Security Engineer Incident Response
Replit is an agentic AI software-creation platform for creating, launching, and growing apps, websites, tools, and businesses through natural language.
Maintainer signals as of 9/25/2026
Funding history
About Replit
Replit combines an AI agent with integrated application infrastructure—including authentication, databases, hosting, monitoring, integrations, and enterprise controls—to let users build and deploy software from one workspace.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will lead security incidents from detection and triage through containment, recovery, and review. You will investigate cloud, container, identity, and application activity; coordinate response stakeholders; build automation and response tooling; maintain playbooks and integrations; improve detections and logging; drive remediation; and run readiness exercises.
Requirements
- Experience leading or serving as technical lead on security incidents in a cloud or SaaS environment
- Hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis
- Proficiency with Python, Go, or Bash for investigation and automation
- Knowledge of Google Cloud Platform security, including IAM, audit logging, GKE, and networking
- Knowledge of Kubernetes and containers
- Understanding of identity systems, SaaS architectures, and cloud attack paths
- Familiarity with software engineering fundamentals, CI/CD pipelines, and package ecosystems
- Understanding of incident-response frameworks, vulnerability lifecycle, and exploitability analysis
Responsibilities
- Lead security incidents from detection and triage through containment, eradication, recovery, and post-incident review
- Coordinate incident response across Security, SRE, Engineering, Legal, and leadership
- Communicate incident status, impact, and risk to technical and executive audiences
- Participate in the security on-call rotation
- Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers
- Determine incident scope, root cause, attacker behavior, and blast radius
- Assess emerging threats and potential impact
- Build scripts, automations, and tools for triage, evidence collection, containment, and response
- Develop and maintain response playbooks and runbooks
- Integrate response workflows with SIEM, SOAR, ticketing, and chat tooling
- Improve detections, logging coverage, and visibility from incident findings
- Lead post-incident reviews and drive remediation to completion
- Run tabletop exercises and simulations
Benefits
- Equity
- 401(k) program with a 4% match
- Health, dental, vision, and life insurance
- Short-term and long-term disability insurance
- Paid parental, medical, and caregiver leave
- Flexible time off and holidays
- Commuter benefits
- Monthly wellness stipend
- In-office setup reimbursement
- Quarterly team gatherings
- In-office amenities
