Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te
Jobiba hiring network
Soc Verification Engineer Jobs
178 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current soc verification engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet is looking for a highly technical Sr. Manager to lead our India-based Service Desk and IT Automation operations. This is a hands-on, working manager role — you will be personally executing technical work (scripting, automation builds, escalated ticket resolution) and leading a team, not just overseeing one. If you're looking for a purely strategic or delegation-only leadership role, this isn't it. You will manage a team spanning Service Desk, Tier 1 SOC support, and IT Automation Engineering — driving the technical maturity of our global support infrastructure through automation, scripting, deep systems integration, and increasingly, AI-augmented workflows (e.g. intelligent ticket triage, SOC alert summarisation, AI-assisted knowledge base drafting). This role reports directly to the Director of End User Systems , with close, cooperative partnership with US-based Desktop Support managers. You Will IT Automation & Architecture Support the IT automation function, driving initiatives that reduce repetitive work and scale operations efficiently Identify repetitive Tier 1 tasks and drive end-to-end automation from identification through build, testing, and measurement Evaluate and build AI-augmented automation where it reduces toil — e.g. intelligent ticket triage, SOC alert summarisation, AI-assisted knowledge base drafting Mentor team on automation best practices and review technical designs before deployment Team Leadership & Execution Manage India-based Service Desk team with daily coordination with US
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning–driven detection and anomaly detection program. You will own the detection and model lifecycle end to end; feature engineering, model training, tuning, and validation, operating over large-scale security data lakes and streaming pipelines. You’ll partner closely with our Security Operations Center (SOC), Security Operations Engineering, and Fraud programs to turn high-volume telemetry into high-confidence, low-noise detections at scale. What you’ll do: Design, build, and maintain machine learning models for anomaly detection (unsupervised clustering, time-series and seasonality baselines, isolation forests, autoencoders, risk scoring) with measurable precision/recall targets. Operationalize models and detections from notebook to production, including enrichment, correlation, and response playbook hooks (detection-as-code, CI/CD, model versioning, and rollback). Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in the security data lake to improve model signal quality. Partner with the SOC to triage, tune, and close detection feedback loops; use analyst dispositions as labels to retrain and improve models, reduce noise, and document runbo
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a founding member of the Security Operations team in EMEA, you will join us at an exciting time in Roblox’s SIRT & SOC program. You will design and build the detections, automation and tooling that let a lean team monitor and protect players, developers, employees and the platform at global scale and serve as security incident commander in the region. This is a highly autonomous role where you will be a primary decision-maker, core to our mission to maintain a highly capable 24/7/365 monitoring and response capability. While you will work in close collaboration with peers at our US West Coast Headquarters, the time difference requires an engineer who can operate independently, making critical decisions without immediate oversight. We favor engineering our way out of toil through automation, orchestration, detections-as-code, and risk-based prioritization, while retaining the deep technical skills required to conduct detailed, hands-on analysis and lead response end-to-end when the situation warrants. Work Environment: This role is based in London, UK. You will be working from a dedicated, private space located within a shared office environment, designed to enable collaboration
At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards and collaborate across the organization to build and maintain trust at scale. As the Third Party Risk Management Lead, you will be responsible for building and running Asana’s Third Party Risk Management (TPRM) program. You will own the end-to-end lifecycle of vendor security risk — from initial due diligence and risk tiering through ongoing monitoring and remediation. You will work closely with Procurement, Legal, Privacy, and Engineering teams to ensure that our third-party relationships are effectively assessed, tracked, and managed. This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. Our employees in Poland are employed under a contract of employment. What you’ll achieve Own and scale Asana’s TPRM program: Design, implement, and continuously improve a risk-based framework for assessing and managing third-party vendors and service providers. Establish risk tiering criteria, assessment workflows, and governance processes that scale with business growth. Lead vendor security assessments: Conduct and oversee security due diligence for new and existing vendors, including reviewing SOC 2 reports, ISO 27001 certifications, security questionnaires (SIG, CAIQ), and other relevant documentation. Identify gaps and work with vendors to remediate findings. Drive rem
At Asana, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations. We are looking for a collaborative, innovative Group Tech Lead to join our security organization in Warsaw. This is a senior technical leadership role that sits at the intersection of offensive and defensive security — a true purple team visionary who will design and drive Asana's threat operations strategy from the ground up. You will set the long-term technical direction for how we detect, emulate, respond to, and continuously improve our defences against real-world adversaries. This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve Purple Team Strategy & Technical Leadership: Define and own the technical strategy for a fully integrated purple team function, bridging offensive (red team) and defensive (blue team) capabilities into a cohesive, intelligence-driven program. Adversary Emulation: Design and implement a structured adversary emulation programme based on real threat intelligence, ensuring red team exercises directly improve blue team detection and response playbooks while establishing continuous feedback loops. Security Maturity & Industry Standards: Lead Asana's security maturity journey, defining a roadmap that progressively advances capabilities toward frameworks and standards such as NIST CSF, ISO 27001, SOC 2, and MITRE ATT&CK maturity l
Datadog’s Implementation Services team helps customers implement and deploy Datadog quickly. Our team of architects leads the discovery, design, build, and launch of the Datadog platform to help customers accelerate time to value and get the most out of their investment. As a member of our team, you will be responsible for developing the technical roadmap for a customer’s implementation, and leading them through it every step of the way. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Design and guide execution of Datadog implementations, including gathering requirements, building technical architecture, and supporting deployment and launch Guide customer onboarding through co-development working sessions and assist when they run into roadblocks Write automation and design architecture for deployment templates Manage the operation of implementation projects Collaborate with other teams, including Customer Success, Technical Account Management, and Sales to deliver an exceptional onboarding experience Who You Are: Experience designing and delivering technical solutions for DevOps Monitoring or architecture systems Hands-on experience with cloud platforms (AWS, Azure, GCP) and compute technologies (EC2, serverless, VMware, VMs, Docker, Kubernetes). Experience with Config Management, IAC and CI/CD tools, including Ansible, Puppet, Terraform, Chef, Jenkins, Circle CI, GitHub Actions, Azure Pipelines, etc… Experience programming/scripting with any of the following: Java, Python, Ruby, Go, Node.JS, PHP, and .NET etc Background in security operations, including SOC management, SIEM tooling (e.g. Splunk Professional Services), and designing or supporting zero-trust networking architectures Successful track record with 5+ years exper
Datadog’s Implementation Services team helps customers implement and deploy Datadog quickly and successfully. Our team of architects leads the discovery, design, build, and launch of the Datadog platform to help customers accelerate time to value and get the most out of their investment. As a Senior Services Architect focused on Security and Cloud SIEM, you will help customers design, implement, and operationalize Datadog’s security capabilities across cloud, infrastructure, application, and log data sources. You will lead structured, outcome-driven professional services engagements delivered through a day-based professional services delivery model, partnering directly with customers through co-development working sessions, architecture workshops, implementation planning, and operational handoff. This role is ideal for someone who combines customer-facing consulting experience with strong cybersecurity knowledge, hands-on Cloud SIEM implementation skills, and an understanding of security control frameworks such as NIST 800-53, the NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, SOC 2, PCI, HIPAA, ISO 27001, or similar standards. At Datadog, we place value in our office culture — the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Design and guide execution of Datadog implementations, focusing on Security and Cloud SIEM deployment, including discovery, requirements gathering, technical architecture, deployment planning, and launch. Partner with customers to map security requirements, controls, and monitoring objectives to Datadog capabilities, including frameworks such as NIST 800-53, NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, SOC 2, PCI, HIPAA, ISO 27001, or similar standards. Advise customers on security data strategy, including log source prioritization, parsing, normalizat
As a Senior Security Engineer focused on Datadog’s Cloud SIEM product, you will help shape the future of security operations by transforming real-world security expertise into scalable detection, investigation, and response capabilities. You will develop high-impact threat detection content, improve AI-assisted security workflows, and help defenders identify and respond to threats across cloud-native and enterprise environments. Working closely with Product, Engineering, and Security Research teams, you will influence the evolution of Datadog Security products while advancing detection coverage across emerging technologies and attack surfaces. This role offers the opportunity to contribute to open source initiatives, publish security research, and help define the next generation of agentic security operations capabilities. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You'll Do: Research attacker techniques, defensive strategies, and emerging threats, translating findings into scalable security capabilities that protect customers at cloud scale. Design and improve AI-powered investigation, threat hunting, and response workflows that support Datadog’s agentic SOC capabilities. Own the lifecycle of threat detections and automated security workflows, from research and design through deployment, measurement, and continuous improvement. Develop high-fidelity detection content across cloud platforms, SaaS applications, identity systems, endpoints, networks, and other modern attack surfaces. Partner with Product, Engineering, Security Research, and customers to influence roadmap decisions and improve security outcomes across the platform. Mentor security engineers and drive improvements through automation, tooling, rapid prototyping, and data-driven optimization. Who Yo
As a Senior Security Engineer focused on Datadog’s Cloud SIEM product, you will help shape the future of security operations by transforming real-world security expertise into scalable detection, investigation, and response capabilities. You will develop high-impact threat detection content, improve AI-assisted security workflows, and help defenders identify and respond to threats across cloud-native and enterprise environments. Working closely with Product, Engineering, and Security Research teams, you will influence the evolution of Datadog Security products while advancing detection coverage across emerging technologies and attack surfaces. This role offers the opportunity to contribute to open source initiatives, publish security research, and help define the next generation of agentic security operations capabilities. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You'll Do: Research attacker techniques, defensive strategies, and emerging threats, translating findings into scalable security capabilities that protect customers at cloud scale. Design and improve AI-powered investigation, threat hunting, and response workflows that support Datadog’s agentic SOC capabilities. Own the lifecycle of threat detections and automated security workflows, from research and design through deployment, measurement, and continuous improvement. Develop high-fidelity detection content across cloud platforms, SaaS applications, identity systems, endpoints, networks, and other modern attack surfaces. Partner with Product, Engineering, Security Research, and customers to influence roadmap decisions and improve security outcomes across the platform. Mentor security engineers and drive improvements through automation, tooling, rapid prototyping, and data-driven optimization. Who Yo
Datadog is seeking a motivated and experienced Security Sales Engineer to join our dynamic enterprise sales engineering team. In this role, you will play a critical part in driving our security sales efforts by providing technical expertise and delivering compelling solutions to our customers. You will work closely with our enterprise sales engineers and sales team to identify customer needs, craft go to market strategy, demonstrate the value of Datadog's security solutions, and ensure customer satisfaction. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What you will do: Support the Enterprise Security Sales team in driving adoption of Datadog’s security offering within target strategic accounts. Collaborate with the broader sales team to identify and understand security requirements across Datadog’s Enterprise customer base. Conduct detailed product demonstrations and presentations, showcasing the capabilities and benefits of Datadog's security solutions. Provide technical expertise and support throughout the sales cycle, including during customer evaluations and proof-of-value initiatives. Develop and maintain a deep understanding of Datadog's security products, industry trends and current vulnerabilities, staying updated with the latest features and enhancements. Assist in the creation of technical proposals, documentation, and other sales materials. Work closely with the product management and engineering teams to relay customer feedback and influence product development. Participate in industry events, conferences, and webinars to promote Datadog's security solutions.. Who You Are : Bachelor’s degree in Computer Science, Information Technology, or a related field. Deep experience with SIEM platforms and detection pipelines, SOC workflows (alert triage
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs Partner wi
At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive. Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft's Customer Trust team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer contractual commitments. We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft's Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We are looking for a highly motivated, organized, and detail-oriented individual to join our Customer Trust team. As a senior member of this team, you will own a portfolio of concurrent, multi-program compliance efforts and help ensure Lyft meets its enterprise promises and contractual commitments to customers on security and privacy across global markets. You'll manage relationships with external auditors and internal stakeholders, scale our program through efficient processes and automation, and serve as a trusted advisor on technical compliance matters spanning North America, the EU, and the UK. Responsibilities: Program & Audit Ownership Own and lead our ISO 27001 compliance program end-to-end, from certification planning and internal audit through surveillance cycles and Statement of Applicability updates Drive execution across our multi-program compliance portfolio spanning SOC 2, PCI DSS, HIPAA, and NIST CSF, alongside global and international frameworks including UK Cyber Essentials, Spain ENS, and emerging EU re
Get new soc verification engineer jobs by email
Daily job updates · Unsubscribe anytime