Replit
Third Party Risk Management and Customer Trust Lead
Full-time8+ yrsFoster City, CANot disclosedApply by 8 Sept 2026
Overview
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. ABOUT THE ROLE: Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners.
What you'll do
- As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists.
- You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections.
- This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams.
- Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses
- Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers
- Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions
- Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines
- Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register
Requirements
- Practical experience with Go, Rust, LLM, RAG.
- Experience level: 8+ yrs.
- Strong written and verbal communication in English.
- Comfortable working on-site in Foster City, CA.
Skills
GoRustLLMRAGScala