Base Salary
$190k - $319k/yr
Responsibilities
- Design and ship scalable security workflows combining taint analysis, reachability, static slicing, and LLM reasoning to detect vulnerabilities such as SSRF, IDOR, injection, authentication gaps, and supply-chain risks.
- Engineer precise, cost-aware, trustworthy agentic pipelines and prompts grounded in deterministic security context.
- Improve automated triage and validation so findings can be evaluated and prioritized at scale.
- Design benchmarks and evaluation loops using real customer codebases.
- Encode vulnerability classes, taint sources, sinks, sanitizers, and security properties as reusable versioned logic.
- Research unfamiliar languages, frameworks, and technologies and develop corresponding detection approaches.
- Partner with Engineering and Product to prototype and validate new security capabilities.
- Publish research, give talks, create cheat sheets and workshops, and represent Semgrep’s security research externally.
- Set research direction based on industry trends and emerging threats and lead work with product and community impact.
Requirements
- Strong application security expertise across fundamental vulnerability classes, languages, and frameworks.
- Experience finding vulnerabilities and explaining their impact and remediation context to developers.
- Fluency writing and auditing code in at least two languages.
- A builder’s mindset and ability to automate security problems into scalable tooling.
- Curiosity about or hands-on experience with applied AI and LLMs, including agentic workflows, prompt engineering, RAG, evaluations, or LLM tool use.
- Experience building or operating production LLM or agent systems, including pydantic-ai, MCP, multi-provider orchestration, evaluation frameworks, and cost/latency management.
- Ability to operate autonomously, break ambiguous problems into milestones, and own outcomes.
- Interest in sharing knowledge through writing, talks, and teaching.
- Program analysis or compiler experience, SAST or Semgrep experience, distributed or durable workflow systems, graph databases, or cloud-native infrastructure is preferred.
- Experience with Kubernetes, Argo, or Temporal is preferred.
- Publishing or presenting security research is preferred.
- Experience training or fine-tuning small or local language models for security or code tasks is preferred.
Benefits
- Competitive benefits program for full-time employees, varying by location.
- Equity is included in the compensation package.
- Remote hiring for US-based roles is currently limited to Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Tech Stack
Categories
About Semgrep
Semgrep is the leader in code security for builders. Teams catch, flag, and fix real issues before they ship, powered by security that learns as you build. Built for builders and trusted by security, the platform unifies SAST, SCA, and secrets scanning, embedding protection directly into the development workflow so security begins where code is written and lives where developers work. Semgrep combines deterministic static analysis with AI reasoning to power detection, triage, and remediation. This approach helps teams uncover real vulnerabilities, prioritize reachable risks, and fix issues faster. Customers report up to 80% fewer false positives across Code and Supply Chain, with 95% of findings validated by security reviewers across more than 6 million results. Founded in San Francisco, Semgrep is backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital. It is recognized by Gartner in Application Security Testing and trusted by leading organizations, including Snowflake, Dropbox, and Figma. Learn more at semgrep.dev.
