Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
Jobiba hiring network
Lead Security Engineer Jobs
6,753 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current lead security engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture. You Will: Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven Fed
About the Team At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Security Engineering is paramount to the success of our business, and DoorDash Security aspires to be one the world’s most admired Security Engineering team. We are committed to building the world's most trusted on-demand, logistics engine for delivery! We're expanding our team of great minds to help us secure and maintain a 24x7, no downtime, global infrastructure system that powers DoorDash’s multi-sided marketplace of consumers, merchants, and drivers. About the Role Our Proactive Security Engineering team is looking for a Staff Security Engineer, Proactive Security to execute on Dasher Security Product Engineering following a forward deployed engineering Pod model.You will be a part of our inclusive, collaborative forward deployed engineering team responsible for building “paved road” Security Product controls directly into our Dasher products to ensure a safe, secure and resilient delivery network. This is not a classic Product Security role performing reviews and operating platform products, this is a forward deployed model where we operate in Pods that focus on domain code bases to build and ship Dasher Security Products focusing on application hardening, anti-app reversing, and payment security in our global Dasher ecosystem.This is a US remote position reporting directly to the Manager of our Proactive Security Engineering team. You’re excited about this opportunity because you will… Lead the technical direction and roadmap for hardening of Dasher Security Products at DoorDash. Partner cross-functionally with Product Engineering, Legal, Security Engineering Platform, Data teams and XFN partners to build “paved road” proactive security controls that enable secure by design AI products into DoorDash eco-system. Examples of Dasher Security Products this team will focus on i
Senior Container Security Engineer – CVE Remediation & Image Hardening About the Role We are looking for a hands-on Senior Container Security Engineer to lead vulnerability remediation and image hardening across Linux-based container environments. This role focuses on deep operating system and container security engineering rather than simple vulnerability scanning. You will analyze, remediate, rebuild, harden, and continuously optimize container images used in modern cloud-native platforms. You will work closely with platform engineering, DevOps, infrastructure, and security teams to build automated remediation pipelines, reduce the attack surface, and deliver production-ready hardened images. What You’ll Do - Own end-to-end CVE remediation across Linux-based container images. - Analyze vulnerabilities across OS packages, libraries, runtimes, and dependencies. - Patch, rebuild, validate, and maintain hardened container images at scale. - Reduce attack surface by removing unnecessary packages, binaries, services, and dependencies. - Build and scale automated remediation pipelines for continuous image patching. - Improve image security posture while minimizing operational disruption. - Generate, validate, and maintain SBOMs to support supply chain visibility and compliance. - Integrate remediation workflows into CI/CD and GitOps pipelines. - Optimize image size, startup performance, and operational efficiency. - Research emerging Linux, container, Kubernetes, and software supply chain threats. - Troubleshoot complex dependency, package compatibility, and runtime security issues. - Help define internal standards for hardened images and secure software delivery. What You Bring - 5+ years of experience in Linux systems engineering, platform engineering, DevSecOps, security engineering, or SRE. - Deep understanding of Linux distributions (Debian, Ubuntu, Alpine, RHEL). - Strong hands-on experience with Docker, Kubernetes, and
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will be on the frontline of protecting both GitLab.com and GitLab the company from security threats. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication, and recovery - while partnering cross-function
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . As an Offensive Security Engineer on the Application Security team within Security, you'll pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red team AI systems, and automate security workflows. This role bridges traditional penetration testing with next-generation AI-augmented offensive security, directly accelerating our ability to protect products and customers. You'll own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response to fundamentally shift how we operate. What you'll do: Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase's product surface. Lead red teaming efforts against internal AI systems, including jailbreak testing, prompt injection analysis, and tool abuse simulation. Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate the bug bounty and vulnerability response pipelines. Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing. Mentor junior security engineers on integrating AI into offensive security workflows to scale team capabilities. Required Skills and Experience: 3+ years of experience in application s
Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and teams across Europe and the US. As AI continues to shape the way we live and work, Synthesia develops products to enhance visual communication and enterprise skill development, helping people work better and stay at the center of successful organizations. Following our recent Series E funding round, where we raised $200 million, our valuation stands at $4 billion. Our total funding exceeds $530 million from premier investors including Accel, NVentures (Nvidia's VC arm), Kleiner Perkins, GV, and Evantic Capital, alongside the founders and operators of Stripe, Datadog, Miro, and Webflow. Location: Europe remote or London hybrid About the role: As our engineering and research organisation grows, so does the complexity of securing it. Our Application Security team is at the forefront of that challenge — building AI-native security tooling, embedding security into the development lifecycle at scale, and finding ways to make a small, highly capable team punch well above its weight. We're looking for an Engineering Manager to lead and grow the AppSec team. This is not a coordination role. You'll be leading a team of exceptionally senior and staff-level engineers who are deeply self-directed and technically excellent. To earn their trust and enable their best work, you'll need to be genuinely close to the craft — able to engage at depth on threat modelling, agentic security tooling, SDLC design, and application risk. You'll also own AppSec strategy and be accountable for how the function scales alongside a product organisation that is growing fast and leaning heavily into AI-assisted development. Important note: Anyone working as a manager within the Infosec team will need to follow the Infosec Team Management Tenets . Key Responsibilities: Lead, support, enable and grow the AppSec team — owning hirin
A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a Senior Identity Security Engineer on Palantir's Identity Security team, you will own the security posture of the identity infrastructure that Palantirians, customers, and services rely on every day. The Identity Security team is responsible for all identity types at Palantir - workforce, customer, workload, and agentic - giving you the rare ability to architect, threat model, and drive security outcomes across the full identity surface. You will help shape the technical direction for identity security at Palantir, reduce standing access, lead identity threat modeling, and contribute to the next generation of identity primitives including agent identity, JIT-native governance, and unified policy enforcement across workforce and customer IAM. As part of Palantir's best-in-class Information Security organization, you will research, architect, and scale solutions that help Palantir stay ahead of a dynamic identity threat landscape.
A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a Senior Identity Security Engineer on Palantir's Identity Security team, you will own the security posture of the identity infrastructure that Palantirians, customers, and services rely on every day. The Identity Security team is responsible for all identity types at Palantir - workforce, customer, workload, and agentic - giving you the rare ability to architect, threat model, and drive security outcomes across the full identity surface. You will help shape the technical direction for identity security at Palantir, reduce standing access, lead identity threat modeling, and contribute to the next generation of identity primitives including agent identity, JIT-native governance, and unified policy enforcement across workforce and customer IAM. As part of Palantir's best-in-class Information Security organization, you will research, architect, and scale solutions that help Palantir stay ahead of a dynamic identity threat landscape.
A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a Senior Identity Security Engineer on Palantir's Identity Security team, you will own the security posture of the identity infrastructure that Palantirians, customers, and services rely on every day. The Identity Security team is responsible for all identity types at Palantir - workforce, customer, workload, and agentic - giving you the rare ability to architect, threat model, and drive security outcomes across the full identity surface. You will help shape the technical direction for identity security at Palantir, reduce standing access, lead identity threat modeling, and contribute to the next generation of identity primitives including agent identity, JIT-native governance, and unified policy enforcement across workforce and customer IAM. As part of Palantir's best-in-class Information Security organization, you will research, architect, and scale solutions that help Palantir stay ahead of a dynamic identity threat landscape.
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detecti
Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team... We are seeking a highly skilled Senior Security Engineer to join our advanced Security Operations team. This role is focused on leading complex incident response and forensic investigations across Windows, macOS, Linux, and AWS environments while helping modernize security operations through automation and AI-driven capabilities. The ideal candidate is a hands-on security expert with deep AWS security expertise, strong threat detection and digital forensic skills, and experience leveraging AI and machine learning technologies to improve detection, response, and operational efficiency. You will play a key role in protecting critical assets, conducting high-impact investigations, mentoring team members, and driving the evolution of our security program against sophisticated and emerging threats. What You'll Get to Do... Lead high-priority incident response and forensic investigations, serving as the primary escalation point for advanced analysis, containment, recovery, root cause determination, and executive-level reporting. Drive threat detection and response across AWS, Windows, macOS, Linux, and endpoint security platforms, leveraging services such as GuardDuty, Security Hub, Detective, CloudTrail, IAM, VPC Flow Logs, and SentinelOne. Conduct malware analysis, host and cloud forensics, evidence collection, and threat hunting activi
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. As Smartsheet grows, our US customer base is increasingly demanding faster, more comprehensive responses to security assessments. We're seeking a Sr. Security Engineer I to lead Customer Trust operations for our US customer base—managing questionnaire triage and completion, supporting customer engagements, and building trusted relationships with enterprise customers. You'll be responsible for understanding customer security concerns, triaging incoming questionnaires, managing queue efficiency, and escalating complex questions appropriately. You'll work closely with EMEA colleagues, sales teams, and security specialists to ensure customers receive timely, accurate responses that build confidence in Smartsheet's security posture. This is an excellent individual contributor and team-player role, and represents a growth opportunity for someone ready to step into a more senior customer-facing security position. You Will: Own US customer trust operations: Manage intake, triage, prioritization, and completion of customer security questionnaires, vendor risk assessments, and RFIs for US-based customers. Respond to customer security inquiries with technical depth: Complete questionnaires accurately, respond to RFIs, and address customer security concerns with responses that
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a founding member of the Security Operations team in EMEA, you will join us at an exciting time in Roblox’s SIRT & SOC program. You will design and build the detections, automation and tooling that let a lean team monitor and protect players, developers, employees and the platform at global scale and serve as security incident commander in the region. This is a highly autonomous role where you will be a primary decision-maker, core to our mission to maintain a highly capable 24/7/365 monitoring and response capability. While you will work in close collaboration with peers at our US West Coast Headquarters, the time difference requires an engineer who can operate independently, making critical decisions without immediate oversight. We favor engineering our way out of toil through automation, orchestration, detections-as-code, and risk-based prioritization, while retaining the deep technical skills required to conduct detailed, hands-on analysis and lead response end-to-end when the situation warrants. Work Environment: This role is based in London, UK. You will be working from a dedicated, private space located within a shared office environment, designed to enable collaboration
Get new lead security engineer jobs by email
Daily job updates · Unsubscribe anytime