Jobs / United States / Replit INC

Staff Software Engineer, Identity & Authorization

Replit INC · 🇺🇸 Foster City, CA

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 26 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 1 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Replit INC paid sponsored hires in similar roles16 certified filings for “Staff Software Engineer” (Software Developers) in CA: $188k–$265k, median $207k. Most were filed at wage level IV (38%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Replit INC

26 H-1B filings certified since Oct 2025

The US Department of Labor certified 26 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 1 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Replit INC →

About the role

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. ABOUT THE TEAM Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly. Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services. Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls. We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here. ABOUT THE ROLE As a Software Engineer, you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity. The work is guided by a few simple questions: - Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf? - Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services? - Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions? - Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials? - Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them? WHAT YOU'LL DO - Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations - Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible - Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS - Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default - Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship - Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives - Research and develop new innovative approaches to Authx in the Agentic world AREAS YOU MIGHT WORK IN - Authorization policy: evolve Replit's central policy decision point and migrate fragmented authorization checks to its typed contract. - Agent delegation: extend the current delegation foundation so the user is the subject and Agent is the authenticated actor, with continuous validation and dynamic permission envelopes as work runs. - Enterprise access control: evolve roles, groups, workspace policy, and app-level grants for both simple collaboration and complex organizations. - Agent and service identity and reliability: operate the token and workload-identity systems that protect service-

View the official posting →

Source: Ashby (employer board) First seen: 2026-10-01 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities