This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a Security Architecture Lead to serve as the primary technical authority for Replit’s security blueprint. In this Technical Lead capacity, you will steer the architectural direction for a team of security architects and engineers, ensuring our platform is resilient and secure by design. You will be a "player-coach"—leading high-impact technical initiatives while providing deep subject matter expertise to both the engineering organization and executive leadership.
Job Responsibility:
Act as the lead technical voice for security architecture, defining the long-term vision and ensuring consistency across complex infrastructure and product projects
Provide high-level guidance and mentorship to security engineers
Lead cross-functional squads through complex security implementations, from initial design to final production deployment
Define and maintain (document) the authoritative "Source of Truth" for Replit’s secure architecture
Drive the design for secure bootstrapping and multi-layered trust
Enforce isolation principles at every level
Actively identify, document, and quantify architectural security risks
Oversee and conduct deep-dive security reviews for core product features and infrastructure
Own the architectural strategy for Availability, specifically defending against DoS threats
Partner with GRC teams to translate complex architectural designs into clear, audit-ready documentation and control frameworks
Act as the technical bridge for the Sales team, addressing complex security inquiries from enterprise customers
Requirements:
8+ years of experience in security engineering or security architecture
Proven experience as a Technical Lead, steering large-scale projects and guiding the work of other senior engineers
Experience writing and maintaining Architecture documents
Deep expertise in cloud-native security architecture (GCP experience is a significant plus) for multi-tenant SaaS products
Experience designing secure boot, hardware/Cloud-KMS-rooted trust, and multi-layered defense systems
Strong understanding of isolation technologies and DDoS mitigation
Exceptional ability to communicate technical risk to both engineering and executive audiences
Strong track record of contributing to Cybersecurity Risk Register