Offensive Security Engineer
Replit
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the role We are looking for a senior-level Offensive Security Engineer to serve as a high-impact "adversary-in-residence" for Replit's cloud-native platform. At Replit, security isn't just about perimeter defense; it's about the integrity of the code that powers millions of environments. In this role, you will lead advanced "whitebox" penetration testing engagements-diving deep into our source code to identify systemic weaknesses, logic flaws, and architectural gaps. You will simulate sophisticated adversary tactics across our web applications, APIs, and containerized infrastructure, ensuring that our AI-integrated development environment remains the most secure place for the world's software to live.What You'll Do
- Lead Whitebox Penetration Testing: Execute end-to-end testing with full access to source code. You will perform manual code-level inspections to uncover complex logic flaws and authorization bypasses that automated tools miss.
- Simulate Adversarial Attacks: Conduct Red and Purple team engagements across our cloud-native stack (K8s, Docker), simulating how a sophisticated actor might move from a code-level exploit to infrastructure-wide impact.
- Secure AI-Enabled Systems: Perform offensive testing on LLM-backed applications and agentic AI workflows, focusing on prompt injection, data leakage, and abuse of AI-driven components.
- Vulnerability Research & Chaining: Identify, exploit, and demonstrate realistic business risk by chaining vulnerabilities-from the application layer down through our internal trust boundaries.
- Build Offensive Tooling: Contribute to internal security frameworks and build AI-assisted testing tools to automate the discovery of common bug classes while maintaining deep manual testing depth.
- Partner with Engineering: Work closely with product teams and security architects to explain root causes, influence design guardrails, and triage high-priority findings from our Bug Bounty (HackerOne) program.
- Experience: 7+ years of hands-on experience in penetration testing, offensive security, or vulnerability research.
- Code Fluency: You are a practitioner of whitebox testing. You can navigate large codebases and have a deep understanding of modern application architectures and secure coding pitfalls.
- Cloud-Native Context: You are comfortable in a cloud-native environment. While your focus is the code, you understand how it interacts with Kubernetes, Docker, and hybrid cloud infrastructure.
- Engineering Skills: Strong proficiency in Go, Python, or TypeScript . You should be capable of writing custom scripts, payloads, and proof-of-concept exploits.
- Adversarial Mindset: You enjoy the "hunt" and have a proven track record of manual exploitation beyond automated scanners.
- Communicator: You can translate a complex code-level exploit into a clear narrative that helps engineering teams understand risk and prioritize fixes.
- Public recognition on platforms like HackerOne or Bugcrowd.
- Experience building or extending AI-based security testing tools.
- Background in incident response or detection engineering from the defensive side.
- Published CVEs or security research in the cloud-native or AI space.
Full-Time Employee Benefits Include: Competitive Salary & Equity 401(k) Program with a 4% match (US Only) Health, Dental, Vision and Life Insurance Short Term and Long Term Disability Paid Parental, Medical, Caregiver Leave Flexible Time Off (FTO) + Holidays Commuter Benefits (In-Office Only) Monthly Wellness Stipend Autonomous Work Environment In Office Set-Up Reimbursement (In-Office Only) Quarterly Team Gatherings In Office Amenities (In-Office Only) Want to learn more about what we are up to?
- Meet the Replit Agent
- Replit: Make an app for that
- Replit Blog
- Amjad TED Talk
- Operating Principles
- Reasons not to work at Replit
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in Foster, CA vacancy
- ...PSIRT Engineer Replit is the agentic software creation platform that enables anyone to... ...platform. You will own the lifecycle of security vulnerabilities affecting our products and... ...Pentesting background or exposure to offensive security work. Familiarity with compliance...SuggestedFull timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$180k - $220k
...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative AI infrastructure. Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry. We've been independently benchmarked...Suggested$200k - $300k
...Staff+ Security Engineer, IT and Corporate Security San Mateo, CA United States Who We Are Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform that includes solutions for video security...SuggestedFull timeWork visaFlexible hoursShift work$269.17k - $326.06k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone. The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards, build scalable...SuggestedFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$100k - $300k
...Embedded Security Engineer San Mateo Company Overview At Skild AI, we are building the world's first general purpose robotic intelligence... ...cases for security controls, and actively participate in offensive security assessments. Responsibilities Conduct...Suggested- ...an experienced professional responsible for helping ensure the security of our customers, staff, systems, communications, and data. This... ...Skills & Qualifications ~4 years of Network Security Engineer experience supporting production environments ~4 years of IT...Work experience placementImmediate startRemote work
$80 per hour
...Our client, a leading organization in autonomous mobility, is seeking a dedicated Network Security Engineer to join their dynamic team. As a Network Security Engineer, you will be integral to supporting the security infrastructure that safeguards our customers, staff,...Weekly payTemporary workRemote workFlexible hours- ...Mid-Level Appsec Vulnerability Management Engineer We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong... ...development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify...Full timeTemporary workWork at officeImmediate startMonday to FridayFlexible hours
- ...Mid-Level Infrastructure Vulnerability Management Engineer Replit is the agentic software creation platform that enables anyone to... ...Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you...Full timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
- ...Senior Security Engineer We're a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer, more efficient, and more capable. Backed by top investors, we've secured a dozen Department of Defense contracts and partnered with...Permanent employmentFull timeLocal areaRemote work3 days per week
- ...Job Description: We are seeking an experienced Network Security Engineer who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data. The Network Security Engineer will support the implementation, maintenance...Remote work
$269.17k - $326.06k
...unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior Manager...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$326.06k - $385.05k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You will play a...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$195k - $300k
...Lead Application Security Engineer San Mateo, CA (Hybrid) Eve is redefining legal technology for plaintiff law firms, and we're building... ...with the evolving security landscape, especially AI-enabled offensive and defensive techniques, and translating that judgment into...Temporary workWork at officeLocal areaFlexible hours$130k - $280k
...platform that includes solutions for video security, access control, air quality sensors,... ...About the role As an embedded security engineer on the Device Security Team, you'll work... ...best practices. Perform red team/offensive assessments against firmware & devices....Full timeWork visaFlexible hoursShift work- ...'s degree in computer science, Cybersecurity, or related field • 8+ years of combined experience in software development, security engineering and security regulatory and compliance, with at least 5 years of experience in security engineering • Strong understanding...
$190k - $230k
...Security isn't just a checkbox at Delight.ai. It's the foundation everything else is built on. If you believe security should accelerate... ...understood, seen, and remembered. Why Enterprise Security Engineer We're building AI that handles real customer conversations...Temporary workWork at officeRemote workFlexible hoursShift work3 days per week$200k - $240k
...largest organizations to empower scientists, engineers, financial experts, product creators,... ...About the Role We are seeking a Security Engineer to evolve Snorkel's security posture... ...and Response (SOAR) playbooks Offensive security : penetration testing, red team...Local area$176k - $253k
...Senior Anti-Abuse Security Engineer At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don't just use tools;...Flexible hours$137.86k - $240k
...Product Security Engineer, Operating System San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role We are seeking a Product Security Engineer with expertise in operating...Local area$146k - $220k
...ethics at the center of everything we do. Expectations are high, and so are the rewards. Robinhood is looking for an Offensive Security Engineer who is passionate about Red Teaming, Adversarial Simulation, and breaking / fixing systems, to join the Red Team. The...Work at officeShift work3 days per week$293.8k - $343.34k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security strategy by shaping and evolving security architecture in alignment with...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$137.86k - $240k
...Product Security Engineer, Cryptography & PKI San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role As a Product Security Engineer specializing in cryptography...Local areaRemote work- ...Bloom Talent Partners is seeking a Cloud Security Engineer in San Mateo, California. The ideal candidate will focus on automating security measures and developing secure coding practices within cloud environments. This role requires expertise in Docker, Kubernetes, and...
$158.9k - $238.3k
...excellence and creativity. We are looking for an inspirational and hardworking person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team of innovative engineers who are unified in their mission to make PlayStation the best...$157k - $185k
.... Expectations are high, and so are the rewards. The Security Operations (SecOps) team works to safeguard Robinhood and its... ...risks before they affect customers. SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and...Work at officeFlexible hoursShift work3 days per week$180k - $235k
...Senior Cloud Security Architect, Security Engineering San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role As the Senior Cloud Security Architect, you will design...Local area$216.68k - $269.17k
...and helping to create safer, more civil shared experiences for everyone. Be a part of Roblox Corporation as a Senior Security Software Engineer in Vulnerability Management. Join our dedicated team to ensure the security of our platform. You will work on scaling vulnerability...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$137.86k - $240k
...Product Security Engineer, Cloud & Infrastructure San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people to solve labor shortages and create abundance. The Role As a Product Security Engineer focused on cloud and infrastructure...Local area$230k - $275k
...centers to serve their customers as fast as possible. Zipline’s security problems aren’t “website got pwned” problems (though those... ...startup environments, wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-ownership security team...InternshipWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
Related searches

