Security Engineer - Vuln Management (Code)
Mid-level AppSec Vulnerability Management Engineer who identifies application vulnerabilities, manages SBOM and supply chain security, and drives compliance tracking for SOC 2, ISO 27001, and PCI-DSS. Requires 5+ years in AppSec/DevSecOps with strong coding skills in JS/TS, Python, and Go.
About the job
What You'll Do
Core Responsibilities
- Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure.
- Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals.
- Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture.
- Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security.
- Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws.
- Tooling Integration: Configure and tune automated security testing tools within CI/CD pipelines to reduce false positives for engineering teams.
- Incident Response Support: Assist Incident Response teams during active breaches or security incidents. Help develop and implement immediate, real-time code or infrastructure countermeasures.
Required Skills & Experience
- 5 years of experience in Application Security, DevSecOps, or Software Engineering roles.
- Solid foundational experience working in a software development capacity.
- Ability to read, understand, and safely patch security flaws in JavaScript/TypeScript, Python, and Go.
- Strong familiarity with build systems, package managers, and compilation workflows across multiple languages and frameworks.
- Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx).
- Understanding of how vulnerability management maps to security compliance frameworks like SOC 2, ISO 27001, or NIST.
What We Value
- Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.
- Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
- Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
- Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.
Skills
JavaScript, TypeScript, Python, Go, SAST, Sca, Semgrep, Snyk, Sbom, SOC 2, ISO 27001, Pci-Dss
Similar jobs
Security Engineering jobsThis role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.