Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te
Jobs in United States
Engineering Manager Application Security in United States
1,795 active opportunities · Updated September 2026
Showing
15 jobs
Explore current engineering manager application security jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
Hiring demand
73/100
rising · 93 related jobs
Hiring trend
+316.7%
Job postings compared with the previous 30 days
Remote options
22.6%
Share of matching jobs listed as remote
Typical salary
$294.5K – $294.5K/yr
Based on 42 salary observations
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Product Security team is responsible for managing the security processes, policies and controls to secure Plaid’s developer and consumer facing products.The product security team is focused on areas like Application Security, Vulnerability Management, Secure Development Lifecycle, Penetration Testing and Cloud Security. We build the services and components that protect Plaid’s products. We move security "left" by engineering common libraries, modules, and workflows that make the secure path the easiest path for all Plaid engineers. Plaid is looking for a Product Security Engineer who is a builder to join our Product Security team. Unlike traditional Product security roles, this position is for a Senior software engineer who wants to solve security challenges at scale by designing and building production-grade services, libraries, and frameworks. Our goal is to make the "secure path" the only path for Plaid developers. The Role You will lead, design and develop security capabilities to manage vulnerabilities lifecycle and automate workflows to reduce KTLO toil. You will own, maintain, and build Plaid’s VM Orchestration service and build solutions to eliminate the entire vulnerability classes. You
About the Team We are a small and fast-moving partnerships team that shapes and executes OpenAI’s most important collaborations. Your mission is to build and grow partnerships across the cybersecurity ecosystem. Reporting to the Cybersecurity Partnerships Lead, you will own a portfolio of cybersecurity technology partners and help them validate, launch, and scale solutions powered by OpenAI models and platforms. About the Role You are an experienced partnerships operator who combines business development, partner management, technical curiosity, and strong execution. You can manage external relationships while driving detailed cross-functional work across product, engineering, technical success, sales, marketing, legal, security, and operations. You move with urgency, follow through consistently, and are comfortable managing a portfolio in a fast-changing market. In this role, you will: Source, close and manage a portfolio of cybersecurity technology partners. Identify high-value use cases across security operations, identity, cloud security, application security, threat intelligence, governance, risk, and compliance. Develop partner plans covering integration, launch, enablement, co-marketing, co-sell, and growth. Support partnership structuring and coordinate product, technical, commercial, legal, and security workstreams. Help partners move from concept and technical validation to production launch and scaled customer adoption. Run regular partner reviews, track commitments, resolve blockers, and identify expansion opportunities. Coordinate closely with product, engineering, technical success, sales, marketing, legal, security, and operations. Measure partner pipeline, launches, model adoption, consumption, customer outcomes, and partner health. You might thrive in this role if you have: 8+ years of experience in partnerships, business development, alliances, partner success, or ecosystem roles. Experience in cybersecurity, enterprise software, cloud platforms, o
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. About the Role The Product Security team helps make Ramp the most secure place for our customers to collect, manage, and put to work their business’ financial information. Our work centers in three areas: Ramp builds products with an eye for security Ramp detects and responds to threats before they cause harm Security powers Ramp’s growth Check out our Engineering Blog for more on our tech stack, mission and values! What You’ll Do Build security-focused application primitives and integrate them into our existing products Design and deploy platform-level mitigations to common security issues Lead remediation of prioritized issues across our technology stack: collaborating with other engineers to triage and fix vulnerabilities discovered internally, through penetration testing, and through our bug bounty program Partner with engineering teams to design and deploy solutions which are inherently secure Champion the use of tooling (linters, static analysis, posture assessment scanners, query inspectors, etc.) which help Ramp engineers build secure system
From $182K/yr
Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team GoDaddy is hiring a Staff Software Engineer to help define and scale our Internal Developer Platform —a centralized system that powers how engineers across the company build, deploy, and operate software. This platform is used by 1,000+ engineers to manage everything from cloud infrastructure and application lifecycle to security, compliance, and cost transparency. In this role, you’ll operate as a technical leader at platform scale, shaping the architecture and direction of systems that directly impact engineering velocity across the company. You’ll work on high-impact initiatives such as AI-powered developer tooling, next-generation API platforms, and the evolution of a unified developer experience spanning APIs, CLI, and UI. This is a high-ownership, high-visibility role where Staff Engineers drive decisions, influence product direction, and partner across infrastructure, security, and platform teams. If you’re motivated by building systems that improve how other engineers work—and want to have a measurable impact on developer productivity at scale—this team sits at the center of GoDaddy’s engineering ecosystem. What You’ll Get to Do... Design and build platform services that power GoDaddy’s internal developer ecosystem, used by 1,000+ engineers. Lead architecture and technical direction for high-scale APIs, infrastructure orchestration,
From $156K/yr
As organizations rapidly adopt AI applications and agentic systems, security teams need visibility and control over how these technologies are being used. Datadog's AI & Data Security product helps customers discover, secure, and govern AI usage across their environments ensuring sensitive data is properly managed from model training through production. As a Product Manager II for AI & Data Security, you will own capabilities for AI discovery, posture management, and data security; giving customers complete visibility into their AI applications, agents, and enabling ecosystem, with prioritized actions to operate AI systems securely. You'll partner with engineering, design, security research, and GTM teams to define and ship platform capabilities that help organizations adopt AI at scale. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Own the roadmap for AI & Data Security capabilities, including AI and data discovery & posture management. Define how security teams can assess and manage the security posture of AI-enabled systems, including configuration risks, sensitive data exposure, and policy violations. Work closely with engineers and designers to deliver new product capabilities end-to-end, from early concept through launch and iteration. Partner with Datadog security researchers to identify emerging risks in AI systems and translate them into actionable product features. Engage with customers to understand how they are adopting AI and validate solutions that help them operate these systems securely. Collaborate with go-to-market teams to enable adoption and communicate the value of AI security capabilities to customers. Who You Are: You have 3+ years of product management experience building technical products, ideally in security,
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks. You will also serve as a technical infrastructure responder during security incidents, deploying real-time cloud or network countermeasures to protect our production ecosystem. What You'll Do Core Responsibilities Infrastructure Scanning & Triage: Perform continuous security scanning across our cloud posture and workloads. Review, validate, and prioritize flaws and misconfigurations based on CVSS scores, real-world exploitability, and infrastructure network exposure. Posture Management & Visibility : Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools to ensure uniform compliance, prevent data leakage, and maintain hardened baselines. Infrastructure-as-Code (IaC) Security: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines to identify architectural risks (e.g., overly permissive IAM, public S3 buckets/Cloud Storage) before they are deployed to production. Workload & Container Security: Manage the continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines (VMs), partnering with SRE and Platform teams to build aut
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An Overview of this role We are seeking a Staff Product Manager to serve as an internal PM embedded within this team. This is not a traditional external-facing product role—it is an internal platform product leadership position. You will own the roadmap for our enterprise systems, act as the strategic voice of the business within engineering, and bring senior product craft to a team of Analysts and engineers who build and operate GitLab's revenue infrastructure. This role is ideal for a seasoned product leader who has deep Quote-to-Cash or Finance domain knowledge, thrives at the intersection of business strategy and techni
From $10K/yr
About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. As Ramp’s founding Privacy engineer, you will build a privacy program that powers Ramp’s growth while earning trust from customers and prospects. What You’ll Do Build privacy-focused application primitives and integrate them into our existing products Partner with other engineering teams to design and deploy solutions which are inherently privacy-centric and secure Improve, implement, and deploy data retention and anonymization strategies across our environment Track shifting legal standards (alongside with Ramp’s Privacy Counsel) and update Ramp systems and processes to match What You Need Minimum of 4 years of experience building software Minimum of 2 years of experienced focused on platform, privacy, and/or security Desire to work in a fast-paced environment, continuously grow, and master your craft Ability to turn business and product ideas into engineering solutions Nice-to-Haves Working knowledge of data-protection legal requirements Experience with Python (Flask), React, and AWS (ECS, as well as other core services) Benefits available to all
From $244K/yr
We're on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. We operate at high scale—trillions of data points per day—allowing for seamless collaboration and problem-solving among Dev, Ops and Security teams globally for tens of thousands of companies. Our engineering culture values pragmatism, honesty, and simplicity to solve hard problems the right way. The Team: As organizations rapidly invest in AI applications and build out AI labs, telemetry volumes are growing exponentially and costs are becoming unpredictable. From LLM interactions to agentic workflows, AI systems generate unpredictable streams of logs, driving up costs and making it harder to maintain efficient observability. These challenges are critical for organizations in regulated industries with strict data residency requirements, where data must remain within controlled environments. Datadog’s Bring Your Own Cloud (BYOC) team is reimagining what observability and security look like at petabyte scale in the AI era. The Opportunity: The Group Product Manager - Bring Your Own Cloud (BYOC) role is responsible for defining and bringing to market the next generation of telemetry analytics and insights capabilities in an AI-first environment. This role is highly technical and creative in nature as you will envision novel ways to enable customers to cost-effectively explore, analyze and report over petabytes of data through a welcoming and easy-to-use interface. You will partner with various teams to take advantage of BitsAI capabilities and surface critical insights on volume usage and retention for popular use cases. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead and grow a team
From $2.3M/yr
At Datadog, we’re on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. We operate at high scale, enabling seamless collaboration and problem-solving among Dev, Ops, and Security teams globally for tens of thousands of companies. Our engineering culture values pragmatism, honesty, and simplicity to solve hard problems the right way. The Observability Data Platform (ODP) is the backbone of everything Datadog delivers – powering how data is ingested, stored, routed, and surfaced across every product at planet scale. As a Senior Product Manager for ODP, you will work with world-class engineers and cross-functional partners to shape how the platform is deployed, controlled, and operated. You will define product direction across the control plane and data layer, translate complex infrastructure trade-offs into clear roadmap decisions, and help customers get the most from their observability investment – regardless of architecture, topology, or scale. At Datadog, we place value in our office culture – the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You Will Do: Develop a deep understanding of the Observability Data Platform customers – platform engineers, SREs, and product managers that own the product verticals – their infrastructure challenges, deployment topologies, and cost-to-serve trade-offs. Define product direction across multiple ODP surfaces, including the control plane and data layer, by articulating clear problem statements and desired outcomes, and partnering with engineering on technical approach and sequencing Lead conversations with design partners and strategic customers to understand real-world platform pain points, validate product assumptions, and guide solutions from early prototypes through General Availability Develop a co
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About Replit Replit is building the world's most ubiquitous AI coding agent. Replit Agent can be used by anybody to bring their ideas to life. Whether it's an app for yourself, the next great startup idea, or a tool to make you more productive at work, Replit Agent can help build it. Replit is also the leader in secure vibe coding. We protect apps, give users features to manage security risks, and help them vibe code more safely. About the role: Replit is changing how people and companies turn ideas into software. Reaching those customers requires engineering that connects acquisition to the product experience and gives teams trustworthy evidence about what works. This role goes beyond operating conventional marketing technology. You will rethink growth systems for a world where agents can observe performance, diagnose problems, take action, and learn from the result. As the founding engineer for Growth Enablement, you will set the technical direction for this area. You will build agentic systems alongside shared foundations for attribution, audiences, lifecycle engagement, referrals, and promotions. The work spans web, mobile, billing, and data. You will work directly with marketing, sales, and partnerships to find the highest-leverage problems and ship the first solutions. Successful projects will become platforms that help these teams move faster and give Replit a clearer view of what drives durable growth. You will: Design agentic growth systems that monitor performance, diagnose failures, run approved experiments, and improve from the results. Explore AI-native approaches to answer engine optimization, campaign operations, audience discovery, and measurement. Build acquisition measurement across web and mobile, in
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role Join our Enterprise Platform team and build the infrastructure foundations that enable the world's largest organizations to run Replit within their security and compliance boundaries. As a Software Engineer on this team, you'll design and implement the deployment flexibility, networking capabilities, authorization systems, and data controls that enterprises require, from single-tenant architectures and private connectivity to custom policy enforcement and customer-managed encryption. You'll work at the intersection of cloud infrastructure and enterprise requirements, partnering with Platform Engineering, Security, and Sales to ship capabilities that unlock adoption at demanding organizations. What You'll Do Build enterprise deployment infrastructure: Design and implement single-tenant and dedicated deployment options, enabling customers to run Replit with the isolation guarantees their security posture requires. Implement private networking capabilities: Build VPC peering, private connectivity, and static IP configurations that allow enterprises to integrate Replit into their existing network architectures. Design authorization services: Build the authorization infrastructure that enforces custom enterprise policies; enabling fine-grained access controls, custom permission models, and policy enforcement that integrates with customers' existing identity and governance systems. Ship data protection features: Implement bring-your-own-key (BYOK) encryption, customer-managed keys, and data residency controls that give enterprises ownership over their most sensitive data. Develop infrastructure automation: Write Terraform modules and automation that enable reliable, repeatable enterprise deployments across reg
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role Join our Enterprise Platform team and build the infrastructure foundations that enable the world's largest organizations to run Replit within their security and compliance boundaries. As a Software Engineer on this team, you'll design and implement the deployment flexibility, networking capabilities, authorization systems, and data controls that enterprises require, from single-tenant architectures and private connectivity to custom policy enforcement and customer-managed encryption. You'll work at the intersection of cloud infrastructure and enterprise requirements, partnering with Platform Engineering, Security, and Sales to ship capabilities that unlock adoption at demanding organizations. What You'll Do Build enterprise deployment infrastructure: Design and implement single-tenant and dedicated deployment options, enabling customers to run Replit with the isolation guarantees their security posture requires. Implement private networking capabilities: Build VPC peering, private connectivity, and static IP configurations that allow enterprises to integrate Replit into their existing network architectures. Design authorization services: Build the authorization infrastructure that enforces custom enterprise policies; enabling fine-grained access controls, custom permission models, and policy enforcement that integrates with customers' existing identity and governance systems. Ship data protection features: Implement bring-your-own-key (BYOK) encryption, customer-managed keys, and data residency controls that give enterprises ownership over their most sensitive data. Develop infrastructure automation: Write Terraform modules and automation that enable reliable, repeatable enterprise deployments across reg
Higher-paying openings
Jobs with higher listed pay
Engineering Manager - Account Security
Roblox · San Mateo, CA, United States
From $3.5M/yr
Engineering Manager II, Media Rendering
Pinterest · San Francisco, US; Remote, US
From $2.5M/yr
Manager, Engineering
Smartsheet · Bellevue, WA, USA
From $2.3M/yr
Engineering Manager I, Innovative Ad Formats
Pinterest · San Francisco, CA, US
From $2.2M/yr
Senior Engineering Manager, AI Safety Platform
Roblox · San Mateo, CA, United States
From $345K/yr
Senior Engineering Manager, AI Roblox Studio
Roblox · San Mateo, CA, United States
From $345K/yr
Related career options
Similar roles with stronger pay
Demand 35/100 · 7 jobs
$4.6M – $4.6M/yr
Salary →Demand 46/100 · 8 jobs
$345K – $345K/yr
Salary →Other cities to consider
More places hiring for this role
Get new engineering manager application security jobs in United States by email
Daily job updates · Unsubscribe anytime