New RJRP now shows Market-Observed Roles alongside verified postings — scored by our Hiring Activity algorithm. How it works →
🔍
Market-Observed Role 🔍 Observed Likely Active (65-79)
This role was detected through Replit's hiring system and hasn't been verified directly by the employer. Our algorithm scored it as Likely Active (65-79) based on freshness, specificity, and company patterns. What does this mean? →

Security Architecture Lead

Replit
🔍 Observed
76
Hiring Activity Score
Likely Active (65-79)
  • Base score
  • Posted 1 days ago
  • has location, quality description (5782 chars)
  • 52 new listings in 30d (×0.98 age 1d)
  • Direct ATS (ashby)
How the Hiring Activity Score works →
Foster City, CA First seen 1 day, 4 hours ago Last seen 4 hours, 25 minutes ago Ashby
Apply on Ashby Search Google for This Role

ATS links often expire — Google search finds the latest posting

Job Description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. ABOUT THE ROLE We are looking for a Security Architecture Lead to serve as the primary technical authority for Replit’s security blueprint.

In this Technical Lead capacity, you will steer the architectural direction for a team of security architects and engineers, ensuring our platform is resilient and secure by design. You will be a "player-coach"—leading high-impact technical initiatives while providing deep subject matter expertise to both the engineering organization and executive leadership. WHAT YOU'LL DO TECHNICAL LEADERSHIP & MENTORSHIP - Architectural North Star: Act as the lead technical voice for security architecture, defining the long-term vision and ensuring consistency across complex infrastructure and product projects.

  • Technical Mentorship: Provide high-level guidance and mentorship to security engineers, fostering a culture of technical excellence and rigorous security design without the overhead of administrative management. - Project Steering: Lead cross-functional squads through complex security implementations, from initial design to final production deployment. ARCHITECTURE STRATEGY & RISK MANAGEMENT - Maintain the Source of Truth: Define and maintain (document) the authoritative "Source of Truth" for Replit’s secure architecture, ensuring these patterns are consistently adopted across all engineering teams.
  • Secure Bootstrapping & Isolation: Drive the design for secure bootstrapping and multi-layered trust. Enforce isolation principles at every level—from technical containerization and network segmentation to business logic and multi-tenant resource separation. - Contribution to Risk Register: Actively identify, document, and quantify architectural security risks.

You will be responsible for ensuring these are accurately reflected in the Cybersecurity Risk Register, translating technical debt into actionable risk profiles for executive stakeholders. SECURITY DESIGN & REVIEW - Deep-Dive Reviews: Oversee and conduct deep-dive security reviews for core product features and infrastructure, identifying potential threats and mitigating risks early in the development lifecycle. - Availability & Resilience: Own the architectural strategy for Availability, specifically defending against DoS threats to ensure a highly resilient platform.

CROSS-FUNCTIONAL ENABLEMENT - Compliance & Documentation: Partner with GRC teams to translate complex architectural designs into clear, audit-ready documentation and control frameworks. Evaluate required controls against architecture and assess readiness for future compliance certifications. - GTM & Sales Support: Act as the technical bridge for the Sales team, addressing complex security inquiries from enterprise customers regarding Replit's architectural integrity.

REQUIRED SKILLS & EXPERIENCE - 8+ years of experience in security engineering or security architecture. - Proven experience as a Technical Lead, steering large-scale projects and guiding the work of other senior engineers. - Experience writing and maintaining Architecture documents.

  • Deep expertise in cloud-native security architecture (GCP experience is a significant plus) for multi-tenant SaaS products. - Experience designing secure boot, hardware/Cloud-KMS-rooted trust, and multi-layered defense systems. - Strong understanding of isolation technologies and DDoS mitigation.
  • Exceptional ability to communicate technical risk to both engineering and executive audiences. - Strong track record of contributing to Cybersecurity Risk Register. WHAT WE VALUE - Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.
  • Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority. - Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight. Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program with a 4% match ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🚗 Commuter Benefits 📱 Monthly Wellness Stipend 🧑‍💻 Autonomous Work Environment 🖥 In Office Set-Up Reimbursement 🏝 Flexible Time Off (FTO) + Holidays 🚀 Quarterly Team Gatherings ☕ In Office Amenities Want to learn more about what we are up to?

  • Meet the Replit Agent https://www.youtube.com/watch?v=IYiVPrxY8-Y - Replit: Make an app for that https://www.youtube.com/watch?v=4zd9hzngFwY - Replit Blog https://blog.replit.com/ - Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi Interviewing + Culture at Replit - Operating Principles https://blog.replit.com/operating-principles - Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Skills

rust go
Job Information
  • Company:
    Replit
  • Location:
    Foster City, CA
  • Job Type:
    Full-Time
  • Work Location:
    Remote
  • Experience Level:
    Senior
  • Source:
    Ashby
  • Status:
    Active
Activity Score
76 /100
Likely Active (76)

Higher scores indicate more likely active hiring based on listing freshness, company activity, and other signals. Learn more →

More from Replit
+
🔍

We now show two types of job listings

Same commitment to real jobs. More opportunities for you. Here's how it works.

✓ Verified Employer-Verified Posts

These jobs were posted directly to RJRP by the employer. The company has been verified through our multi-step process. This is our gold standard — the employer is real, the job is real, and you can apply with confidence.

✓ 100% employer verified
🔍 Observed Market-Observed Roles

These roles were detected through employer hiring systems like Workday. They haven't been verified by the employer directly, so we score each one using our Hiring Activity Score — an algorithm that analyzes freshness, specificity, company hiring patterns, and more to estimate whether the role is actively being filled.

📊 Only high-scoring listings are shown

Our promise hasn't changed. We will never show you a listing we can't stand behind. Market-observed roles must pass our scoring threshold before they appear on RJRP. Anything that looks like a ghost job, a talent pipeline, or a dead listing gets filtered out — you'll never see it.