Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer - Vuln Management (Code)

Replit

Mid-Level Appsec Vulnerability Management Engineer

We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem.

Core Responsibilities
  • Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.
  • Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
  • Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.
  • Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security.
  • Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
  • Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.
  • Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.
Required Skills & Experience
  • 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
  • Solid foundational experience working in a software development capacity.
  • Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
  • Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.
  • Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).
  • Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.
What We Value
  • The ability to see the "big picture" and understand how security decisions impact the entire stack.
  • The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
  • Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
  • A passion for breaking down complex security challenges into elegant, scalable engineering solutions.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:

  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security Engineer - Vuln Management (Code) in San Mateo, CA vacancy
  •  ...seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development...  ...role, you will bridge the gap between security, compliance, and engineering teams. You...  ...develop and implement immediate, real-time code or infrastructure countermeasures. Experience... 
    Suggested
    Full time
    Temporary work
    Work at office
    Immediate start
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    2 days ago
  •  ...creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and... 
    Suggested
    Full time
    Temporary work
    Work at office
    Immediate start
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    1 day ago
  • $200k - $300k

     ...Staff+ Security Engineer, IT and Corporate Security San Mateo, CA United States Who We Are Verkada is transforming how organizations...  ..., air quality sensors, alarms, intercoms, and visitor management. We've got serious momentum in the market: more than 30,0... 
    Suggested
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    1 day ago
  • $130k - $280k

     ...includes solutions for video security, access control, air quality...  ..., intercoms, and visitor management. We’ve got serious momentum...  ...* Partner closely with engineering and product teams to improve...  ...features, and strategies; * Coding ability. You will sometimes... 
    Suggested
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    4 days ago
  • $145k - $240k

     ...SuperDial is building the automation engine that fixes revenue cycle management. We work with leading MSOs, DSOs,...  ...environments and mission critical workflows, security is a first-principles priority....  .... Define and enforce secure coding practices, CI/CD controls, and... 
    Suggested

    SuperDial

    Burlingame, CA
    5 days ago
  • $130k - $280k

     ...includes solutions for video security, access control, air quality...  ...alarms, intercoms, and visitor management. We've got serious...  ...As an embedded security engineer on the Device Security Team,...  ...participate in security design & code reviews. Explore innovative... 
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    23 hours ago
  • $245k - $306.5k

     ...leader in Intelligent Content Management. Our platform enables...  ...the entire content lifecycle, secure critical content, and transform...  ...a Staff Enterprise Security Engineer who will be a part of our Enterprise...  ...scripting, infrastructure-as-code, and orchestration platforms... 
    Live in
    Work at office
    Immediate start
    Shift work
    3 days per week

    Box

    Redwood City, CA
    4 days ago
  • $216.68k - $269.17k

     ...to create safer, more civil shared experiences for everyone. Be a part of Roblox Corporation as a Senior Security Software Engineer in Vulnerability Management. Join our dedicated team to ensure the security of our platform. You will work on scaling vulnerability... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    17 days ago
  •  ...looking for a highly skilled PSIRT Engineer to lead the vulnerability...  ...You will own the lifecycle of security vulnerabilities affecting our...  ..., Triage & Validation Manage intake from bug bounty...  ...understanding of CI/CD workflows, code structure, and software engineering... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    2 days ago
  • $170.6k - $390k

     ...to grow your career in information security! The opportunity The Senior Network...  ...Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role...  ...Transformation Script Writing/Coding abilities Proficiency in Security... 
    Summer holiday
    Remote work
    Flexible hours

    EY

    San Mateo, CA
    4 days ago
  • $269.17k - $326.06k

     ...civil shared experiences for everyone. The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production...  ...balancing deep technical work (threat modeling, code review, penetration testing) with systemic... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    3 days ago
  •  ...Offensive Security Engineer Replit is the agentic software creation platform that enables anyone to build applications using natural language...  ...about perimeter defense; it's about the integrity of the code that powers millions of environments. In this role, you will... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    San Mateo, CA
    3 days ago
  • $180k - $220k

     ...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative...  ...encryption, identity and access management, secure API gateways, secure model...  ...Proficiency with infrastructure-as-code using Terraform and Python, including experience... 

    Fireworks AI

    San Mateo, CA
    3 days ago
  • $80 per hour

     ...organization in autonomous mobility, is seeking a dedicated Network Security Engineer to join their dynamic team. As a Network Security Engineer,...  ...IT, Product, and Operations to enhance security measures. Manage and support AWS network security services, including AWS... 
    Weekly pay
    Temporary work
    Remote work
    Flexible hours

    Manpower Group Inc.

    Foster, CA
    1 day ago
  • $269.17k - $326.06k

     ...experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will...  ...organization and report to the Senior Manager of Infrastructure Security. You will...  ...Have: ~5+ years of experience writing code and/or relevant technical experience.... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    23 days ago
  • $326.06k - $385.05k

     ...shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security...  ...autonomous agentic workflows. Test application code following the OWASP Testing Methodology. Mentor... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    1 day ago
  • $293.8k - $343.34k

     ...everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security...  ..., reporting directly to the Senior Manager of Enterprise Security Engineering. You...  ...or operating workflows using low-code and no-code orchestration platforms.... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    2 days ago
  • $137.86k - $240k

     ...Product Security Engineer, Cryptography & PKI San Carlos, CA (on-site) About 1X We build...  ...systems. You Will Design and manage end-to-end cryptographic services,...  ...destruction Secure build systems and code-signing workflows Develop factory provisioning... 
    Local area
    Remote work

    1X Technologies AS

    San Carlos, CA
    4 days ago
  •  ...combined experience in software development, security engineering and security regulatory and compliance...  ...assessment • Experience with secure coding practices, vulnerability remediation,...  ...Able to identify Identity and Access management attacks • Data collection, storage,... 

    Glow Networks

    San Mateo, CA
    2 days ago
  • $137.86k - $240k

     ...Product Security Engineer, Operating System San Carlos, CA (on-site) About 1X We build...  ...systems Contribute and ship C/C++ code (or similar) to production environments...  ...access control and Linux permissions management Solid understanding of CI/CD security... 
    Local area

    1X Technologies AS

    San Carlos, CA
    4 days ago
  • $230k - $275k

     ...fast as possible. Zipline’s security problems aren’t “website got...  ...hats, and collaborates across engineering disciplines. You’ll join a small...  ...like the NIST AI Risk Management Framework (including a profile...  ...controls, secrets management, and code review patterns that don’t... 
    Internship
    Work at office
    Local area

    Namely

    South San Francisco, CA
    1 day ago
  •  ...About the Role We're hiring a hands-on Engineering Manager to build and lead Replit's Anti-Abuse...  ...You'll partner across Support, Legal, Security, Infrastructure, and the Money and Growth...  ...time. Ship as a hands-on EM: Stay in the code. Use the latest AI coding tools (... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    3 days ago
  • $205k - $275k

     ...Application Security Engineer Opportunity We're hiring an Application Security Engineer to work hands...  ...practitioner role; you'll spend your time in code, in tooling, and in design reviews, not writing strategy decks or managing people. You'll report to our security... 
    Home office
    Flexible hours

    AKASA

    South San Francisco, CA
    4 days ago
  •  ...Job Description: We are seeking an experienced Network Security Engineer who will be responsible for helping ensure the security of our...  ...IT, Product, and Operations teams. Experience with change management and a focus on customer experience as a key component of... 
    Remote work

    LanceSoft

    San Mateo, CA
    2 days ago
  •  ...professional responsible for helping ensure the security of our customers, staff, systems,...  ...~4 years of Network Security Engineer experience supporting production environments...  ...Qualifications Experience with change management Focus on customer experience as a key... 
    Work experience placement
    Immediate start
    Remote work

    Artech

    San Mateo, CA
    3 days ago
  •  ...Senior Security Engineer We're a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer,...  ...Protect sensitive data through strong controls for access management, encryption, and secure data handling. Identify, assess,... 
    Permanent employment
    Full time
    Local area
    Remote work
    3 days per week

    BeaconAI

    San Carlos, CA
    3 days ago
  • $200k - $300k

     ...Staff Backend Engineer - Device Security San Mateo, CA United States Who We Are Verkada is transforming how organizations protect their...  ..., air quality sensors, alarms, intercoms, and visitor management. We've got serious momentum in the market: more than 30... 
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    5 days ago
  • $195k - $300k

     ...Lead Application Security Engineer San Mateo, CA (Hybrid) Eve is redefining legal technology...  .... You'll review designs, write code, build automation, harden systems, and...  ...threat modeling, code review, vulnerability management, and secure deployment. Partner with... 
    Temporary work
    Work at office
    Local area
    Flexible hours

    EVE Inc

    San Mateo, CA
    10 hours ago
  • $158.9k - $238.3k

     ...person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team...  ..., building, development, testing, and management of security tools and processes that...  ...applications and controls Write code to automate security processes which seamlessly... 

    PlayStation Global

    San Mateo, CA
    7 days ago
  •  ...Bloom Talent Partners is seeking a Cloud Security Engineer in San Mateo, California. The ideal candidate will focus on automating security measures and developing secure coding practices within cloud environments. This role requires expertise in Docker, Kubernetes, and... 

    Bloom Talent Partners

    San Mateo, CA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer - Vuln Management (Code). Be the first to apply!