Page 1
Loading more openings…
You've reached the end of the list.
Senior/Staff Security Researcher
Semgrep ·
Pay
$190k–319k
Setting
Remote
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
- Semgrep Code https://semgrep.dev/products/semgrep-code/: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
- Semgrep Workflows https://semgrep.dev/products/semgrep-workflows/: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
- Semgrep Guardian https://semgrep.dev/products/semgrep-guardian/: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
- Semgrep Multimodal https://semgrep.dev/products/semgrep-multimodal/: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
WHAT YOU’LL DO
- Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
- Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
- Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
- Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
- Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
- Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
- Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
- Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
YOU ARE IDEAL FOR THIS ROLE IF YOU HAVE
- Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
- Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
- Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
- A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
- Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
- A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
- Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
- Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
NICE TO HAVE
- Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
- Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
- Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
- Experience at fast-paced startups, or on similarly minded teams inside larger companies.
- A track record of publishing or presenting security research.
- Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
COMPENSATION
Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
Our compensation package includes equity and benefits in addition to salary.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Senior/Staff Security Researcher
Semgrep ·
Pay
$190k–319k
Setting
Remote
Senior/Staff Security Researcher
Location
Remote - US
Employment Type
Full time
Department
Engineering Org
Overview
Application
About Semgrep
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev.
About the role
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
Semgrep Code: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
Semgrep Workflows: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
Semgrep Guardian: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
Semgrep Multimodal: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
What you’ll do
Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
You are ideal for this role if you have
Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
Nice to have
Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
Experience at fast-paced startups, or on similarly minded teams inside larger companies.
A track record of publishing or presenting security research.
Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
Compensation
Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
Our compensation package includes equity and benefits in addition to salary.
What we offer (FTE only)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits.
Who we are
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Apply for this Job
Powered by
Privacy PolicySecurityVulnerability Disclosure
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Senior/Staff Security Researcher
Semgrep ·
Pay
$190k–319k
Setting
Remote
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
- Semgrep Code https://semgrep.dev/products/semgrep-code/: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
- Semgrep Workflows https://semgrep.dev/products/semgrep-workflows/: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
- Semgrep Guardian https://semgrep.dev/products/semgrep-guardian/: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
- Semgrep Multimodal https://semgrep.dev/products/semgrep-multimodal/: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
WHAT YOU’LL DO
- Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
- Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
- Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
- Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
- Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
- Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
- Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
- Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
YOU ARE IDEAL FOR THIS ROLE IF YOU HAVE
- Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
- Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
- Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
- A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
- Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
- A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
- Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
- Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
NICE TO HAVE
- Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
- Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
- Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
- Experience at fast-paced startups, or on similarly minded teams inside larger companies.
- A track record of publishing or presenting security research.
- Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
COMPENSATION
Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
Our compensation package includes equity and benefits in addition to salary.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Senior Technical Account Manager (EMEA)
Semgrep ·
Pay
Not listed
Setting
Remote
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
The Senior Technical Account Manager (TAM) is a critical role that services Semgrep’s most important customers. Our TAMs drive the implementation and on-going adoption of Semgrep for their book of business. This Senior TAM will partner with our customers to ensure the value of using our platform is met by creating personalized growth plans for each account, de-escalating urgent situations that create churn risk, being an expert for their account, representing the voice of the customer for product improvements, and delivering executive business reviews to both practitioners and executive audiences. This customer-facing role also partners with many teams across Semgrep - including Sales, Product Management, Engineering, Marketing, and Support.
Location: London, UK
Prior experience in a fast-paced tech environment is helpful, but we are more interested in your problem solving skills than your pedigree. So if this opportunity excites you but you don’t meet the exact requirements, apply anyway!
WHAT YOU’LL DO
- Host monthly check-in’s with customers to understand their successes and challenges
- Speak with technical stakeholders within our customer base and internally within Semgrep
- Create personalized success plans for customers to ensure they grow the value of using our platform
- Partner with Sales to host executive business reviews with practitioners and the executive buyers
- Collaborate with Tech Support to resolve bug tickets, and with Product to submit and follow up on feature requests
- Advocate on behalf of your customers for product roadmap items to evolve our product suite and features
- De-escalate urgent issues that may introduce churn risk
- Evolve our best practices to deliver exceptional service to our customers
- Contribute to documentation to widen the available information for how to use our products
YOU ARE IDEAL FOR THIS ROLE IF YOU HAVE
- 5v+ years of experience working in a customer facing role - prior experience as a Technical Account Manager, Account Manager, or Product Manager for a highly technical product is preferred
- A deep understanding of developer workflows and build systems, including CI / CD environments such as GitHub Actions, GitLab, Circle CI, Jenkins, and Buildkite and SCM environments such as Git, SVN, Perforce etc.
- Strategic thinker with deep customer empathy; ability to create and execute plans to grow accounts
- Excellent written and verbal communication skills with the ability to influence with an executive presence
- Familiarity with Web Application Security concepts including OWASP Top 10.
- A background or genuine interest in DevSecOps or AppSec
- Engineering or technical degree from a four year college or university
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Senior Technical Account Manager (EMEA)
Semgrep ·
Pay
Not listed
Setting
Remote
Senior Technical Account Manager (EMEA)
Location
Remote - International
Employment Type
Full time
Location Type
Remote
Department
Sales Org
Overview
Application
About Semgrep
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev.
About the role
The Senior Technical Account Manager (TAM) is a critical role that services Semgrep’s most important customers. Our TAMs drive the implementation and on-going adoption of Semgrep for their book of business. This Senior TAM will partner with our customers to ensure the value of using our platform is met by creating personalized growth plans for each account, de-escalating urgent situations that create churn risk, being an expert for their account, representing the voice of the customer for product improvements, and delivering executive business reviews to both practitioners and executive audiences. This customer-facing role also partners with many teams across Semgrep - including Sales, Product Management, Engineering, Marketing, and Support.
Location: London, UK
Prior experience in a fast-paced tech environment is helpful, but we are more interested in your problem solving skills than your pedigree. So if this opportunity excites you but you don’t meet the exact requirements, apply anyway!
What you’ll do
Host monthly check-in’s with customers to understand their successes and challenges
Speak with technical stakeholders within our customer base and internally within Semgrep
Create personalized success plans for customers to ensure they grow the value of using our platform
Partner with Sales to host executive business reviews with practitioners and the executive buyers
Collaborate with Tech Support to resolve bug tickets, and with Product to submit and follow up on feature requests
Advocate on behalf of your customers for product roadmap items to evolve our product suite and features
De-escalate urgent issues that may introduce churn risk
Evolve our best practices to deliver exceptional service to our customers
Contribute to documentation to widen the available information for how to use our products
You are ideal for this role if you have
5v+ years of experience working in a customer facing role - prior experience as a Technical Account Manager, Account Manager, or Product Manager for a highly technical product is preferred
A deep understanding of developer workflows and build systems, including CI / CD environments such as GitHub Actions, GitLab, Circle CI, Jenkins, and Buildkite and SCM environments such as Git, SVN, Perforce etc.
Strategic thinker with deep customer empathy; ability to create and execute plans to grow accounts
Excellent written and verbal communication skills with the ability to influence with an executive presence
Familiarity with Web Application Security concepts including OWASP Top 10.
A background or genuine interest in DevSecOps or AppSec
Engineering or technical degree from a four year college or university
What we offer (FTE only)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits.
Who we are
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Apply for this Job
Powered by
Privacy PolicySecurityVulnerability Disclosure
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Senior Technical Support Engineer EMEA
Semgrep ·
Pay
$35k–110k
Setting
Remote
Job not found
The job you requested was not found.
View all open positions
Powered by
Privacy PolicySecurityVulnerability Disclosure
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Sales Solutions Engineer - Digital Native
Semgrep ·
Pay
$152k–190k
Setting
Remote
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
As a Sales Engineer at Semgrep, you’ll be an integral part of a diverse team working to help developers everywhere build more secure applications. Your daily engagements with our customers would directly contribute to a more productive and durable development process that catches software vulnerabilities before they go live. You will be the technical expert working directly with our customers to understand their goals and challenges, integrate our products and services into their environments, and ensure we deliver the maximum value possible.
Location expectations:
- Ideal preference is for the candidate to be based out of San Francisco, CA office in a hybrid capacity but we are open to any candidates working remotely in the United States
Prior experience in a fast-paced, tech environment is helpful, but we are more interested in your problem solving abilities than your pedigree. So if this opportunity excites you but you don’t meet the exact requirements, apply anyway!
WHAT YOU’LL DO
- Become an expert on Semgrep and integrating our platform into the software development lifecycle.
- Own the technical aspects of the sales process - demonstrate product features and expertise, deliver successful proof of concepts, and educate customers on best practices.
- Help our customers identify and understand their security vulnerabilities and build robust systems to detect and prevent them in the future.
- Articulate to customers how our platform is uniquely differentiated to power their security program with greater speed, accuracy, and flexibility than other offerings.
- Champion our customers’ needs internally to guide our product and development teams in continuing to deliver products that delight application security teams and their organizations.
- Minimize customer friction in adopting and deploying Semgrep through building automation, refining processes, or creating content for external consumption.
YOU ARE IDEAL FOR THIS ROLE IF YOU HAVE
- Excellent verbal and written communication and presentation skills in English.
- An interest in people and helping them solve challenging technical problems
- 5-8 years working with customers in a pre-sales, customer success, or customer/product support experience.
- A deep understanding of developer workflows and build systems, including CI / CD environments such as GitHub Actions, GitLab, Bitbucket and Azure Devops
- Exposure to application security, vulnerability management, and static analysis programs.
- A bachelor’s degree in computer science, computer engineering, similar technical field of study, boot-camp completion, or equivalent practical experience.
COMPENSATION
Salary Range: $152,000 - $190,000* USD ($217,000 - $272,00 uncapped OTE)
Our compensation package includes equity and benefits in addition to salary.
Please note that the range listed is for someone based in the San Francisco Bay Area.
WHAT WE OFFER (FTE ONLY)
Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.
We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.
WHO WE ARE
We bring together people from a wide range of backgrounds and disciplines—from physics and philosophy to formal methods research and full-fledged corporations. We’re new parents and new grads, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.
Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in Semgrep’s mission, and treat Semgrep’s values as your own, you belong here.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin.
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Sales Solutions Engineer - Digital Native
Semgrep ·
Pay
$152k–190k
Setting
Remote
Listed by Semgrep for a position based in the United States. Employers on this board attest they are hiring domestically.
Select a role
The full posting opens here — pay, setting and the full description, without leaving the list.