Security Engineer - Incident Response
$230k - $360kReplit
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We're looking for a Security Engineer with deep incident response experience to help defend Replit, a fast-moving, cloud-native AI vibe-coding platform. You'll be the person who takes charge when something goes wrong. You'll lead investigations from first signal to root cause, coordinate containment across Security, SRE, and Engineering, and keep stakeholders informed while the incident is moving fast.
This isn't a pure responder role. We want a well-rounded security engineer who has run real incidents and wants to make the next one faster. You'll write the scripts, automations, and tooling that take manual work out of triage, evidence collection, and containment. You'll also turn lessons from each incident into better detections, playbooks, and platform hardening.
Responsibilities
Incident Response
Serve as incident commander or technical lead for security incidents, from detection and triage through containment, eradication, recovery, and post-incident review.
Coordinate response across Security, SRE, Engineering, Legal, and leadership. Drive decisions under pressure and keep a clear record of actions taken.
Communicate incident status, impact, and risk clearly to technical and executive audiences.
Participate in and help shape the security on-call rotation.
Investigation & Forensics
Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, Cloud Logging, telemetry, and host and container artifacts.
Determine scope, root cause, attacker behavior, and blast radius for confirmed incidents.
Quickly assess whether emerging threats (0-days, active exploitation campaigns, bug bounty findings, customer reports) apply to Replit, and whether we're already affected.
IR Automation & Tooling
Build scripts, automations, and tools (Python, Go, Bash, or directly on Replit) that speed up response, such as automated enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage.
Develop and maintain response playbooks and runbooks, and automate them where possible.
Integrate response workflows with SIEM, SOAR, ticketing, and chat tooling to cut time-to-contain.
Detection & Continuous Improvement
Turn incident findings into new or improved detections, logging coverage, and visibility.
Lead blameless post-incident reviews and drive remediation items to completion.
Run tabletop exercises and simulations to test readiness and find gaps.
Required Skills & Experience
Proven experience leading or serving as technical lead on security incidents in a cloud or SaaS environment.
Strong hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis. Comfortable working through large datasets under time pressure.
Proficiency writing production-quality scripts or tools in Python, Go, or Bash for investigation and automation.
Solid knowledge of cloud architecture and security, especially Google Cloud Platform (IAM, audit logging, GKE, networking).
Working knowledge of Kubernetes and containers, including how to investigate and contain compromised workloads.
Understanding of identity systems, SaaS architectures, and common cloud attack paths (credential theft, privilege escalation, supply chain, token abuse).
Familiarity with software engineering fundamentals, CI/CD pipelines, and package ecosystems, so you can work effectively with Engineering on code-level fixes.
Understanding of IR frameworks and lifecycle (for example NIST 800-61), plus the vulnerability lifecycle and exploitability analysis.
Preferred Qualifications
Experience building or operating SOAR or other response automation platforms.
Digital forensics experience with cloud, Linux hosts, or containers.
Experience with threat intelligence, threat hunting, or security research.
Experience with bug bounty programs or coordinated vulnerability disclosure.
Familiarity with detection-as-code practices and writing detection rules.
Experience in fast-paced, cloud-native, or AI/ML-driven environments.
Relevant certifications (such as GCIH, GCFA, GCFR), or equivalent hands-on experience.
What We Value
Curiosity & initiative: Strong desire to understand attacker behaviors, emerging threats, and how they apply to real-world systems.
Speed & analytical rigor: Ability to quickly assess high-risk vulnerabilities with clear, evidence-based reasoning.
Collaboration: Comfort working across cross-functional teams spanning Security, SRE, Engineering, and Infrastructure.
Clear communication: Ability to explain findings, risks, and mitigation strategies to stakeholders at all levels.
Ownership mindset: Takes initiative to drive investigations, improvements, and remediations to completion.
Continuous learning: Passion for staying up to date on new vulnerabilities, exploit trends, and cloud-native security best practices.
Full-Time Employee Benefits Include:
Competitive Salary & Equity
401(k) Program with a 4% match ( US Only )
⚕️ Health, Dental, Vision and Life Insurance
Short Term and Long Term Disability
Paid Parental, Medical, Caregiver Leave
Flexible Time Off (FTO) + Holidays
Commuter Benefits ( In-Office & US Only )
Monthly Wellness Stipend
Autonomous Work Environment
In Office Set-Up Reimbursement ( In-Office Only )
Quarterly Team Gatherings
☕ In Office Amenities ( In-Office Only )
Want to learn more about what we are up to?
Self-driving Company
Replit Agent at Scale
AI Adoption
Build Open-Source Apps
Interviewing + Culture at Replit
Operating Principles
Reasons not to work at Replit
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
- ...Responsibilities Lead security incidents from detection and triage through containment, eradication, recovery, and post-incident review. Coordinate incident response across Security, SRE, Engineering, Legal, and leadership while communicating status, impact, and...SuggestedFull timeTemporary workWork at officeFlexible hours
$209k - $313k
..., and other digital services.Snap Security teams protect the trust and safety... ...’re looking for a Senior Security Engineer to join our Detection and Response (D&R) team!What you’ll do:Design,... ...with multiple Snap Inc. teams during incidents and drive response effortsIdentify...SuggestedFull timeLive inWork at officeLocal area$146k - $172k
...high, and so are the rewards. About the TeamThe Security Operations (SecOps) team at Robinhood... ...cybersecurity industry!About the RoleAs a Senior Security Engineer (IC5) on the Detection & Response team, you will drive our incident response strategy and build robust detection...SuggestedWork at officeFlexible hoursShift work3 days per week- ...Location Type Hybrid Department Engineering Cloud & Security Security About Beacon AI We’re... ...our team. In this role, you will be responsible for ensuring the security and... ...to commercial and DoD customers. Incident Response: Lead incident response efforts...SuggestedPermanent employmentFull timeWork at officeLocal areaRemote work3 days per week
$190k - $230k
Security isn't just a checkbox at Delight.ai. It's the foundation everything... ...about security the way our engineers think about product: automate what... ...Develop AI-assisted detection and response workflows, automating alert triage, incident timelines, and routine reporting...SuggestedTemporary workWork at officeRemote workFlexible hoursShift work3 days per week$209k - $313k
...Saturn, and other digital services.Snap Security teams protect the trust and safety of... ...forefront.We’re looking for a Security Engineer to join our Offensive Security Team! What... ..., and contributing to high-stakes incident response efforts.Explore novel research topics relevant...Full timeLive inWork at officeLocal area- ...speeds.About You and The Role Product security at Zipline protects systems that directly... ...and field-ops teams. Expect hands-on engineering work, prioritized ownership of... ...regression prevention.Build and harden incident response for product incidents: author playbooks...Local area
$196.75k - $243.29k
...more civil shared experiences for everyone.As a Senior Security Engineer on the Detection and Response (D&R) team at Roblox, you’ll protect our user... ...data platforms, and respond alongside the team during incidents. This is a hybrid in-office role in San Mateo.You Will...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$123k - $230k
...Security Engineer Austin, Texas, United States; South San Francisco, California, United... ...by building detections, responding to incidents, and hardening systems. You will threat... ...and fix them. Job Description and Responsibilities: Run and improve security...Full timeTemporary workFlexible hours$180.6k - $289.3k
...you.Job DescriptionVisa’s Cyber Security team is seeking a Cyber Security Engineer to design, build, and operate large... ...’s multi‑cloud ecosystem.Key Responsibilities:Security Engineering & Platform... ...manual intervention and accelerate incident response workflows.GenAI &...Full timePart timeWork experience placementWork at officeLocal areaRemote work$269.17k - $326.06k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone.The Security organization at Roblox is responsible for designing and engineering secure systems from inception through production. We define security standards, build scalable...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$146.54k - $189.64k
....Leads and governs DOJ Data Security Program (DSP) IAM controls,... ...and execution, including role engineering, role lifecycle management,... ...access request fulfillment, incident/problem management, and operational... ...the disclosure is (a) in response to a formal complaint or...Full timeFor contractorsLocal area$10 per hour
...environment? Come join us. All security disciplines work under the... ...and tooling that hundreds of engineers around the world rely on... ...theft before they turn into incidents. Endpoint & device lifecycle... ...our EDR stack's detection and response coverage across the fleet....Work at officeImmediate startRelocationRelocation packageFlexible hours$198k - $238k
...Technology and Applications - Information Security /Full-time /HybridZoox's Network... ...the company — from corporate offices to engineering labs and product/mission environments.... ...applications, analyzing resumes, or assessing responses and identifying potential...Full timeTemporary workRemote workRelocation package$115k - $140k
...Qualys is a leading provider of cloud-based security and compliance solutions, processing... ...We are seeking a Senior Security Engineer - AI/ML who sits at the intersection of... ...into production hardening strategies. Key Responsibilities Build Build and deploy GenAI applications...Full timeFlexible hours$135k - $200k
Palo Alto, CAInformation Security /Full-time /HybridA World-Changing... ...a Senior Identity Security Engineer on Palantir's Identity... ...The Identity Security team is responsible for all identity types at Palantir... ..., offensive security, or incident response background -...Full timeWork experience placementWork at officeRemote workWork from homeRelocation packageShift work$146k - $172k
...accountability, and a strong focus on security and ethics in everything we... ...a Staff Offensive Security Engineer, you will plan and execute... ...to strengthen detection and response capabilities. You will help... ...adversarial simulations and improve incident readinessCommunicate findings...Work at officeShift work3 days per week$196.75k - $243.29k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone.As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our defense capabilities. Working...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...Security Engineer Poseidon is an AI data infrastructure company focused on sourcing and delivering high-quality real-world data for... ...Poseidon and PIP Labs, including monitoring, alert triage, incident response and remediation. Secure and administer our AWS...
- Engineering • Full-time • San Francisco; Palo Alto, CA Apply Our mission is to automate... ..., and shipping code. About the Role Security GRC Engineers design, implement, and scale... ...and AI governance terms. Support incident response communications - draft and review customer...Full timeContract workWork at office
$200k - $300k
...includes solutions for video security, access control, air quality... ...scientists, hardware engineers and experienced founders who... ...commitment to using technology responsibly. We believe keeping data private... ...data enrichment and incident response workflowsFacilitate...Full timeWork visaFlexible hoursShift work- ..., CA. We are unable to work with third-party companies for this role. Title: Network Security Engineer - Contract Duration: 1 year (likely extension) Responsibilities Design, implement, and support network security solutions, including firewalls, IDS/IPS...Contract workRemote work
$100k - $128k
...Time, 35 hours/week, fully onsite The Physical Security Systems Engineer is a technical operations role responsible for the day-to-day operation, troubleshooting,... ...troubleshooting, system configuration, and real-time incident response - including monitoring, analysis,...Full timeRemote workFlexible hours$251k - $377k
...Saturn, and other digital services.Snap Security teams protect the trust and safety of... ....We're looking for a Security Engineering Manager to lead our Production Security... ...libraries, and participate directly in incident response for production environments.Drive identification...Full timeLive inWork at officeLocal area- ...Information Security Consultant We have an immediate opening for an information security consultant. Candidate must... ...-Do Attitude Secondary Skills (Preferred) Incident Response Security Engineering Project Management For immediate response and...Immediate start
$130k - $165k
23andMe Research Institute is looking for an experienced Security Operations Engineer to join our Security Operations team. In this role you will lead security incident response as Incident Commander, triage and investigate alerts, and build the detection and automation...Local area$241k - $298k
...DescriptionWe are looking for a Principal Engineer — Product & Application Security to be the top technical authority... ...againstVulnerability Management & Incident ResponseServe as the top technical... ...strategy for the bug bounty and responsible-disclosure programTechnical...Flexible hoursShift work$251.09k - $306.73k
..., more civil shared experiences for everyone.As a Senior Security Software Engineer on the IAM team at Roblox, you'll build the next generation... ....Have the independence, opportunity, and end-to-end responsibility to develop security services within the Roblox infrastructure...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$147k - $184.8k
...geographic location.Position Summary:The AI Security Engineer will be a key member of the “Structure Brain” initiative, responsible for designing, implementing, and... ...controls in AWS.Monitor and respond to security incidents within the AI/ML platform.AI Governance and...Contract workWork at officeRemote work$165k - $280k
...goal of enabling human life on Mars.SR. NETWORK SECURITY ENGINEERSpaceX is looking for a Sr. Network Security Engineer to design, implement, and operate security... ...possess the ingenuity to excel in this position.RESPONSIBILITIES:Design, implement, and support network...Permanent employmentTemporary workRemote workFlexible hoursWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Incident Response. Be the first to apply!
- senior cloud security engineer Foster, CA
- aws cloud security engineer Foster, CA
- sr information security engineer Foster, CA
- network security engineer Foster, CA
- information technology security engineer Foster, CA
- security engineer Foster, CA
- IT security engineer Foster, CA
- application security engineer
- principal security engineer
- senior cloud security engineer


