Replit
Product Security Engineer (PSIRT- Product Security Incident Response Team)
Remote Security role with clear candidate location fit.
PostedApr 20, 2026
Eligible countries1 accepted country
Seniority signalOpen level
Work settingRemote
Accepted candidate locations
USA
Role overview
Product Security Engineer (PSIRT- Product Security Incident Response Team)
Requirements and responsibilities
Readable role content extracted into sections for faster review.
Vulnerability Intake, Triage & Validation
- Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
- Independently validate, reproduce, severity-score, and document findings.
- Identify duplicates and maintain a clean vulnerability records pipeline.
- Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).
Remediation Coordination & SLA Management
- Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
- Provide detailed reproduction steps, proof-of-concepts, and technical analyses.
- Track SLAs, remediation progress, regression testing, and systemic improvements.
- Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.
Bug Bounty & Vulnerability Disclosure Program Management
- Design and evolve the bug bounty program, including scope, rules, and reward structures.
- Manage platform selection, private vs. public launches, and community engagement.
- Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.
- Determine reward payouts, bonus decisions, and recognition for top contributors.
Coordinated Disclosure & CVE Management
- Lead the coordinated vulnerability disclosure process for internal and external findings.
- Negotiate disclosure timelines with researchers and partners.
- Coordinate CVE assignments and publications, and prepare customer/public advisories.
Required Skills
- Experience running or triaging for bug bounty programs (HackerOne ideally).
- Strong ability to triage, validate, and reproduce vulnerabilities independently.
- Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
- Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
- Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.
Nice to haves
- Scripting or automation experience (Python, Go, Bash).
- Pentesting background or exposure to offensive security work.
- Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
- Experience authoring public advisories or CVE writeups.
- Hands-on experience with SIEM, Cloud Logging, and investigative tooling.
Nice to haves
- Meet the Replit Agent
- Replit: Make an app for that
- Replit Blog
- Amjad TED Talk
Nice to haves
- Operating Principles
- Reasons not to work at Replit
Similar roles
Keep a backup shortlist.
Stack
Use these tags to compare similar remote roles.
Location eligibility
Candidates should apply only when their profile country is listed here.
Your profileCountry not setSign in to check your country against this role.
Hiring flow
WithMira shows the role, then sends candidates to the company application.
1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.