# Security Engineer - Vuln Management (Infra) at Replit

- Company: Replit
- What the company does: Describe what you want. Replit builds it. Get a working app or website in minutes. No coding required. Backed by Y Combinator and a16z.
- Company website: https://replit.com
- Type: Startups
- Level: Mid level
- Location: Foster City, CA
- Work setup: Remote
- Pay: $210K to $270K base salary per year (USD)
- Posted: 2026-05-26
- Apply by: 2026-10-08
- Apply: https://jobs.ashbyhq.com/replit/4b290489-9ce6-45f9-bbc8-e1baa4bd8b6f
- Page: https://www.1752.vc/careers/jobs/replit-security-engineer-vuln-management-infra/

## About the role

We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks.

## What they're looking for

- Experience : 5 years of experience in Cloud Security, DevSecOps, or Systems Engineering roles
- Cloud Infrastructure Depth : Strong foundational experience working with multi-cloud environments (Deep GCP expertise preferred, with working knowledge of AWS or Azure)
- Posture Management & Scanning Tooling : Hands-on experience operating modern infrastructure security platforms such as Wiz, Orca, Prisma Cloud, Lacework, or cloud-native options (GCP Security Command Center)
- IaC and Automation Fluency : Strong proficiency with Infrastructure as Code platforms (Terraform, Pulumi) and GitOps deployment workflows. Ability to evaluate and configure IaC scanners like Checkov, Tfsec, or KICS
- Containerization & Orchestration : Deep understanding of Docker/container security and Kubernetes architectures (e.g., GKE, EKS), including runtime security, network policies, and workload identity
- Compliance Awareness : Understanding of how infrastructure configurations and vulnerability management map to security compliance frameworks like SOC 2, ISO 27001, CIS Benchmarks, or NIST

Tags: Engineering
