Offensive Security Engineer
Replit
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the role We are looking for a senior-level Offensive Security Engineer to serve as a high-impact "adversary-in-residence" for Replit's cloud-native platform. At Replit, security isn't just about perimeter defense; it's about the integrity of the code that powers millions of environments. In this role, you will lead advanced "whitebox" penetration testing engagements-diving deep into our source code to identify systemic weaknesses, logic flaws, and architectural gaps. You will simulate sophisticated adversary tactics across our web applications, APIs, and containerized infrastructure, ensuring that our AI-integrated development environment remains the most secure place for the world's software to live.What You'll Do
- Lead Whitebox Penetration Testing: Execute end-to-end testing with full access to source code. You will perform manual code-level inspections to uncover complex logic flaws and authorization bypasses that automated tools miss.
- Simulate Adversarial Attacks: Conduct Red and Purple team engagements across our cloud-native stack (K8s, Docker), simulating how a sophisticated actor might move from a code-level exploit to infrastructure-wide impact.
- Secure AI-Enabled Systems: Perform offensive testing on LLM-backed applications and agentic AI workflows, focusing on prompt injection, data leakage, and abuse of AI-driven components.
- Vulnerability Research & Chaining: Identify, exploit, and demonstrate realistic business risk by chaining vulnerabilities-from the application layer down through our internal trust boundaries.
- Build Offensive Tooling: Contribute to internal security frameworks and build AI-assisted testing tools to automate the discovery of common bug classes while maintaining deep manual testing depth.
- Partner with Engineering: Work closely with product teams and security architects to explain root causes, influence design guardrails, and triage high-priority findings from our Bug Bounty (HackerOne) program.
- Experience: 7+ years of hands-on experience in penetration testing, offensive security, or vulnerability research.
- Code Fluency: You are a practitioner of whitebox testing. You can navigate large codebases and have a deep understanding of modern application architectures and secure coding pitfalls.
- Cloud-Native Context: You are comfortable in a cloud-native environment. While your focus is the code, you understand how it interacts with Kubernetes, Docker, and hybrid cloud infrastructure.
- Engineering Skills: Strong proficiency in Go, Python, or TypeScript . You should be capable of writing custom scripts, payloads, and proof-of-concept exploits.
- Adversarial Mindset: You enjoy the "hunt" and have a proven track record of manual exploitation beyond automated scanners.
- Communicator: You can translate a complex code-level exploit into a clear narrative that helps engineering teams understand risk and prioritize fixes.
- Public recognition on platforms like HackerOne or Bugcrowd.
- Experience building or extending AI-based security testing tools.
- Background in incident response or detection engineering from the defensive side.
- Published CVEs or security research in the cloud-native or AI space.
Full-Time Employee Benefits Include: Competitive Salary & Equity 401(k) Program with a 4% match (US Only) Health, Dental, Vision and Life Insurance Short Term and Long Term Disability Paid Parental, Medical, Caregiver Leave Flexible Time Off (FTO) + Holidays Commuter Benefits (In-Office Only) Monthly Wellness Stipend Autonomous Work Environment In Office Set-Up Reimbursement (In-Office Only) Quarterly Team Gatherings In Office Amenities (In-Office Only) Want to learn more about what we are up to?
- Meet the Replit Agent
- Replit: Make an app for that
- Replit Blog
- Amjad TED Talk
- Operating Principles
- Reasons not to work at Replit
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in Foster, CA vacancy
- ...are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program... ...platform. You will own the lifecycle of security vulnerabilities affecting our products... ...Pentesting background or exposure to offensive security work. Familiarity with compliance...SuggestedFull timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$115k - $140k
...Qualys is a leading provider of cloud-based security and compliance solutions, processing vast... ...We are seeking a Senior Security Engineer - AI/ML who sits at the intersection of hands-on AI/ML engineering and offensive security research. You will both build andbreak...SuggestedFlexible hours$180k - $220k
...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative AI infrastructure. Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry. We've been independently benchmarked...Suggested$100k - $300k
...Embedded Security Engineer San Mateo Company Overview At Skild AI, we are building the world's first general purpose robotic intelligence... ...cases for security controls, and actively participate in offensive security assessments. Responsibilities Conduct...Suggested- ...to application creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance...SuggestedFull timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
- ...creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application...Full timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
- ...Network Security Engineer We are seeking an experienced Network Security Engineer who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data. The Network Security Engineer will support the implementation, maintenance...Remote work
$385.05k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer in the Enterprise Security team, you will advance Roblox's Enterprise Security strategy by building the systems and integrations...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$195k - $300k
...Lead Application Security Engineer San Mateo, CA (Hybrid) Eve is redefining legal technology for plaintiff law firms, and we're building... ...with the evolving security landscape, especially AI-enabled offensive and defensive techniques, and translating that judgment into...Temporary workWork at officeLocal areaFlexible hours$326.06k - $385.05k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You will play a...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$190k - $230k
...Job Description Job Description Security isn't just a checkbox at Delight.ai. It's the foundation everything else is built on. If... ...feel understood, seen, and remembered. Why Enterprise Security Engineer We're building AI that handles real customer conversations...Temporary workWork at officeRemote workFlexible hoursShift work3 days per week$130k - $280k
...platform that includes solutions for video security, access control, air quality sensors,... ...About the role As an embedded security engineer on the Device Security Team, you'll work... ...best practices. Perform red team/offensive assessments against firmware & devices....Full timeWork visaFlexible hoursShift work- ...Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company — from corporate offices to engineering labs and product/mission environments. As a Senior or Staff Network Security Engineer, you will design, implement...Temporary workRemote workRelocation package
- ...'s degree in computer science, Cybersecurity, or related field • 8+ years of combined experience in software development, security engineering and security regulatory and compliance, with at least 5 years of experience in security engineering • Strong understanding...
$146k - $220k
...ethics at the center of everything we do. Expectations are high, and so are the rewards. Robinhood is looking for an Offensive Security Engineer who is passionate about Red Teaming, Adversarial Simulation, and breaking / fixing systems, to join the Red Team. The...Work at officeShift work3 days per week$293.8k - $343.34k
...technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security strategy by shaping and evolving security architecture in alignment with...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$230k - $275k
...centers to serve their customers as fast as possible. Zipline's security problems aren't "website got pwned" problems (though those... ...environments, wears many hats, and collaborates across engineering disciplines. You'll join a small, high-ownership security team...InternshipWork at officeLocal area$174k - $253k
Google Inc. is seeking a Security Engineer in San Bruno, California to create a secure environment for users. Responsibilities include analyzing vulnerabilities, leading incident responses, and collaborating with software engineers to safeguard sensitive data. Candidates...$216.68k - $269.17k
...unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Cloud Security Engineer, you will define and implement the security strategy and controls across our hybrid and multi-cloud environment. Embedded...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$158.9k - $238.3k
...excellence and creativity. We are looking for an inspirational and hardworking person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team of innovative engineers who are unified in their mission to make PlayStation the best...$157k - $185k
.... Expectations are high, and so are the rewards. The Security Operations (SecOps) team works to safeguard Robinhood and its... ...risks before they affect customers. SecOps partners closely with engineering and infrastructure teams to strengthen detection coverage and...Work at officeFlexible hoursShift work3 days per week- ...Data Protection Security Engineer – Netskope Lead In this role, you’ll own the end-to-end deployment, configuration, and operational health of the Netskope environment while driving enterprise-wide DLP initiatives and zero-trust access strategies. You’ll partner closely...
$200k - $350k
...The Role We're hiring a hands-on Staff Security Engineer to build the security foundation for a frontier AI platform serving enterprise customers - owning product/API security, enterprise security architecture, compliance readiness, and incident response as the...Immediate startFlexible hours$180k - $258k
...Senior Security Engineer We're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our platforms are resilient against all threats while meeting compliance requirements...Flexible hours$157k - $185k
...performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Security Engineering team builds systems and practices that help protect Robinhood’s platform, infrastructure, and customers at scale. The team...Permanent employmentWork at officeFlexible hoursShift work3 days per week$187k - $220k
...ethics at the center of everything we do. Expectations are high, and so are the rewards. At Robinhood, we view security as an engineering and design challenge, not an administrative one. We are looking for a lead architect for our next-generation automated defense...Work at officeFlexible hoursShift work3 days per week- ...Information Security Consultant We have an immediate opening for an information security consultant. Candidate must have the following... ...Skills (Preferred) Incident Response Security Engineering Project Management For immediate response and interview...Immediate start
$174k - $253k
...equivalent practical experience. 5 years of experience with security assessments, security design reviews, or threat modeling. 5 years... ...purpose languages. 5 years of experience with security engineering, computer and network security, and security protocols. Preferred...- A leading logistics company in South San Francisco seeks an experienced Security Engineer to own security for their application and cloud ecosystem. The candidate will work with engineering teams to enhance secure architecture and manage vulnerabilities. You should have...
- ...creation. About the Role We are looking for a Product Security Architect to serve as the subject matter expert for Replit's... ...initiatives and providing deep subject matter expertise to both the engineering organization and executive leadership. What You'll Do...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
Related searches
- senior cloud security engineer Foster, CA
- network security engineer Foster, CA
- security engineer Foster, CA
- IT security engineer Foster, CA
- information technology security engineer Foster, CA
- hardware security engineer
- endpoint security engineer
- associate security engineer
- senior cloud security engineer
- application security engineer


