Senior Technical Program Manager, Security
Job description
About the role
Replit is on a mission to create a dynamic software development platform that empowers users globally to build applications using natural language. In this pivotal role, you will take charge of enhancing the security framework of our platform by spearheading the vulnerability management initiative. Your primary responsibility will be to ensure that security threats are systematically identified, prioritized, and addressed across all systems in a timely manner.
Key facts
What you'll do
- Lead and optimize the vulnerability management program, which includes processes for intake, severity assessment, establishing service level agreements (SLAs), and tracking remediation efforts for various asset types.
- Oversee the operations of the bug bounty program, which involves triaging reported vulnerabilities, managing payouts, and generating reports on the health of the program.
- Direct the remediation efforts for vulnerabilities found within the Google Cloud Platform (GCP) infrastructure, working closely with both engineering and security teams to ensure effective resolution.
- Manage the resolution of code and supply chain vulnerabilities that are flagged by security tools across engineering repositories, ensuring that security is integrated into the development lifecycle.
- Develop and sustain processes for assessing and monitoring the security posture of third-party Software as a Service (SaaS) applications utilized by the organization.
- Establish and uphold escalation protocols for critical or overdue findings, including processes for risk acceptance and exception handling.
- Collaborate with engineering managers and technical leads to incorporate remediation tasks into sprint planning, ensuring compliance with established SLAs.
- Create and maintain a centralized repository for tracking vulnerability status, aging, SLA compliance, and risk trends, complete with dashboards for leadership visibility.
- Support audit and compliance efforts (such as SOC 2 and ISO 27001) by ensuring that all necessary evidence related to vulnerability management is readily available.
- Drive process enhancements and automation initiatives to minimize manual efforts in triaging vulnerabilities and to expedite remediation timelines.
Requirements
- A minimum of 4 to 6 years of experience in technical program management, security program management, or security operations, with a focus on vulnerability or application security initiatives.
- Proven experience managing a bug bounty program, including workflows for triage and payouts.
- Solid understanding of GCP security principles, including Identity and Access Management (IAM), networking configurations, Security Command Center, and common cloud misconfigurations.
- Familiarity with GitHub development practices and code security tools, such as Wiz Code, Dependabot, and various SAST/DAST/SCA tools.
- Strong grasp of vulnerability scoring frameworks, particularly the Common Vulnerability Scoring System (CVSS), and the ability to prioritize risks effectively.
- Exceptional cross-functional communication skills, with the ability to convey technical risks to executive leadership and hold engineering teams accountable for security measures.
- Demonstrated capability to create insightful reporting and dashboards using tools like Linear, Jira, ServiceNow, Tableau, or Looker for real-time visibility into program performance.
- Experience with compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP is highly desirable.
Nice to have
- Experience with security automation tools and techniques to streamline vulnerability management processes.
- Knowledge of programming or scripting languages to facilitate automation and integration tasks.
- Familiarity with incident response processes and frameworks to effectively manage security incidents.
Skills & tools
- Proficient in vulnerability management tools and methodologies.
- Strong analytical skills for assessing security risks and developing mitigation strategies.
- Excellent project management skills, with the ability to manage multiple priorities and deadlines effectively.
Practical notes
Replit offers a competitive salary and equity package, along with a 401(k) plan that includes a 4% match (for U.S. employees). Additional benefits include comprehensive health, dental, vision, and life insurance, short and long-term disability coverage, paid parental leave, medical and caregiver leave, flexible time off, and holiday pay. Commuter benefits are available for in-office employees, along with a monthly wellness stipend. The company fosters an autonomous work environment, provides reimbursement for in-office setup costs, and organizes quarterly team gatherings. We actively encourage applications from candidates of diverse backgrounds.
About the company
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.