Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Engineer

Replit

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the role

We are looking for a senior-level Offensive Security Engineer to serve as a high-impact "adversary-in-residence" for Replit's cloud-native platform. At Replit, security isn't just about perimeter defense; it's about the integrity of the code that powers millions of environments.

In this role, you will lead advanced "whitebox" penetration testing engagements-diving deep into our source code to identify systemic weaknesses, logic flaws, and architectural gaps. You will simulate sophisticated adversary tactics across our web applications, APIs, and containerized infrastructure, ensuring that our AI-integrated development environment remains the most secure place for the world's software to live.
What You'll Do
  • Lead Whitebox Penetration Testing: Execute end-to-end testing with full access to source code. You will perform manual code-level inspections to uncover complex logic flaws and authorization bypasses that automated tools miss.
  • Simulate Adversarial Attacks: Conduct Red and Purple team engagements across our cloud-native stack (K8s, Docker), simulating how a sophisticated actor might move from a code-level exploit to infrastructure-wide impact.
  • Secure AI-Enabled Systems: Perform offensive testing on LLM-backed applications and agentic AI workflows, focusing on prompt injection, data leakage, and abuse of AI-driven components.
  • Vulnerability Research & Chaining: Identify, exploit, and demonstrate realistic business risk by chaining vulnerabilities-from the application layer down through our internal trust boundaries.
  • Build Offensive Tooling: Contribute to internal security frameworks and build AI-assisted testing tools to automate the discovery of common bug classes while maintaining deep manual testing depth.
  • Partner with Engineering: Work closely with product teams and security architects to explain root causes, influence design guardrails, and triage high-priority findings from our Bug Bounty (HackerOne) program.
Required Skills & Experience
  • Experience: 7+ years of hands-on experience in penetration testing, offensive security, or vulnerability research.
  • Code Fluency: You are a practitioner of whitebox testing. You can navigate large codebases and have a deep understanding of modern application architectures and secure coding pitfalls.
  • Cloud-Native Context: You are comfortable in a cloud-native environment. While your focus is the code, you understand how it interacts with Kubernetes, Docker, and hybrid cloud infrastructure.
  • Engineering Skills: Strong proficiency in Go, Python, or TypeScript . You should be capable of writing custom scripts, payloads, and proof-of-concept exploits.
  • Adversarial Mindset: You enjoy the "hunt" and have a proven track record of manual exploitation beyond automated scanners.
  • Communicator: You can translate a complex code-level exploit into a clear narrative that helps engineering teams understand risk and prioritize fixes.
Bonus Qualifications
  • Public recognition on platforms like HackerOne or Bugcrowd.
  • Experience building or extending AI-based security testing tools.
  • Background in incident response or detection engineering from the defensive side.
  • Published CVEs or security research in the cloud-native or AI space.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.


Full-Time Employee Benefits Include:

Competitive Salary & Equity

401(k) Program with a 4% match (US Only)

Health, Dental, Vision and Life Insurance

Short Term and Long Term Disability

Paid Parental, Medical, Caregiver Leave

Flexible Time Off (FTO) + Holidays

Commuter Benefits (In-Office Only)

Monthly Wellness Stipend

Autonomous Work Environment

In Office Set-Up Reimbursement (In-Office Only)

Quarterly Team Gatherings

In Office Amenities (In-Office Only)

Want to learn more about what we are up to?
  • Meet the Replit Agent
  • Replit: Make an app for that
  • Replit Blog
  • Amjad TED Talk
Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in Foster, CA vacancy
  •  ...are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program...  ...platform. You will own the lifecycle of security vulnerabilities affecting our products...  ...Pentesting background or exposure to offensive security work. Familiarity with compliance... 
    Suggested
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    2 days ago
  • $115k - $140k

     ...Qualys is a leading provider of cloud-based security and compliance solutions, processing vast...  ...We are seeking a Senior Security Engineer - AI/ML who sits at the intersection of hands-on AI/ML engineering and offensive security research. You will both build andbreak... 
    Suggested
    Flexible hours

    Qualys

    Foster, CA
    3 days ago
  • $180k - $220k

     ...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative AI infrastructure. Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry. We've been independently benchmarked... 
    Suggested

    Fireworks AI

    San Mateo, CA
    3 days ago
  • $100k - $300k

     ...Embedded Security Engineer San Mateo Company Overview At Skild AI, we are building the world's first general purpose robotic intelligence...  ...cases for security controls, and actively participate in offensive security assessments. Responsibilities Conduct... 
    Suggested

    Skild AI

    San Mateo, CA
    4 days ago
  •  ...to application creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance... 
    Suggested
    Full time
    Temporary work
    Work at office
    Immediate start
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    2 days ago
  •  ...creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application... 
    Full time
    Temporary work
    Work at office
    Immediate start
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    4 days ago
  •  ...Network Security Engineer We are seeking an experienced Network Security Engineer who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data. The Network Security Engineer will support the implementation, maintenance... 
    Remote work

    Denken Solutions

    San Mateo, CA
    2 days ago
  • $385.05k

     ...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer in the Enterprise Security team, you will advance Roblox's Enterprise Security strategy by building the systems and integrations... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    10 days ago
  • $195k - $300k

     ...Lead Application Security Engineer San Mateo, CA (Hybrid) Eve is redefining legal technology for plaintiff law firms, and we're building...  ...with the evolving security landscape, especially AI-enabled offensive and defensive techniques, and translating that judgment into... 
    Temporary work
    Work at office
    Local area
    Flexible hours

    EVE Inc

    San Mateo, CA
    1 day ago
  • $326.06k - $385.05k

     ...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You will play a... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    6 days ago
  • $190k - $230k

     ...Job Description Job Description Security isn't just a checkbox at Delight.ai. It's the foundation everything else is built on. If...  ...feel understood, seen, and remembered. Why Enterprise Security Engineer We're building AI that handles real customer conversations... 
    Temporary work
    Work at office
    Remote work
    Flexible hours
    Shift work
    3 days per week

    Sendbird

    San Mateo, CA
    29 days ago
  • $130k - $280k

     ...platform that includes solutions for video security, access control, air quality sensors,...  ...About the role As an embedded security engineer on the Device Security Team, you'll work...  ...best practices. Perform red team/offensive assessments against firmware & devices.... 
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    1 day ago
  •  ...Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company — from corporate offices to engineering labs and product/mission environments. As a Senior or Staff Network Security Engineer, you will design, implement... 
    Temporary work
    Remote work
    Relocation package

    Zoox

    Foster, CA
    17 days ago
  •  ...'s degree in computer science, Cybersecurity, or related field • 8+ years of combined experience in software development, security engineering and security regulatory and compliance, with at least 5 years of experience in security engineering • Strong understanding... 

    Glow Networks

    San Mateo, CA
    2 days ago
  • $146k - $220k

     ...ethics at the center of everything we do. Expectations are high, and so are the rewards. Robinhood is looking for an Offensive Security Engineer who is passionate about Red Teaming, Adversarial Simulation, and breaking / fixing systems, to join the Red Team. The... 
    Work at office
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    more than 2 months ago
  • $293.8k - $343.34k

     ...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security strategy by shaping and evolving security architecture in alignment with... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    2 days ago
  • $230k - $275k

     ...centers to serve their customers as fast as possible. Zipline's security problems aren't "website got pwned" problems (though those...  ...environments, wears many hats, and collaborates across engineering disciplines. You'll join a small, high-ownership security team... 
    Internship
    Work at office
    Local area

    Zipline

    South San Francisco, CA
    29 days ago
  • $174k - $253k

    Google Inc. is seeking a Security Engineer in San Bruno, California to create a secure environment for users. Responsibilities include analyzing vulnerabilities, leading incident responses, and collaborating with software engineers to safeguard sensitive data. Candidates... 

    Google Inc.

    San Bruno, CA
    1 day ago
  • $216.68k - $269.17k

     ...unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Cloud Security Engineer, you will define and implement the security strategy and controls across our hybrid and multi-cloud environment. Embedded... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    9 days ago
  • $158.9k - $238.3k

     ...excellence and creativity. We are looking for an inspirational and hardworking person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team of innovative engineers who are unified in their mission to make PlayStation the best... 

    PlayStation Global

    San Mateo, CA
    2 days ago
  • $157k - $185k

     .... Expectations are high, and so are the rewards. The Security Operations (SecOps) team works to safeguard Robinhood and its...  ...risks before they affect customers. SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and... 
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    2 days ago
  •  ...Data Protection Security Engineer – Netskope Lead In this role, you’ll own the end-to-end deployment, configuration, and operational health of the Netskope environment while driving enterprise-wide DLP initiatives and zero-trust access strategies. You’ll partner closely... 

    Comrise

    San Mateo, CA
    12 hours ago
  • $200k - $350k

     ...The Role We're hiring a hands-on Staff Security Engineer to build the security foundation for a frontier AI platform serving enterprise customers - owning product/API security, enterprise security architecture, compliance readiness, and incident response as the... 
    Immediate start
    Flexible hours

    Inception LLC

    San Mateo, CA
    1 day ago
  • $180k - $258k

     ...Senior Security Engineer We're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our platforms are resilient against all threats while meeting compliance requirements... 
    Flexible hours

    Candid Health

    Menlo Park, CA
    4 days ago
  • $157k - $185k

     ...performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Security Engineering team builds systems and practices that help protect Robinhood’s platform, infrastructure, and customers at scale. The team... 
    Permanent employment
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    1 day ago
  • $187k - $220k

     ...ethics at the center of everything we do. Expectations are high, and so are the rewards. At Robinhood, we view security as an engineering and design challenge, not an administrative one. We are looking for a lead architect for our next-generation automated defense... 
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    12 hours ago
  •  ...Information Security Consultant We have an immediate opening for an information security consultant. Candidate must have the following...  ...Skills (Preferred) Incident Response Security Engineering Project Management For immediate response and interview... 
    Immediate start

    BayInfotech

    San Mateo, CA
    4 days ago
  • $174k - $253k

     ...equivalent practical experience. 5 years of experience with security assessments, security design reviews, or threat modeling. 5 years...  ...purpose languages. 5 years of experience with security engineering, computer and network security, and security protocols. Preferred... 

    Google Inc.

    San Bruno, CA
    1 day ago
  • A leading logistics company in South San Francisco seeks an experienced Security Engineer to own security for their application and cloud ecosystem. The candidate will work with engineering teams to enhance secure architecture and manage vulnerabilities. You should have... 

    Zipline International Inc.

    South San Francisco, CA
    1 day ago
  •  ...creation. About the Role We are looking for a Product Security Architect to serve as the subject matter expert for Replit's...  ...initiatives and providing deep subject matter expertise to both the engineering organization and executive leadership. What You'll Do... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!