Cloud Security Lead
- Salary
- ₹10–20 LPA
- Location
- Foster City
- Experience
- Senior
About the company & role
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. Join us at the forefront of AI and cloud-native security as we work to secure one of the most innovative developer platforms in the world. As the Cloud Security Lead , you will shape the cloud and infrastructure security program that protects millions of developers, enables safe AI-assisted development, and ensures organizations can confidently bring our platform into enterprise environments. In this role, you will own cloud security across GCP (primary) and supplemental environments in AWS and Azure , as well as containerized systems, SaaS platforms, and our multi-tenant AI infrastructure. You’ll improve our security posture through strong architecture, posture management, secure-by-default development practices, and close partnership with Engineering, Compliance, Security Architecture, and Platform teams. This is a highly impactful, hands-on leadership role—perfect for someone who wants to solve complex security challenges at scale while influencing product, engineering, and go-to-market teams. What You’ll Do: Cloud Security Engineering Lead configuration hardening across GCP , with additional oversight of workloads and integrations running in AWS and Azure . Own and optimize CSPM platforms across multi-cloud environments—establishing configuration baselines, guardrails, and remediation workflows. Secure critical SaaS platforms , ensuring proper configurations, access controls, and engineering integrations. Lead infrastructure vulnerability management across multi-cloud systems, containers, registries, and platform services. Enhance security across containerized and Kubernetes (GKE/EKS/AKS) workloads, including runtime protections, network policies, and workload identity. Assess secure logging configurations across c