Security Engineer Incident Response

Replit is an agentic AI software-creation platform for creating, launching, and growing apps, websites, tools, and businesses through natural language.

Series D0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/25/2026

Foster City, United States
About Replit

Replit combines an AI agent with integrated application infrastructure—including authentication, databases, hosting, monitoring, integrations, and enterprise controls—to let users build and deploy software from one workspace.

View jobs by Replit

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will lead security incidents from detection and triage through containment, recovery, and review. You will investigate cloud, container, identity, and application activity; coordinate response stakeholders; build automation and response tooling; maintain playbooks and integrations; improve detections and logging; drive remediation; and run readiness exercises.

Requirements

  • Experience leading or serving as technical lead on security incidents in a cloud or SaaS environment
  • Hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis
  • Proficiency with Python, Go, or Bash for investigation and automation
  • Knowledge of Google Cloud Platform security, including IAM, audit logging, GKE, and networking
  • Knowledge of Kubernetes and containers
  • Understanding of identity systems, SaaS architectures, and cloud attack paths
  • Familiarity with software engineering fundamentals, CI/CD pipelines, and package ecosystems
  • Understanding of incident-response frameworks, vulnerability lifecycle, and exploitability analysis

Responsibilities

  • Lead security incidents from detection and triage through containment, eradication, recovery, and post-incident review
  • Coordinate incident response across Security, SRE, Engineering, Legal, and leadership
  • Communicate incident status, impact, and risk to technical and executive audiences
  • Participate in the security on-call rotation
  • Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers
  • Determine incident scope, root cause, attacker behavior, and blast radius
  • Assess emerging threats and potential impact
  • Build scripts, automations, and tools for triage, evidence collection, containment, and response
  • Develop and maintain response playbooks and runbooks
  • Integrate response workflows with SIEM, SOAR, ticketing, and chat tooling
  • Improve detections, logging coverage, and visibility from incident findings
  • Lead post-incident reviews and drive remediation to completion
  • Run tabletop exercises and simulations

Benefits

  • Equity
  • 401(k) program with a 4% match
  • Health, dental, vision, and life insurance
  • Short-term and long-term disability insurance
  • Paid parental, medical, and caregiver leave
  • Flexible time off and holidays
  • Commuter benefits
  • Monthly wellness stipend
  • In-office setup reimbursement
  • Quarterly team gatherings
  • In-office amenities