Mechanical Engineer Jobs at Replit with Visa Sponsorship
Mechanical Engineer roles at Replit sit at the intersection of hardware and a fast-moving software infrastructure company, covering everything from data center systems to physical product development. Replit has a track record of sponsoring H-1B visas for engineering talent, making it a viable target if you need work authorization.
See All Mechanical Engineer at Replit JobsOverview
Showing 5 of 26+ Mechanical Engineer Jobs at Replit jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 26+ Mechanical Engineer Jobs at Replit
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Mechanical Engineer Jobs at Replit.
Get Access To All Jobs
INTRODUCTION
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
ABOUT THE ROLE
We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure.
This role requires strong technical ability to reproduce vulnerabilities, deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly.
WHAT YOU’LL DO
Vulnerability Intake, Triage & Validation
- Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
- Independently validate, reproduce, severity-score, and document findings.
- Identify duplicates and maintain a clean vulnerability records pipeline.
- Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).
Remediation Coordination & SLA Management
- Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
- Provide detailed reproduction steps, proof-of-concepts, and technical analyses.
- Track SLAs, remediation progress, regression testing, and systemic improvements.
- Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.
Bug Bounty & Vulnerability Disclosure Program Management
- Design and evolve the bug bounty program, including scope, rules, and reward structures.
- Manage platform selection, private vs. public launches, and community engagement.
- Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.
- Determine reward payouts, bonus decisions, and recognition for top contributors.
Coordinated Disclosure & CVE Management
- Lead the coordinated vulnerability disclosure process for internal and external findings.
- Negotiate disclosure timelines with researchers and partners.
- Coordinate CVE assignments and publications, and prepare customer/public advisories.
REQUIRED SKILLS
- Experience running or triaging for bug bounty programs (HackerOne ideally).
- Strong ability to triage, validate, and reproduce vulnerabilities independently.
- Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
- Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
- Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.
NICE TO HAVE
- Scripting or automation experience (Python, Go, Bash).
- Pentesting background or exposure to offensive security work.
- Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
- Experience authoring public advisories or CVE writeups.
- Hands-on experience with SIEM, Cloud Logging, and investigative tooling.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
FULL-TIME EMPLOYEE BENEFITS INCLUDE:
- Competitive Salary & Equity
- 401(k) Program with a 4% match
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Commuter Benefits
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement
- Flexible Time Off (FTO) + Holidays
- Quarterly Team Gatherings
- In Office Amenities
COMPENSATION RANGE: $180K - $325K
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

INTRODUCTION
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
ABOUT THE ROLE
We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure.
This role requires strong technical ability to reproduce vulnerabilities, deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly.
WHAT YOU’LL DO
Vulnerability Intake, Triage & Validation
- Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels.
- Independently validate, reproduce, severity-score, and document findings.
- Identify duplicates and maintain a clean vulnerability records pipeline.
- Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC).
Remediation Coordination & SLA Management
- Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation.
- Provide detailed reproduction steps, proof-of-concepts, and technical analyses.
- Track SLAs, remediation progress, regression testing, and systemic improvements.
- Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance.
Bug Bounty & Vulnerability Disclosure Program Management
- Design and evolve the bug bounty program, including scope, rules, and reward structures.
- Manage platform selection, private vs. public launches, and community engagement.
- Communicate clearly with researchers, provide clarifications, and handle feedback or disputes.
- Determine reward payouts, bonus decisions, and recognition for top contributors.
Coordinated Disclosure & CVE Management
- Lead the coordinated vulnerability disclosure process for internal and external findings.
- Negotiate disclosure timelines with researchers and partners.
- Coordinate CVE assignments and publications, and prepare customer/public advisories.
REQUIRED SKILLS
- Experience running or triaging for bug bounty programs (HackerOne ideally).
- Strong ability to triage, validate, and reproduce vulnerabilities independently.
- Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc.
- Familiarity with cloud platforms (GCP preferred) and SaaS architectures.
- Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals.
NICE TO HAVE
- Scripting or automation experience (Python, Go, Bash).
- Pentesting background or exposure to offensive security work.
- Familiarity with compliance frameworks such as SOC 2 and ISO 27001.
- Experience authoring public advisories or CVE writeups.
- Hands-on experience with SIEM, Cloud Logging, and investigative tooling.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
FULL-TIME EMPLOYEE BENEFITS INCLUDE:
- Competitive Salary & Equity
- 401(k) Program with a 4% match
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Commuter Benefits
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement
- Flexible Time Off (FTO) + Holidays
- Quarterly Team Gatherings
- In Office Amenities
COMPENSATION RANGE: $180K - $325K
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
See all 26+ Mechanical Engineer at Replit jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Mechanical Engineer at Replit roles.
Get Access To All JobsTips for Finding Mechanical Engineer Jobs at Replit Jobs
Tailor your portfolio for software infrastructure hardware
Replit's mechanical engineering work centers on physical systems that support cloud and developer infrastructure. Highlight projects involving thermal management, server hardware, or data center equipment rather than traditional manufacturing or consumer product experience.
Confirm H-1B eligibility before applying
Mechanical Engineering qualifies as a specialty occupation under USCIS guidelines when the role requires a bachelor's degree or higher in the specific field. Verify your degree maps directly to the posted job title before submitting your application.
Use Migrate Mate to surface open roles early
H-1B cap-subject petitions must be filed by April 1 for an October start date, so finding open positions well before January gives you enough runway. Use Migrate Mate to browse current Mechanical Engineer openings at Replit filtered by sponsorship.
Raise sponsorship directly during the offer stage
Technology companies like Replit typically have in-house immigration counsel or a retained law firm. Once you receive a verbal offer, ask specifically whether the role is budgeted for H-1B sponsorship before negotiating compensation terms.
Document cross-functional engineering experience for your petition
USCIS scrutinizes specialty occupation claims for Mechanical Engineers at software companies. Gather documentation showing your work directly supports Replit's technical infrastructure, such as collaboration records with hardware, electrical, or platform engineering teams.
Mechanical Engineer at Replit jobs are hiring across the US. Find yours.
Find Mechanical Engineer at Replit JobsFrequently Asked Questions
Does Replit sponsor H-1B visas for Mechanical Engineers?
Yes, Replit sponsors H-1B visas for Mechanical Engineers. As a technology company, Replit works with immigration counsel to support engineering hires who require work authorization. Because H-1B petitions are subject to the annual cap and lottery, you need to secure an offer and begin the process well ahead of the April 1 filing deadline.
How do I apply for Mechanical Engineer jobs at Replit?
Applications go through Replit's careers page, where Mechanical Engineer roles are listed with requirements and team context. You can also browse current openings filtered by visa sponsorship on Migrate Mate, which surfaces active Replit listings specifically relevant to candidates who need H-1B support. Tailor your resume to reflect hardware work that connects to cloud or developer infrastructure.
Which visa types are commonly used for Mechanical Engineer roles at Replit?
The H-1B is the primary visa type Replit sponsors for Mechanical Engineers. Mechanical Engineering qualifies as a specialty occupation under USCIS standards when the role requires a specific bachelor's degree or higher. If you hold an existing H-1B with another employer, a transfer to Replit is generally possible without waiting for the next lottery cycle.
What qualifications and experience does Replit expect for Mechanical Engineers?
Replit's Mechanical Engineer roles typically require a bachelor's degree in Mechanical Engineering or a closely related field. Given the company's focus on software infrastructure, relevant experience includes thermal systems, hardware design for data center environments, or physical product development at technology companies. Hands-on familiarity with CAD software and cross-functional collaboration with electrical or systems engineering teams is commonly expected.
How do I plan my timeline if I need H-1B sponsorship at Replit?
USCIS opens H-1B registrations in March, with cap-subject petitions filed by April 1 for an October 1 start date. If you're selected in the lottery, your employer files the full petition during a designated window. Start targeting Replit openings by January at the latest so there's enough time to receive an offer, complete the LCA filing with DOL, and prepare petition documents before the deadline.
See which Mechanical Engineer at Replit employers are hiring and sponsoring visas right now.
Search Mechanical Engineer at Replit Jobs