools for enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage.
  • Develop and maintain response playbooks and runbooks and integrate workflows with SIEM, SOAR, ticketing, and chat tools.
  • Improve detections, logging coverage, and visibility based on incident findings.
  • Lead blameless post-incident reviews, drive remediation to completion, and run tabletop exercises and simulations.
  • Participate in and help shape the security on-call rotation.

Requirements

  • Proven experience leading or serving as technical lead on security incidents in a cloud or SaaS environment.
  • Strong hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis, including working through large datasets under time pressure.
  • Production-quality scripting or tool development in Python, Go, or Bash.
  • Knowledge of cloud architecture and security, especially Google Cloud Platform, IAM, audit logging, GKE, and networking.
  • Working knowledge of Kubernetes and containers, including investigation and containment of compromised workloads.
  • Understanding of identity systems, SaaS architectures, and cloud attack paths such as credential theft, privilege escalation, supply chain attacks, and token abuse.
  • Familiarity with software engineering fundamentals, CI/CD pipelines, and package ecosystems.
  • Understanding of incident-response frameworks and lifecycle, including NIST 800-61, as well as vulnerability lifecycle and exploitability analysis.
  • Preferred qualifications include SOAR or response-automation experience, digital forensics, threat intelligence, threat hunting, security research, bug bounty or coordinated vulnerability disclosure experience, detection-as-code, and experience in cloud-native or AI/ML-driven environments.
  • Relevant certifications such as GCIH, GCFA, or GCFR, or equivalent hands-on experience, are preferred.

Benefits

  • Competitive salary and equity.
  • 401(k) program with a 4% match for US employees.
  • Health, dental, vision, life, short-term disability, and long-term disability insurance.
  • Paid parental, medical, and caregiver leave.
  • Flexible Time Off and holidays.
  • Commuter benefits for in-office US employees.
  • Monthly wellness stipend.
  • Autonomous work environment.
  • In-office setup reimbursement where applicable.
  • Quarterly team gatherings and in-office amenities.
Replit

About Replit

501-1,000 employees

Replit builds a browser-based software development platform with an AI coding agent, collaborative IDE, and built-in deployment for individuals, teams, and businesses. It offers freemium and paid plans for developers and organizations, plus hosting and enterprise features used to create and run web applications. Founded in 2016 and headquartered in Foster City, California, Replit is privately held and serves a global user base.

Contact me