ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
As a Senior Engineering Manager for Semgrep Guardian, you'll lead the platform team making security a native property of software at the moment it's written — not a gate applied afterward. Code is increasingly authored inside AI agents, the MCP layer, and the IDE, and Guardian is the platform layer that embeds Semgrep's deterministic security analysis directly into that loop. Semgrep's detection teams own best-in-class SAST, secrets, SCA, and malware engines; Guardian owns the integration, orchestration, and distribution that turn them into a single, low-latency risk verdict an agent or developer can act on in the moment.
Your team owns the surfaces where that verdict is produced and consumed — agent-harness hooks and the partner SDK, the security MCP server, IDE and editor extensions, the orchestration and policy layer, and the unified risk API. Success is measured not by findings produced, but by adoption of that verdict across Semgrep's products, our partners' agents and IDEs, and the trust developers place in it. Through Semgrep's culture of transparency, you'll see and influence the decisions that make a startup successful.
You will:
- Work closely with your product and design partners to create a roadmap for the success of your platform that balances iterative changes with big bets
- Prioritize and direct your team's schedule, balancing the needs of developing new technology, serving internal and external consumers, and maintaining internal technical quality
- Retain and strengthen engineers with coaching and mentorship, regular feedback, performance reviews, and performance management when necessary
- Build an environment of trust that rewards creativity, risk taking, and personal responsibility
- Continually grow your team through the hiring of diverse, productive, high-level technical talent
Please note, this role sits onsite 3 days a week in either of our office hubs( San Francisco, New York City, Denver, or Boston).
You are ideal for this role if you have:
- 3+ years of experience leading software engineering teams
- A strong foundation in product development and bringing products to production via a multi-disciplinary engineering team — including understanding best practices for design, iterative milestone creation, and utilizing customer feedback
- Familiarity with agile development principles and iterative milestone development
- A strong desire to help engineers and other leaders grow through coaching and mentorship
- You have opinions on building durable platforms, APIs, or SDKs for demanding consumers; have worked on developer tooling, IDE/editor extensions, or AI agent, MCP, and protocol integrations; or have built a security product before
COMPENSATION
The estimated starting annual salary range for this position is $230,000 to $288,000 USD. The actual base salary will be determined based on a number of factors, which may include job-related skills, relevant experience, qualifications, location, internal equity, and market data. In addition to base salary, total compensation may include equity, variable compensation, and benefits. We view equity as a meaningful part of our compensation philosophy and a way for employees to share in the long-term value they help create.
Compensation ranges are reviewed regularly and may be adjusted as the role, individual performance, or market conditions evolve.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Engineering
41 days ago
Senior Engineering Manager, Guardian
Semgrep · San Francisco, Boston, New York, Denver, California , United States
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at .
About the role
As a Senior Engineering Manager for Semgrep Guardian, you'll lead the platform team making security a native property of software at the moment it's written — not a gate applied afterward. Code is increasingly authored inside AI agents, the MCP layer, and the IDE, and Guardian is the platform layer that embeds Semgrep's deterministic security analysis directly into that loop. Semgrep's detection teams own best-in-class SAST, secrets, SCA, and malware engines; Guardian owns the integration, orchestration, and distribution that turn them into a single, low-latency risk verdict an agent or developer can act on in the moment. Your team owns the surfaces where that verdict is produced and consumed — agent-harness hooks and the partner SDK, the security MCP server, IDE and editor extensions, the orchestration and policy layer, and the unified risk API. Success is measured not by findings produced, but by adoption of that verdict across Semgrep's products, our partners' agents and IDEs, and the trust developers place in it. Through Semgrep's culture of transparency, you'll see and influence the decisions that make a startup successful.
You will:
Work closely with your product and design partners to create a roadmap for the success of your platform that balances iterative changes with big bets
Prioritize and direct your team's schedule, balancing the needs of developing new technology, serving internal and external consumers, and maintaining internal technical quality
Retain and strengthen engineers with coaching and mentorship, regular feedback, performance reviews, and performance management when necessary
Build an environment of trust that rewards creativity, risk taking, and personal responsibility
Continually grow your team through the hiring of diverse, productive, high-level technical talent
Please note, this role sits onsite 3 days a week in either of our office hubs( San Francisco, New York City, Denver, or Boston).
You are ideal for this role if you have:
3+ years of experience leading software engineering teams
A strong foundation in product development and bringing products to production via a multi-disciplinary engineering team — including understanding best practices for design, iterative milestone creation, and utilizing customer feedback
Familiarity with agile development principles and iterative milestone development
A strong desire to help engineers and other leaders grow through coaching and mentorship
You have opinions on building durable platforms, APIs, or SDKs for demanding consumers; have worked on developer tooling, IDE/editor extensions, or AI agent, MCP, and protocol integrations; or have built a security product before
Compensation
The estimated starting annual salary range for this position is $230,000 to $288,000 USD. The actual base salary will be determined based on a number of factors, which may include job-related skills, relevant experience, qualifications, location, internal equity, and market data. In addition to base salary, total compensation may include equity, variable compensation, and benefits. We view equity as a meaningful part of our compensation philosophy and a way for employees to share in the long-term value they help create.
Compensation ranges are reviewed regularly and may be adjusted as the role, individual performance, or market conditions evolve.
What we offer (FTE only)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit .
Who we are
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Engineering
41 days ago
Senior Engineering Manager, Guardian
Semgrep · San Francisco, Boston, New York, Denver, California , United States
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
As a Senior Engineering Manager for Semgrep Guardian, you'll lead the platform team making security a native property of software at the moment it's written — not a gate applied afterward. Code is increasingly authored inside AI agents, the MCP layer, and the IDE, and Guardian is the platform layer that embeds Semgrep's deterministic security analysis directly into that loop. Semgrep's detection teams own best-in-class SAST, secrets, SCA, and malware engines; Guardian owns the integration, orchestration, and distribution that turn them into a single, low-latency risk verdict an agent or developer can act on in the moment.
Your team owns the surfaces where that verdict is produced and consumed — agent-harness hooks and the partner SDK, the security MCP server, IDE and editor extensions, the orchestration and policy layer, and the unified risk API. Success is measured not by findings produced, but by adoption of that verdict across Semgrep's products, our partners' agents and IDEs, and the trust developers place in it. Through Semgrep's culture of transparency, you'll see and influence the decisions that make a startup successful.
You will:
- Work closely with your product and design partners to create a roadmap for the success of your platform that balances iterative changes with big bets
- Prioritize and direct your team's schedule, balancing the needs of developing new technology, serving internal and external consumers, and maintaining internal technical quality
- Retain and strengthen engineers with coaching and mentorship, regular feedback, performance reviews, and performance management when necessary
- Build an environment of trust that rewards creativity, risk taking, and personal responsibility
- Continually grow your team through the hiring of diverse, productive, high-level technical talent
Please note, this role sits onsite 3 days a week in either of our office hubs( San Francisco, New York City, Denver, or Boston).
You are ideal for this role if you have:
- 3+ years of experience leading software engineering teams
- A strong foundation in product development and bringing products to production via a multi-disciplinary engineering team — including understanding best practices for design, iterative milestone creation, and utilizing customer feedback
- Familiarity with agile development principles and iterative milestone development
- A strong desire to help engineers and other leaders grow through coaching and mentorship
- You have opinions on building durable platforms, APIs, or SDKs for demanding consumers; have worked on developer tooling, IDE/editor extensions, or AI agent, MCP, and protocol integrations; or have built a security product before
COMPENSATION
The estimated starting annual salary range for this position is $230,000 to $288,000 USD. The actual base salary will be determined based on a number of factors, which may include job-related skills, relevant experience, qualifications, location, internal equity, and market data. In addition to base salary, total compensation may include equity, variable compensation, and benefits. We view equity as a meaningful part of our compensation philosophy and a way for employees to share in the long-term value they help create.
Compensation ranges are reviewed regularly and may be adjusted as the role, individual performance, or market conditions evolve.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
- Semgrep Code https://semgrep.dev/products/semgrep-code/: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
- Semgrep Workflows https://semgrep.dev/products/semgrep-workflows/: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
- Semgrep Guardian https://semgrep.dev/products/semgrep-guardian/: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
- Semgrep Multimodal https://semgrep.dev/products/semgrep-multimodal/: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
WHAT YOU’LL DO
- Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
- Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
- Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
- Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
- Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
- Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
- Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
- Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
YOU ARE IDEAL FOR THIS ROLE IF YOU HAVE
- Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
- Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
- Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
- A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
- Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
- A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
- Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
- Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
NICE TO HAVE
- Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
- Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
- Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
- Experience at fast-paced startups, or on similarly minded teams inside larger companies.
- A track record of publishing or presenting security research.
- Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
COMPENSATION
Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
Our compensation package includes equity and benefits in addition to salary.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Senior/Staff Security Researcher
Location
Remote - US
Employment Type
Full time
Department
Engineering Org
Overview
Application
About Semgrep
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev.
About the role
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
Semgrep Code: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
Semgrep Workflows: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
Semgrep Guardian: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
Semgrep Multimodal: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
What you’ll do
Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
You are ideal for this role if you have
Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
Nice to have
Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
Experience at fast-paced startups, or on similarly minded teams inside larger companies.
A track record of publishing or presenting security research.
Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
Compensation
Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
Our compensation package includes equity and benefits in addition to salary.
What we offer (FTE only)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits.
Who we are
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Apply for this Job
Powered by
Privacy PolicySecurityVulnerability Disclosure
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
- Semgrep Code https://semgrep.dev/products/semgrep-code/: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
- Semgrep Workflows https://semgrep.dev/products/semgrep-workflows/: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
- Semgrep Guardian https://semgrep.dev/products/semgrep-guardian/: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
- Semgrep Multimodal https://semgrep.dev/products/semgrep-multimodal/: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
WHAT YOU’LL DO
- Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
- Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
- Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
- Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
- Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
- Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
- Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
- Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
YOU ARE IDEAL FOR THIS ROLE IF YOU HAVE
- Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
- Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
- Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
- A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
- Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
- A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
- Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
- Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
NICE TO HAVE
- Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
- Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
- Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
- Experience at fast-paced startups, or on similarly minded teams inside larger companies.
- A track record of publishing or presenting security research.
- Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
COMPENSATION
Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
Our compensation package includes equity and benefits in addition to salary.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
Semgrep is building a system called Workflows https://semgrep.dev/products/semgrep-workflows/ that combines traditional code security scanning tools with LLMs in innovative ways to detect, validate, and even remediate security issues better than traditional tools or LLMs on their own. This system is fundamental to how Semgrep is going to succeed in an AI-native world.
The workflows system consists of an SDK for composing operations (typically CLI tool calls and agent invocations) into workflows, an environment for periodically executing these workflows, and a set of pre-defined workflows that work out of the box. The workflows team owns all three of these areas (with assistance from our platform, infrastructure, and security research teams).
We are looking for an engineering manager to lead a team of 3-5 engineers and make their own contributions as well. You are ideal for this role if you have:
- 3+ years of experience leading software engineering teams
- Familiarity with agile development principles and iterative milestone development
- A strong desire to help engineers and other leaders grow through coaching and mentorship
- Ideally, you will have expertise in two of the following three areas:
- Public SDK or API design and support
- Data workflow orchestration (e.g. Metaflow or Argo workflows)
- Applying AI to cybersecurity problems
You might spend a typical day:
- Working with your team, product management, and engineering leadership to craft your team’s strategic direction and a strong quarter over quarter roadmap to execute on it
- Defining goals within a team meeting to ensure your team is executing on their short term goals week over week while providing them the vision for the future of the product
- Coaching a senior engineer, helping them gain the skills needed to lead and mentor other engineers through increasingly difficult projects
- Making direct technical contributions to help deliver new features and gain a strong understanding of the work your team is doing
This is a hybrid role with the expectation you’ll join us 3+ days per week in our San Francisco office
COMPENSATION
The estimated starting annual salary range for this position is $197,000 to $288,000 USD. The actual base salary will be determined based on a number of factors, which may include job-related skills, relevant experience, qualifications, location, internal equity, and market data. In addition to base salary, total compensation may include equity, variable compensation, and benefits. We view equity as a meaningful part of our compensation philosophy and a way for employees to share in the long-term value they help create.
Compensation ranges are reviewed regularly and may be adjusted as the role, individual performance, or market conditions evolve.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
About the Role
Semgrep is hiring a Corporate Counsel to be an integral part of the company's legal function during a pivotal stage of growth.
This role will own and drive commercial transactions across the business, partnering closely with stakeholders to support a fast-moving, highly technical organization. This role will report to the COO and work closely with Semgrep’s Fractional General Counsel and the Legal Innovation and Contracts Manager to build scalable legal processes, improve contracting velocity, and shape how legal supports the business as the company grows.
The ideal candidate is excited to work at the forefront of AI-native software development and will leverage AI and automation thoughtfully to improve legal workflows, contracting efficiency, and legal operations.
The right person takes ownership, is highly responsive, business-minded, and comfortable operating independently.
What You’ll Do
- Lead negotiation and execution of customer and vendor agreements, including SaaS agreements, MSAs, DPAs, NDAs, procurement agreements, and related commercial contracts.
- Serve as a practical, solutions-oriented advisor to internal stakeholders, balancing legal risk with business priorities.
- Help define how commercial legal operates at Semgrep, including contracting workflows, templates, playbooks, and approval processes.
- Evaluate and implement practical uses of AI within legal workflows, including contract review, playbook development, knowledge management, and process automation.
- Advise internal teams on legal issues related to SaaS, data privacy, data security, AI, and intellectual property.
- Support Product, Security, and Engineering teams on customer-facing legal and compliance considerations.
- Stay current on evolving legal and regulatory developments affecting AI, developer tools, cybersecurity, and open-source software.
- Build strong cross-functional relationships and become a trusted advisor across the organization.
- Bring a generalist mindset and the ability to flex across legal disciplines as needed.
You’re a Good Fit If You
- J.D. and active membership in at least one U.S. state bar, with a preference to practice law in California.
- 3+ years of legal experience with a mix of law firm and in-house, preferably in a high-growth SaaS or technology company.
- Understand legal issues related to data privacy, data security, software development, AI, and intellectual property.
- Experience in developer tools, cybersecurity, infrastructure software, IP, and open-source software
- Self-starter, solutions-oriented, problem solver, not a task manager, and comfortable operating independently while taking ownership of outcomes and driving agreements to execution.
- Highly responsive, moves swiftly, curious, and communicates clearly.
- Have strong business judgment and provide pragmatic, actionable guidance in fast-moving environments.
- Enjoy building processes and improving systems rather than simply maintaining them.
- A history of implementing AI-based processes and legal technology is strongly preferred.
- Are naturally intellectually curious, thoughtful, and detail-oriented
- Thrive in environments with ambiguity, rapid growth, and evolving priorities.
- Comfortable operating in a fast-moving organization and partnering cross-functionally to support the company’s fast growth while managing risk.
Why This Role
- Opportunity to help shape the legal function at a category-defining code security for builders company.
- Direct partnership with a fractional general counsel and company leadership.
- Meaningful ownership and autonomy from day one.
- Exposure to cutting-edge legal issues at the intersection of AI, security, and developer tools.
- Collaborative, thoughtful, and high-agency culture.
COMPENSATION
Salary Range: $264,000 - $330,000
Our compensation package includes equity and benefits in addition to salary.
Please note that the range listed is for someone based in the San Francisco Bay Area.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at .
About the role
Semgrep is building a system called Workflows that combines traditional code security scanning tools with LLMs in innovative ways to detect, validate, and even remediate security issues better than traditional tools or LLMs on their own. This system is fundamental to how Semgrep is going to succeed in an AI-native world.
The workflows system consists of an SDK for composing operations (typically CLI tool calls and agent invocations) into workflows, an environment for periodically executing these workflows, and a set of pre-defined workflows that work out of the box. The workflows team owns all three of these areas (with assistance from our platform, infrastructure, and security research teams).
We are looking for an engineering manager to lead a team of 3-5 engineers and make their own contributions as well. You are ideal for this role if you have:
3+ years of experience leading software engineering teams
Familiarity with agile development principles and iterative milestone development
A strong desire to help engineers and other leaders grow through coaching and mentorship
Ideally, you will have expertise in two of the following three areas:
Public SDK or API design and support
Data workflow orchestration (e.g. Metaflow or Argo workflows)
Applying AI to cybersecurity problems
You might spend a typical day:
Working with your team, product management, and engineering leadership to craft your team’s strategic direction and a strong quarter over quarter roadmap to execute on it
Defining goals within a team meeting to ensure your team is executing on their short term goals week over week while providing them the vision for the future of the product
Coaching a senior engineer, helping them gain the skills needed to lead and mentor other engineers through increasingly difficult projects
Making direct technical contributions to help deliver new features and gain a strong understanding of the work your team is doing
This is a hybrid role with the expectation you’ll join us 3+ days per week in our San Francisco office
Compensation
The estimated starting annual salary range for this position is $197,000 to $288,000 USD. The actual base salary will be determined based on a number of factors, which may include job-related skills, relevant experience, qualifications, location, internal equity, and market data. In addition to base salary, total compensation may include equity, variable compensation, and benefits. We view equity as a meaningful part of our compensation philosophy and a way for employees to share in the long-term value they help create.
Compensation ranges are reviewed regularly and may be adjusted as the role, individual performance, or market conditions evolve.
What we offer (FTE only)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit .
Who we are
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at .
About the Role
Semgrep is hiring a Corporate Counsel to be an integral part of the company's legal function during a pivotal stage of growth.
This role will own and drive commercial transactions across the business, partnering closely with stakeholders to support a fast-moving, highly technical organization. This role will report to the COO and work closely with Semgrep’s Fractional General Counsel and the Legal Innovation and Contracts Manager to build scalable legal processes, improve contracting velocity, and shape how legal supports the business as the company grows.
The ideal candidate is excited to work at the forefront of AI-native software development and will leverage AI and automation thoughtfully to improve legal workflows, contracting efficiency, and legal operations.
The right person takes ownership, is highly responsive, business-minded, and comfortable operating independently.
What You’ll Do
Lead negotiation and execution of customer and vendor agreements, including SaaS agreements, MSAs, DPAs, NDAs, procurement agreements, and related commercial contracts.
Serve as a practical, solutions-oriented advisor to internal stakeholders, balancing legal risk with business priorities.
Help define how commercial legal operates at Semgrep, including contracting workflows, templates, playbooks, and approval processes.
Evaluate and implement practical uses of AI within legal workflows, including contract review, playbook development, knowledge management, and process automation.
Advise internal teams on legal issues related to SaaS, data privacy, data security, AI, and intellectual property.
Support Product, Security, and Engineering teams on customer-facing legal and compliance considerations.
Stay current on evolving legal and regulatory developments affecting AI, developer tools, cybersecurity, and open-source software.
Build strong cross-functional relationships and become a trusted advisor across the organization.
Bring a generalist mindset and the ability to flex across legal disciplines as needed.
You’re a Good Fit If You
J.D. and active membership in at least one U.S. state bar, with a preference to practice law in California.
3+ years of legal experience with a mix of law firm and in-house, preferably in a high-growth SaaS or technology company.
Understand legal issues related to data privacy, data security, software development, AI, and intellectual property.
Experience in developer tools, cybersecurity, infrastructure software, IP, and open-source software
Self-starter, solutions-oriented, problem solver, not a task manager, and comfortable operating independently while taking ownership of outcomes and driving agreements to execution.
Highly responsive, moves swiftly, curious, and communicates clearly.
Have strong business judgment and provide pragmatic, actionable guidance in fast-moving environments.
Enjoy building processes and improving systems rather than simply maintaining them.
A history of implementing AI-based processes and legal technology is strongly preferred.
Are naturally intellectually curious, thoughtful, and detail-oriented
Thrive in environments with ambiguity, rapid growth, and evolving priorities.
Comfortable operating in a fast-moving organization and partnering cross-functionally to support the company’s fast growth while managing risk.
Why This Role
Opportunity to help shape the legal function at a category-defining code security for builders company.
Direct partnership with a fractional general counsel and company leadership.
Meaningful ownership and autonomy from day one.
Exposure to cutting-edge legal issues at the intersection of AI, security, and developer tools.
Collaborative, thoughtful, and high-agency culture.
Compensation
Salary Range: $264,000 - $330,000
Our compensation package includes equity and benefits in addition to salary.
Please note that the range listed is for someone based in the San Francisco Bay Area.
What we offer (FTE only)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit .
Who we are
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Select a role
The full posting opens here — pay, setting and the full description, without leaving the list.