Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te
Jobs in United States
Senior Security Risk Management Framework Engineer in United States
1,941 active opportunities · Updated October 2026
Showing
15 jobs
Explore current senior security risk management framework engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
From $114K/yr
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives. The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness. This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives. This role will be based remotely in the United States Responsibilities: Scope of Ownership Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness Program Leadership Own
Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. Join Micron as a Senior Manager, Logistics Security Program, where you will have the outstanding opportunity to lead a world-class global security initiative! This role is critical in ensuring the flawless implementation of our logistics security strategy, encouraging collaboration with key partners, and advancing our program to new heights. Responsibilities: Direct Micron’s worldwide logistics security initiative for valuable shipments, establishing strategy, governance, standards, controls, and performance expectations throughout the transportation network. Lead and expand a distributed team of logistics security experts while promoting uniform performance across Asia Pacific, the Americas, Europe, and other priority regions. Maintain a risk-based shipment security framework that assesses lane, geography, modality, theft history, business impact, recovery capability, and other key risk factors. Establish and enforce logistics provider security requirements, including cargo tracking, route compliance, geofencing, chain of custody, tamper detection, monitoring, blocking issue, and recovery protocols. Partner multi-functionally with Procurement, Logistics, Global Security, Legal, Risk, Finance, and business collaborators to integrate security requirements into contracts, procedures, governance, and scorecards. Coordinate logistics security vendors and providers, including selection, performance management, service levels, monitoring operations, recovery capabilities, and corrective ac
From $209.3K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr
From $243.3K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Enterprise Security Engineer, you will play a critical role in executing Roblox’s Enterprise Security Strategy. You will design, deploy, and manage security solutions to protect Roblox’s corporate infrastructure and ensure secure, compliant operations across the organization. Working closely with Corporate Engineering and Trust & Safety teams, you will translate business requirements into robust security implementations that enable secure productivity while mitigating risk. You will be reporting directly to the Senior Manager of Enterprise Security Engineering. You'll partner with security professionals across the Information Security organization, and work cross-functionally with teams throughout Roblox to drive security initiatives that scale with our business. You will: Evaluate and implement security technologies and vendor solutions to ensure alignment with enterprise security requirements, compliance standards, and overall risk management strategy Lead and drive initiatives across core security domains, including Endpoint Security, SaaS Security, Identity & Access Management (IAM), Agentic AI Governance, and Supply Chain Security. Collaborate closely with IT, engin
Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. As the Logistics Security Program Manager for EMEA, this role is an essential part of Micron’s Global Security team. The person leads the management and continuous refinement of the company’s important logistics security efforts across the EMEA area. This position serves as the regional authority, advancing risk-focused security methods that protect high-value shipments, improve supply chain durability, and lower transportation security risks in intricate multimodal logistics networks. As a senior individual contributor, the Logistics Security Program Manager takes charge of regional program initiatives on their own. They apply solid judgment to shifting threat conditions and collaborate with colleagues across functions and external partners to produce security results. The position involves balancing security, operational efficiency, and business continuity while transforming regional risks into scalable, practical controls that advance cargo visibility, shipment protection, and incident readiness. Responsibilities: Act as the EMEA logistics security authority, guiding the creation and implementation of risk-focused security programs for valuable and sensitive shipments involving carriers, freight forwarders, and logistics providers. Develop, apply, and manage shipment security controls, including tracking, telematics, geofencing, chain of custody, tamper detection, monitoring, critical issue handling, recovery processes, and carrier compliance requirements. Conduct carrier, route, l
From $203.2K/yr
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As the Senior Director, Internal Audit you'll report to the Vice President, Internal Audit, and help strengthen GitLab's Internal Audit function. You'll turn an established audit methodology into consistent, practical ways of working, guide audit quality and execution, and help prepare and implement a risk-based audit plan that addresses GitLab's strategic, business, and compliance objectives. You'll also support the Internal Audit strategy and roadmap, lead the facilitation of our enterprise risk management program, and build trusted relationships with business partners across GitLab. What you’ll d
Senior Security Engineer, Vulnerability Management Here at Datadog, we think about vulnerability management a little differently. We embrace open source software, recognize our role in the software supply chain, and see attackers weaponizing vulnerabilities faster than ever. We are looking for a Senior Security Engineer who can combine vulnerability-management judgment with hands-on engineering to help us scale and improve our vulnerability lifecycle across Datadog’s multi-cloud products and services. In this role, you will turn ambiguous security problems into clear solutions, and work with engineering teams to address root causes and develop technical controls that reduce vulnerabilities earlier in the SDLC. You’ll use AI and automation to help scale the overall vulnerability lifecycle across Datadog. You will use data and sound technical judgment to prioritize risk, and partner with security, product, platform, and compliance teams to bring scalable solutions into practice. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do Work across the vulnerability lifecycle from detection and impact assessment through risk-based prioritization, remediation, and verification. Use AI and automation to build tools, services, and workflows that make security ideas concrete, validate them quickly, and create alignment for scalable implementation. Reduce engineering toil through a “PRs, not tickets” approach, using automation to enrich findings, identify ownership, recommend or deliver fixes, and track outcomes. Analyze recurring vulnerabilities and remediation failures to identify root causes and opportunities to prevent issues earlier in the SDLC. Partner with SDLC Security, Product Security, platform teams, and engineering teams to balance technical constraints, busin
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Senior Software Engineer, Trust (TPRM) - Job Description As a Senior Software Engineer on Vanta's Trust TPRM team, you'll build the full-stack product experiences and underlying data infrastructure that help enterprises manage vendor risk at scale — working across teams focused on vendor lifecycle management and vendor monitoring. Vanta's Trust TPRM (Third-Party Risk Management) team is building the products that make vendor risk management seamless for security and procurement teams. From vendor onboarding and lifecycle management to continuous monitoring and procurement integrations, we're creating the platform that helps Vanta customers understand, track, and mitigate third-party risk — a fast-growing, business-critical capability for modern enterprises. As a Senior Software Engineer, you'll contribute as a core member of either the Vendor Lifecycle or Vendor Monitoring Experience team. You'll design and ship full-stack features that directly shape how customers manage vendor relationships, collaborate with product and design partners, and bring real engineering ownership to a product area that's growing quickly within Vanta. What you’ll do as a Senior Software Engineer at Vanta: Design, build, and maintain full-stack features across the TPRM product surface, including vendor onboarding, lifecycle management, and monitoring workflows Contribute to the vendor data model and core platform abstractions that power TPRM products Write clean, well-tested code and actively participate in code reviews; uphold engineering quality standards Engage in architecture discussions and contribute to technical decision-making within your team
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Senior Security Engineer at Vanta, you’ll own projects with impact across the business to help us run an efficient and highly effective security team. The security team at Vanta ensures that we are a trustworthy steward of sensitive data. We also contribute subject matter expertise to the product, sales, marketing, support, and engineering functions, given the nature of our business. You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process and building tools to make it easy for developers to ship products securely, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you! What you’ll do as a Senior Security Engineer at Vanta: Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios Contribute to complex prioritization discussions around which risks are the most important to solve next Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management) Partner with engineering teams to architect secure software, address security concerns, and build a strong security culture Build, customize, a
Job Requisition ID # 26WD100179 Position Overview The Trust Risk Manager leads the Trust Risk Program at Autodesk and manages a multidisciplinary organization that includes Third-Party Risk Management as well as senior risk professionals. T rust Risk at Autodesk is an established team and program . W e are looking for a leader with the lived experience of operationalizing a risk program that is Trusted by leaders and executives to drive risk-based decisions in the areas of Trust – Security, Privacy, Trusted AI, and Resilience. This individual will report directly to the Director of Trust Governance, Risk, and Compliance. The successful candidate will bring deep expertise in at least one Trust risk domain and sufficient breadth across security, privacy, trusted AI, resilience, and third-party risk to integrate specialist perspectives into an enterprise risk view. Operationalizing risk management and working with executive stakeholders is as much of an art as it is science . Th e Trust Risk Manager needs to have lived, practical experience to g
From $123.7K/yr
About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively. Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessmen
At Freddie Mac, our mission of Making Home Possible is what motivates us, and it’s at the core of everything we do. Since our charter in 1970, we have made home possible for more than 90 million families across the country. Join an organization where your work contributes to a greater purpose. Position Overview: The Cyber Security team at Freddie Mac is searching for a strong data analyst to collaborate on developing and administering data security policies as well as safeguarding information, evaluating existing data security procedures and identifying new areas of risk for Freddie Mac. If this role sounds like a fit for your skill set, please read on, apply and learn why there is #MoreatFreddieMac ! Our Impact: We develop and train the enterprise on relevant Identity and Access Management best practices, develop and support automated IAM processes, and develop and implement ongoing IAM efficiency improvements with limited oversight by managers. The role will work closely with Enterprise partners and security control owners on IAM automation development activities and alignment of IAM processes with InfoSec maturity targets as described in the InfoSec Strategy. Your Impact: Senior Data Analyst who can develop and implement new and updated business process automation for all Identity and Access Management activities. Develop and proposes strategies to reduce security risk in the organization by implementing procedural prevention, detection, and response measures, while still enabling positive business outcomes. Comfortable supporting ad hoc data retrieval and analysis requests using SQL queries and Copilot/Excel . Creating audit-ready reference documentation. This role will allow for and support rapid AI-based extrapolation/replication of these services as future automated IAM microservices. Qualifications: Typically, 5 - 7 years of rel
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The Role: Positioned in the first line of defense (1LOD) and reporting to the Head of Business Controls, this experienced executive will act as the Business Controls Lead for SoFi’s Technology and Cybersecurity organizations. This includes comprehensive coverage of Engineering, Information Security, Infrastructure, and Data across the full SoFi Legal structure: SoFi Inc., SoFi Bank, Galileo, Technisys, and SoFi Hong Kong. The Business Controls Lead will act as the direct advisor to the Chief Technology Officer (CTO), Chief Information Security Officer (CISO), and their senior leadership teams. You will lead a team of experienced IT risk & controls team charged with promoting risk awareness and ensure the overall effectiveness of risk and compliance management program implementation and execution across the 1LOD. This role provides support, advisory services, and enables strategic alignment directly to department heads to accelerate and ensure quality execution. You will be responsible for supporting and driving consistent 1LOD adherence to critical programs, such as building and maintaining risk and control self-assessments (RCSAs); identification and evaluation of control effectiveness through control testing; 1LOD risk reporting; and supporting audits and regulatory exams. You will monitor the first l
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Requisition Job Description Position Summary The Director, Corporate Affairs Technology leads the strategy, delivery, and operations of technology solutions supporting Legal, Compliance, and Corporate Security functions. This role partners with Corporate Affairs leadership to enable regulatory compliance, risk management, and enterprise protection through modern, scalable, and AI-driven technology solutions. This position is a leader-of-leaders role , with direct oversight of Senior Managers and their teams, and is accountable for delivering business-aligned outcomes across the Corporate Affairs application portfolio. Key Responsibilities Define and execute the technology strategy and multi-year roadmap for Corporate Affairs (Legal, Compliance, Corporate Security) Serve as a strategic partner to business leadership, aligning technology solutions to legal, compliance, and security priorities Lead and develop Senior Managers and their teams , ensuring strong performance, accountability, and organizational growth Own the end-to-end application portfolio , including design, delivery, operations, and modernization of platforms Champion AI, automation, and advanced analytics solutions to transform legal, compliance,
Other cities to consider
More places hiring for this role
Get new senior security risk management framework engineer jobs in United States by email
Daily job updates · Unsubscribe anytime