We're redefining how software is built and who gets to build it. Our mission is to achieve Autonomy for All: making programming accessible, collaborative, and powered by AI. Realizing that vision requires a platform that legitimate users can trust and adversarial actors cannot exploit
We're hiring a Data Scientist to help build Replit's Trust & Safety and Anti-Abuse program from the ground up. You'll turn noisy behavioral, identity, payment, infrastructure, and content signals into the measurement systems, detections, and decisions that protect Replit's users, platform, and economics. You'll work closely with Engineering, Support, Legal, Security, Infrastructure, Money, and Growth to make abuse economically unviable while keeping friction low for legitimate users
Replit sits at the frontier of AI-native abuse. Our platform is a target for phishing and scam hosting, cryptomining, LLM token farming, card and coupon fraud, referral abuse, and increasingly, abuse driven by AI agents themselves. You'll help define how we identify, measure, and respond to these threats without compromising the experience of good users
Own the analytical foundation for Trust & Safety, including abuse prevalence, fraud loss, false-positive and false-negative rates, time to detect, time to mitigate, appeal and reversal rates, and verification step-up conversion
Build reliable datasets and dbt models that connect product events, account and identity signals, payment activity, infrastructure usage, content classifications, enforcement actions, appeals, and support outcomes
Develop and evaluate risk models, rules, and anomaly-detection systems for threats such as phishing, scam hosting, cryptomining, token farming, payment fraud, promotional abuse, and AI-agent exploitation
Design rigorous offline evaluations, shadow-mode tests, holdouts, and controlled experiments to measure detection quality and the user impact of new policies, enforcement actions, and progressive verification
Define thresholds and decision frameworks that balance abuse reduction, economic loss, customer friction, and false positives across free, paid, and enterprise users
Investigate emerging abuse patterns, quantify their impact, identify coordinated behavior, and turn ambiguous signals into clear recommendations for product and engineering teams
Develop predictive models that estimate account, device, transaction, workspace, or deployment risk and embed those signals into detection, review, and escalation workflows
Partner with Support and Legal to improve case review, appeals, reason-code quality, and feedback loops so human decisions become useful model and policy signals
Build monitoring that detects model drift, attacker adaptation, data-quality failures, and unexpected harm to legitimate users
Communicate findings clearly to technical and non-technical partners, including the tradeoffs, uncertainty, and evidence behind high-impact decisions
Build a measurement framework for Replit's abuse surface, reconcile incomplete labels across automated detections, human review, appeals, chargebacks, and support cases, and establish a trustworthy baseline for the first time
Design and evaluate a risk-scoring model for suspicious account clusters using identity, device, payment, graph, and product-behavior signals, then define thresholds that materially reduce fraud while protecting legitimate users
Analyze a phishing detection rule that appears highly precise, uncover that it disproportionately bans paying users with legitimate brand references, and redesign its evaluation and review path to reduce false positives
Measure a progressive verification "ladder of trust," determining when to step users up to additional verification and quantifying the tradeoff between abuse prevented and legitimate-user conversion lost
Detect coordinated token-farming or promotional-abuse networks by combining account-linkage graphs, referral behavior, payment patterns, and infrastructure usage, then partner with Engineering to operationalize the findings
Evaluate a new enforcement policy in shadow mode, estimate its counterfactual impact, and recommend whether to launch, revise, or reject it before any users are affected