AI
Curated AI Jobs
Replit

Third Party Risk Management and Customer Trust Lead

Replit10 Jul 2026
fulltimeremote
Apply for this position

Before you apply

Listed location: Foster City, CA

Work arrangement: remote. A remote label does not confirm worldwide eligibility or visa sponsorship.

Read the employer’s description for qualifications, compensation and work eligibility. Confirm the position is still open on the application page.

Job description supplied by Replit; category and skill labels may be inferred. How our listings work · Report a problem

Job Description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.


About the role:

Replit’s ecosystem is powered by an expanding array of external services and essential AI model partners. As our lead for Security Vendor Risk & Contract Reviews, you will architect and execute a risk management program focused on substantive evaluation rather than just processing checklists. You’ll analyze SOC 2 documentation, security assessments, and system architectures to determine actual risk profiles, collaborating with our Legal team to secure necessary contractual protections. This role reports to the Head of Security GRC and involves high-impact partnerships across Legal, Engineering, and Product teams.


What You'll Do

  • Run substantive third-party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses

  • Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers

  • Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI-specific provisions

  • Review contracts for non-standard security language when flagged by Legal or deal desk, and recommend redlines

  • Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register

  • Enable sales through maturing the customer trust program

  • Build the capability for continuous monitoring of vendor ecosystem


Required Skills & Experience

  • 8+ years in third-party/vendor risk management, security risk, or a related GRC role

  • Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation

  • Experience reviewing or redlining security and data-handling contract language, ideally in partnership with a legal team

  • Working knowledge of data privacy fundamentals (GDPR, CCPA) as they relate to vendor and subprocessor relationships

  • Strong cross-functional collaboration skills — this role touches Legal, Engineering, Product, and Sales regularly

  • Experience building repeatable, scalable vendor review processes rather than inheriting an existing one


Bonus Qualifications

  • Direct experience assessing foundation model providers or AI/ML vendors specifically

  • Experience automating or streamlining third-party review workflows (e.g., continuous vendor monitoring, automated evidence pulls) is a plus

  • Familiarity with NIST AI RMF, ISO 42001, or the EU AI Act

  • Background at an AI-native product company or an LLM/model provider

  • Paralegal experience or formal contract review training

  • Relevant certifications (CTPRP, CISSP, CIPP/E)

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:

💰 Competitive Salary & Equity

💹 401(k) Program with a 4% match (US Only)

⚕️ Health, Dental, Vision and Life Insurance

🩼 Short Term and Long Term Disability

🚼 Paid Parental, Medical, Caregiver Leave

🏝 Flexible Time Off (FTO) + Holidays

🚗 Commuter Benefits (In-Office & US Only)

📱 Monthly Wellness Stipend

🧑‍💻 Autonomous Work Environment

🖥 In Office Set-Up Reimbursement (In-Office Only)

🚀 Quarterly Team Gatherings

☕ In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Skills mentioned

LLM

Categories

Frequently asked questions

Is the Third Party Risk Management and Customer Trust Lead position at Replit remote?

Yes. The Third Party Risk Management and Customer Trust Lead role at Replit is a remote position. Country eligibility is not specified here; check the employer listing.

What type of employment is the Third Party Risk Management and Customer Trust Lead role?

Replit is hiring for a full-time Third Party Risk Management and Customer Trust Lead position.

Which skills are mentioned for the Third Party Risk Management and Customer Trust Lead job at Replit?

Detected skill labels include LLM. Check the employer description to distinguish required skills from preferred experience.

How do I apply for the Third Party Risk Management and Customer Trust Lead position at Replit?

You can apply for the Third Party Risk Management and Customer Trust Lead role directly through Replit's official application link provided on this page.

Interested in this role?

Apply directly on the company's website.

Apply Now
Replit

Replit

Website
Posted10 Jul 2026
Typefulltime
LevelLead
LocationRemote
Apply NowView All Jobs at Replit

Share this job