InterviewHack.ai
Start free
Jobs / Replit

Security Engineer - Incident Response

Replit·Foster City, CARemotesenior$19,167–$30,000 USD/mo

In short

  • →Ingeniero de Seguridad que lidera respuestas ante incidentes en una plataforma cloud-nativa de código con IA.
  • →Días a día: investigar intrusiones, automatizar respuestas y mejorar detecciones usando Python/Go en GCP y Kubernetes.
  • →Destacado: el rol implica liderar incidentes reales, escribir herramientas que aceleren la respuesta y actuar como puente entre seguros, SRE y ingeniería.

Experiencia significativa requiere inglés.

Apply on company site ↗Share on WhatsApp
✓ Free to start✓ Runs in your browser✓ First dossier, no card✓ Ready in ~1 minute

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Your first dossier is free.

The questions they'll ask you

1. ¿Cómo abordarías un incidente de acceso no autorizado a cuentas de usuarios en GCP en tiempo real?

2. Describe un script automatizado que hayas escrito para recopilar evidencia en un incidente de seguridad.

3. ¿Cómo validas si una vulnerabilidad de 0-day afecta a una plataforma como Replit?

🔒 +7 more questions

No card. Upload your resume and the full dossier is ready in ~1 minute.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

💵 USD · Remote · No visa

Not finding what you want? Try Micro1

Micro1 places engineers directly at US companies paying in USD. One vetting, multiple offers — no cold applying.

Get matched by Micro1 →
📬Jobs picked for YOUR resume, every morning on WhatsApp. Free: text “vacantes” and the bot sends your daily matches. Subscribe →

What they ask for

  • ✓Liderazgo técnico en incidentes de seguridad en entornos cloud/SaaS.
  • ✓Habilidades avanzadas en investigación con SIEM, logs de nube y análisis de datos bajo presión.
  • ✓Experiencia concreta en Python, Go o Bash para automatización de respuestas.
  • ✓Conocimiento profundo de GCP (IAM, audit logging, GKE, redes).
  • ✓Experiencia con Kubernetes y contenedores, incluyendo contención de workloads comprometidos.
  • ✓Familiaridad con arquitecturas SaaS, sistemas de identidad y caminos de ataque en cloud.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

SIEMCloud LoggingGCPIAMGKEKubernetesBashPythonGoSOAR

Who should you write to at Replit?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

Compensation: $230K – $360K. Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. ABOUT THE ROLE We're looking for a Security Engineer with deep incident response experience to help defend Replit, a fast-moving, cloud-native AI vibe-coding platform. You'll be the person who takes charge when something goes wrong. You'll lead investigations from first signal to root cause, coordinate containment across Security, SRE, and Engineering, and keep stakeholders informed while the incident is moving fast. This isn't a pure responder role. We want a well-rounded security engineer who has run real incidents and wants to make the next one faster. You'll write the scripts, automations, and tooling that take manual work out of triage, evidence collection, and containment. You'll also turn lessons from each incident into better detections, playbooks, and platform hardening.   RESPONSIBILITIES Incident Response - Serve as incident commander or technical lead for security incidents, from detection and triage through containment, eradication, recovery, and post-incident review. - Coordinate response across Security, SRE, Engineering, Legal, and leadership. Drive decisions under pressure and keep a clear record of actions taken. - Communicate incident status, impact, and risk clearly to technical and executive audiences. - Participate in and help shape the security on-call rotation. Investigation & Forensics - Investigate suspicious activity across cloud infrastructure, containers, identity systems, and application layers using SIEM, Cloud Logging, telemetry, and host and container artifacts. - Determine scope, root cause, attacker behavior, and blast radius for confirmed incidents. - Quickly assess whether emerging threats (0-days, active exploitation campaigns, bug bounty findings, customer reports) apply to Replit, and whether we're already affected. IR Automation & Tooling - Build scripts, automations, and tools (Python, Go, Bash, or directly on Replit) that speed up response, such as automated enrichment, evidence collection, credential and session revocation, workload isolation, and alert triage. - Develop and maintain response playbooks and runbooks, and automate them where possible. - Integrate response workflows with SIEM, SOAR, ticketing, and chat tooling to cut time-to-contain. Detection & Continuous Improvement - Turn incident findings into new or improved detections, logging coverage, and visibility. - Lead blameless post-incident reviews and drive remediation items to completion. - Run tabletop exercises and simulations to test readiness and find gaps.   REQUIRED SKILLS & EXPERIENCE - Proven experience leading or serving as technical lead on security incidents in a cloud or SaaS environment. - Strong hands-on investigation skills with SIEM, cloud audit logs, and log-based analysis. Comfortable working through large datasets under time pressure. - Proficiency writing production-quality scripts or tools in Python, Go, or Bash for investigation and automation. - Solid knowledge of cloud architecture and security, especially Google Cloud Platform (IAM, audit logging, GKE, networking). - Working knowledge of Kubernetes and containers, including how to investigate and contain compromised workloads. - Understanding of identity systems, SaaS architectures, and common cloud attack paths (credential theft, privilege escalation, supply chain, token abuse). - Familiarity with software engineering fundamentals, CI/CD pipelines, and package ecosystems, so you can work effectively with Engineering on code-level fixes. - Understanding of IR frameworks and lifecycle (for example NIST 800-61), plus the vulnerability lifecycle and exploitability analysis.   PREFERRED QUALIFICATIONS - Experi

More jobs like this

Remote Security Engineer jobs

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsCompanies hiringAll free toolsResume verdict (Jev)Free cover letterInterview questions by roleTechnical assessment simulator"Tell me about yourself" answerFree ATS checkerInterview-English checkSalary checkSalary negotiation scriptFree STAR answerLinkedIn headline + AboutLATAM salary reportFree coursesBlogTailored CVSpoken practicePricingAffiliates — 30%

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Cloud Security Lead

Replit · Foster City, CA

→

M&A Lead, Corporate Development

Replit · Foster City, CA

→

Staff Software Engineer, Agentic Ads

Replit · Foster City, CA

→

Engineering Manager, Site Reliability Engineering

Replit · Foster City, CA

→