Security Engineer - Vuln Management (Code)
Replit
Mid-Level Appsec Vulnerability Management Engineer
We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem.
Core Responsibilities
- Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.
- Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
- Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.
- Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security.
- Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
- Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.
- Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.
Required Skills & Experience
- 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
- Solid foundational experience working in a software development capacity.
- Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
- Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.
- Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).
- Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.
What We Value
- The ability to see the "big picture" and understand how security decisions impact the entire stack.
- The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
- Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
- A passion for breaking down complex security challenges into elegant, scalable engineering solutions.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
- ...seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development... ...role, you will bridge the gap between security, compliance, and engineering teams. You... ...develop and implement immediate, real-time code or infrastructure countermeasures. Experience...SuggestedFull timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
- ...creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and...SuggestedFull timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
$200k - $300k
...Staff+ Security Engineer, IT and Corporate Security San Mateo, CA United States Who We Are Verkada is transforming how organizations... ..., air quality sensors, alarms, intercoms, and visitor management. We've got serious momentum in the market: more than 30,0...SuggestedFull timeWork visaFlexible hoursShift work$130k - $280k
...includes solutions for video security, access control, air quality... ..., intercoms, and visitor management. We’ve got serious momentum... ...* Partner closely with engineering and product teams to improve... ...features, and strategies; * Coding ability. You will sometimes...SuggestedFull timeWork visaFlexible hoursShift work$145k - $240k
...SuperDial is building the automation engine that fixes revenue cycle management. We work with leading MSOs, DSOs,... ...environments and mission critical workflows, security is a first-principles priority.... .... Define and enforce secure coding practices, CI/CD controls, and...Suggested$130k - $280k
...includes solutions for video security, access control, air quality... ...alarms, intercoms, and visitor management. We've got serious... ...As an embedded security engineer on the Device Security Team,... ...participate in security design & code reviews. Explore innovative...Full timeWork visaFlexible hoursShift work$245k - $306.5k
...leader in Intelligent Content Management. Our platform enables... ...the entire content lifecycle, secure critical content, and transform... ...a Staff Enterprise Security Engineer who will be a part of our Enterprise... ...scripting, infrastructure-as-code, and orchestration platforms...Live inWork at officeImmediate startShift work3 days per week$216.68k - $269.17k
...to create safer, more civil shared experiences for everyone. Be a part of Roblox Corporation as a Senior Security Software Engineer in Vulnerability Management. Join our dedicated team to ensure the security of our platform. You will work on scaling vulnerability...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...looking for a highly skilled PSIRT Engineer to lead the vulnerability... ...You will own the lifecycle of security vulnerabilities affecting our... ..., Triage & Validation Manage intake from bug bounty... ...understanding of CI/CD workflows, code structure, and software engineering...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$170.6k - $390k
...to grow your career in information security! The opportunity The Senior Network... ...Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role... ...Transformation Script Writing/Coding abilities Proficiency in Security...Summer holidayRemote workFlexible hours$269.17k - $326.06k
...civil shared experiences for everyone. The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production... ...balancing deep technical work (threat modeling, code review, penetration testing) with systemic...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...Offensive Security Engineer Replit is the agentic software creation platform that enables anyone to build applications using natural language... ...about perimeter defense; it's about the integrity of the code that powers millions of environments. In this role, you will...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$180k - $220k
...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative... ...encryption, identity and access management, secure API gateways, secure model... ...Proficiency with infrastructure-as-code using Terraform and Python, including experience...$80 per hour
...organization in autonomous mobility, is seeking a dedicated Network Security Engineer to join their dynamic team. As a Network Security Engineer,... ...IT, Product, and Operations to enhance security measures. Manage and support AWS network security services, including AWS...Weekly payTemporary workRemote workFlexible hours$269.17k - $326.06k
...experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will... ...organization and report to the Senior Manager of Infrastructure Security. You will... ...Have: ~5+ years of experience writing code and/or relevant technical experience....Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$326.06k - $385.05k
...shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security... ...autonomous agentic workflows. Test application code following the OWASP Testing Methodology. Mentor...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$293.8k - $343.34k
...everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security... ..., reporting directly to the Senior Manager of Enterprise Security Engineering. You... ...or operating workflows using low-code and no-code orchestration platforms....Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$137.86k - $240k
...Product Security Engineer, Cryptography & PKI San Carlos, CA (on-site) About 1X We build... ...systems. You Will Design and manage end-to-end cryptographic services,... ...destruction Secure build systems and code-signing workflows Develop factory provisioning...Local areaRemote work- ...combined experience in software development, security engineering and security regulatory and compliance... ...assessment • Experience with secure coding practices, vulnerability remediation,... ...Able to identify Identity and Access management attacks • Data collection, storage,...
$137.86k - $240k
...Product Security Engineer, Operating System San Carlos, CA (on-site) About 1X We build... ...systems Contribute and ship C/C++ code (or similar) to production environments... ...access control and Linux permissions management Solid understanding of CI/CD security...Local area$230k - $275k
...fast as possible. Zipline’s security problems aren’t “website got... ...hats, and collaborates across engineering disciplines. You’ll join a small... ...like the NIST AI Risk Management Framework (including a profile... ...controls, secrets management, and code review patterns that don’t...InternshipWork at officeLocal area- ...About the Role We're hiring a hands-on Engineering Manager to build and lead Replit's Anti-Abuse... ...You'll partner across Support, Legal, Security, Infrastructure, and the Money and Growth... ...time. Ship as a hands-on EM: Stay in the code. Use the latest AI coding tools (...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$205k - $275k
...Application Security Engineer Opportunity We're hiring an Application Security Engineer to work hands... ...practitioner role; you'll spend your time in code, in tooling, and in design reviews, not writing strategy decks or managing people. You'll report to our security...Home officeFlexible hours- ...Job Description: We are seeking an experienced Network Security Engineer who will be responsible for helping ensure the security of our... ...IT, Product, and Operations teams. Experience with change management and a focus on customer experience as a key component of...Remote work
- ...professional responsible for helping ensure the security of our customers, staff, systems,... ...~4 years of Network Security Engineer experience supporting production environments... ...Qualifications Experience with change management Focus on customer experience as a key...Work experience placementImmediate startRemote work
- ...Senior Security Engineer We're a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer,... ...Protect sensitive data through strong controls for access management, encryption, and secure data handling. Identify, assess,...Permanent employmentFull timeLocal areaRemote work3 days per week
$200k - $300k
...Staff Backend Engineer - Device Security San Mateo, CA United States Who We Are Verkada is transforming how organizations protect their... ..., air quality sensors, alarms, intercoms, and visitor management. We've got serious momentum in the market: more than 30...Full timeWork visaFlexible hoursShift work$195k - $300k
...Lead Application Security Engineer San Mateo, CA (Hybrid) Eve is redefining legal technology... .... You'll review designs, write code, build automation, harden systems, and... ...threat modeling, code review, vulnerability management, and secure deployment. Partner with...Temporary workWork at officeLocal areaFlexible hours$158.9k - $238.3k
...person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team... ..., building, development, testing, and management of security tools and processes that... ...applications and controls Write code to automate security processes which seamlessly...- ...Bloom Talent Partners is seeking a Cloud Security Engineer in San Mateo, California. The ideal candidate will focus on automating security measures and developing secure coding practices within cloud environments. This role requires expertise in Docker, Kubernetes, and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Vuln Management (Code). Be the first to apply!
- senior application security engineer San Mateo, CA
- sr information security engineer San Mateo, CA
- security engineer San Mateo, CA
- aws cloud security engineer San Mateo, CA
- network security engineer San Mateo, CA
- senior cloud security engineer San Mateo, CA
- IT security engineer San Mateo, CA
- information technology security engineer San Mateo, CA
- security software engineer San Mateo, CA
- health information management work from home San Mateo, CA


