Senior Technical Program Manager, Security
Job description
Senior Technical Program Manager, Security at replit.
About the role
Replit is building an agentic software creation platform, enabling users worldwide to develop applications with natural language. This role focuses on enhancing the security of our platform by leading the vulnerability management program. You will ensure that security risks are identified, prioritized, and resolved efficiently across all systems.
Key facts
What you'll do
- Oversee and refine the vulnerability management program, covering intake, severity assessment, SLA establishment, and remediation tracking for all asset types.
- Manage bug bounty operations, including triage, payouts, and reporting on program health.
- Direct the remediation of vulnerabilities within Google Cloud Platform (GCP) infrastructure, collaborating with engineering and security teams.
- Coordinate the resolution of code and supply chain vulnerabilities identified by security tools across engineering repositories.
- Develop and maintain processes for evaluating and monitoring the security posture of third-party SaaS applications.
- Establish and enforce escalation procedures for critical or overdue findings, including risk acceptance and exception processes.
- Collaborate with engineering managers and tech leads to integrate remediation tasks into sprint planning and ensure adherence to SLAs.
- Create and maintain a central source for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for leadership.
- Provide support for audit and compliance initiatives (SOC 2, ISO 27001) by ensuring vulnerability management evidence is ready.
- Implement process improvements and automation to reduce manual effort in triage and accelerate remediation times.
Requirements
- 4-6+ years in technical program management, security program management, or security operations, with direct experience in vulnerability or application security programs.
- Practical experience managing a bug bounty program, including triage and payout workflows.
- Functional understanding of GCP security fundamentals, such as IAM, networking, Security Command Center, and common cloud misconfigurations.
- Familiarity with GitHub development practices and code security tools like Wiz Code, Dependabot, SAST/DAST/SCA tools.
- Strong understanding of vulnerability scoring frameworks (CVSS) and risk-based prioritization.
- Excellent cross-functional communication skills, capable of translating technical risks for executives and holding engineering teams accountable.
- Demonstrated ability to create reporting and dashboards using tools like Linear, Jira, ServiceNow, Tableau, or Looker for real-time program visibility.
- Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP.
Practical notes
Benefits include competitive salary and equity, 401(k) with 4% match (US only), health, dental, vision, and life insurance, short and long-term disability, paid parental, medical, and caregiver leave, flexible time off, holidays, commuter benefits (in-office only), monthly wellness stipend, autonomous work environment, in-office setup reimbursement (in-office only), quarterly team gatherings, and in-office amenities (in-office only). We encourage applications from diverse backgrounds.