SOC Engineer at Replit monitoring and assessing emerging threats in cloud infrastructure and AI coding environments. Conducting investigations and collaborating with teams for mitigation strategies.
Responsibilities
Continuously monitor emerging threats including bad actor activity, 0-day vulnerabilities, public exploitation campaigns, bug bounty reports, and customer-reported security issues
Quickly assess the applicability of these threats to Replit’s cloud infrastructure, SaaS services, internal tooling, and platform components
Conduct targeted investigations to determine whether Replit is already impacted by a newly discovered threat, vulnerability, or exploit
Analyze logs, telemetry, and system behaviors using SIEM, metrics, Cloud Logging, and related tools
Identify gaps or weaknesses in existing detection or visibility and propose improvements
Research potential impact paths and develop mitigation strategies for confirmed or applicable threats
Partner closely with Security, SRE, and Engineering teams to coordinate and implement containment, patches, configuration updates, or code-level fixes
Document findings, mitigations, and follow-up actions clearly for internal teams
Requirements
Strong understanding of software engineering fundamentals including code structure, build systems, dependencies, and package ecosystems
Understanding of CI/CD pipelines and DevOps workflows
Solid knowledge of cloud architecture, especially Google Cloud Platform (GCP)
Familiarity with SaaS architectures, identity systems, and integration patterns
Hands-on experience with SIEM, Cloud Logging, and log-based investigation workflows
Ability to perform investigations using log data, behavioral indicators, and threat intelligence
General understanding of vulnerability lifecycles, exploitability analysis, and common attack vectors
Experience with threat intelligence, security research, or vulnerability analysis preferred
Familiarity with Kubernetes, containers, serverless infrastructure, or modern distributed systems preferred
Ability to write scripts or small tools for investigation or automation (Python, Go, Bash) preferred
Experience working with bug bounty programs or coordinated vulnerability disclosure workflows preferred
Experience in fast-paced, cloud-native, or AI/ML-driven environments preferred
Director of Security Operations overseeing incident response tasks at Gartner. Leading a geographically dispersed team and improving capabilities for detecting and responding to threats.
Senior Manager for Product Security Ops & Strategy at Salesforce overseeing strategic initiatives and ensuring alignment with security goals. Driving operational excellence and executive communication across teams.
Security Operations Manager responsible for planning and managing security programs at Cox Enterprises. Collaborating with stakeholders and analyzing security vulnerabilities while conducting investigations.
Security Operations Centre Analyst for Paysafe, responding to real - time security alerts and assisting Incident Response in security events. Requires collaboration in a global team environment with various security frameworks.
SOC Analyst focusing on real - time security monitoring and incident response for Atos Group in Bengaluru, ensuring proactive threat detection and effective response to incidents.
Manage global corporate security operations programs at OpenAI, collaborating across teams to enhance security measures. Focus on operational standards and program development for effective security initiatives.
Senior SOC Analyst leading advanced security monitoring and response across various platforms. Collaborating with teams to strengthen security posture and mentor junior analysts.
SOC Analyst developing cybersecurity solutions at Capgemini for leading organizations. Engaging in incident response and security operations in a collaborative environment with global colleagues.