Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
Salary not disclosed
Check market pay for comparable Security Incident Response Engineer roles before applying.
Role overview
Job description
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe’s business or users. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed, working across multiple AMER time zones, and will regularly coordinate with stakeholders in EMEA and APAC.
What you’ll do
You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint hardening, you will gain a deep understanding of Stripe’s systems, tooling, and workflows to be able to differentiate between legitimate and malicious activity. Using both threat intelligence and collected telemetry, you will guide and build Stripe-specific signals enrichment logic and incident response solutions that scale with our company. Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms.
Responsibilities
- Analyze and investigate a broad range of threats or activities occurring on client devices
- Develop requirements for detection models and enhancements to existing systems
- Collect, transform, and ingest raw data from disparate sources into threat detection pipelines
- Streamline incident response capabilities, ensuring the tooling and processes are clear
- Work cross-functionally with security engineering and data science teams to build solutions for analyzing security events data at scale and protecting Stripe networks, systems, and data from threats
- Provide actionable insights to help identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity
- Act as the subject-matter expert and primary contact for stakeholder teams invested in Security Analytics and Detection programs as well as Stripe-wide security initiatives
- Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security
- B.S. or M.S. Computer Science or related field, or equivalent experience
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proficiency with developing and using novel analytical methods to build, automate, and improve detection and response systems
- Ability to communicate results clearly and focus on impact
- Ability to think creatively and holistically about reducing risk in a complex environment
Preferred qualifications
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with software engineering, data processing and analysis tools (e.g. Databricks/Jupyter, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Familiarity with network observability, security software, or data engineering solutions (osquery, Splunk/LogScale, etc.)
- Experience in one or more of the following areas: user and entity behavior analytics (UEBA), security information event management (SIEM), security orchestration automation and response (SOAR), or data loss prevention (DLP)
What they are looking for
Skills & requirements

Hiring company
Stripe
Stripe is a financial services platform that helps all types of businesses accept payments, build flexible billing models and manage money movement.
Keep exploring
Similar active roles
Fresh roles matched to this title and market.
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will be on the frontline of protecting both GitLab.com and GitLab the company from security threats. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-function
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As an Intermediate Security Engineer on GitLab's Security Incident Response Team (SIRT), you will be on the frontline of protecting both GitLab.com and GitLab the company from security threats. This role operates on a compressed 4-day work schedule, with a full-time week's hours condensed into four longer working days. Shifts run either Sunday through Wednesday or Wednesday through Saturday to provide 24/7/365 security coverage. Your primary focus will be detecting and responding to security incidents during your scheduled shifts. You'll work extensively with our incident response automation tools to inve
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from th
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them. AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL: Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment. Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers. Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from th
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world. What you’ll do In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed
🔔 Get job alerts
New Security Incident Response Engineer jobs in US Remote, straight to your inbox.
No spam · Unsubscribe anytime