SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Replit is seeking a Senior Technical Program Manager to own the vulnerability management program end-to-end. This role drives vulnerability intake, triage, remediation, and reporting across bug bounty programs, Google Cloud Platform infrastructure, GitHub-hosted source code, and third-party SaaS services. You will partner with platform engineering, product engineering, SRE, security, IT, legal, and vendor management teams to ensure vulnerabilities are identified quickly, triaged accurately, and closed within SLA while maintaining clear visibility of organizational risk posture.
Key responsibilities include: establishing and improving the vulnerability management program with intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types; managing bug bounty operations including triage, payouts, and program health reporting; driving GCP infrastructure vulnerability remediation across IAM, networking, Compute/GKE, storage, and logging/monitoring; coordinating remediation of vulnerabilities from SAST/DAST/SCA tools (Wiz Code, Snyk, Dependabot) across engineering repositories; building processes for assessing third-party SaaS security posture; defining escalation paths for overdue or critical findings with risk acceptance workflows; embedding remediation work into sprint planning and holding teams accountable; establishing dashboards and reporting for engineering, security, and executive leadership; supporting SOC 2, ISO 27001, and compliance audit efforts; and driving process improvements and automation to reduce manual effort.
Required experience includes 4–6+ years in technical program management, security program management, or security operations with direct ownership of vulnerability management or application security programs. You need hands-on bug bounty program experience (HackerOne, Bugcrowd, Intigriti), working knowledge of GCP security fundamentals, familiarity with GitHub workflows and code security tooling, strong grasp of CVSS and risk-based prioritization, excellent cross-functional communication skills, proven ability to build reporting dashboards (Linear, Jira, ServiceNow, Tableau, Looker), and experience supporting compliance frameworks (SOC 2, ISO 27001, PCI-DSS, FedRAMP).
The ideal candidate uses AI and automation to scale their impact while maintaining focus on clarity, tradeoffs, and execution. You should demonstrate systems thinking, technical influence without direct authority, comfort with end-to-end program ownership, and a bias for action in closing the gap between vulnerability discovery and remediation.