wagey.ggwagey.gg
31,364  jobs31,364  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,364)/Security Engineer Role(376)/semgrep (10) - Senior/Staff Security Researcher
semgrep

semgrep - Senior/Staff Security Researcher

Remote - USA$190k - $319k+ Equity1w ago
RemoteStaffNAArtificial IntelligenceSecurity EngineerSenior ResearcherKubernetesTemporalClose

Requirements

• Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details. • Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer). • Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code. • A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over. • Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t. • Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness. • A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology. • Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight. • Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep. • Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals. • Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor). • Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal). • Experience at fast-paced startups, or on similarly minded teams inside larger companies. • A track record of publishing or presenting security research. • Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.

Responsibilities

• Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks. • Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code. • Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review. • Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good. • Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems. • Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection. • Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user. • Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community. • Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.

Benefits

• Salary Range: $190,000 - $319,000 (Pay range will vary based on location) • Our compensation package includes equity and benefits in addition to salary. • Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles. • We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. Benefits offerings vary by location to reflect local requirements and norms. For more detailed, location-specific information, please visit Semgrep Benefits https://www.notion.so/semgrep/Semgrep-Benefits-1593009241a88029bd7edf1fed1dfde2.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

OpenAIOpenAI - Offensive Security Agent Engineer1w ago
·United States·$347k - $490k/year + Equity
In OfficeNAArtificial IntelligenceData AnalyticsSecurity EngineerKubernetesObservableLinux
ZocdocZocdoc - Senior Staff Security Engineer, Vulnerability Management1w ago
·Remote - USA Remote·$200k - $200k/year + Equity
RemoteNAStaffCloud ComputingArtificial IntelligenceSecurity EngineerGoRustPythonExecutive SupportAWSGCPAzureDockerKubernetesPhoenix
OpenAIOpenAI - Security Engineer, Detection and Response1mo ago
·San Francisco, California, United States·$293k - $385k/year + Equity
In OfficeNACloud ComputingArtificial IntelligenceSecurity EngineerKubernetesPlaneAzureAWSGCP
OpenAIOpenAI - Security Engineer, Insider Threat Detection & Response3mo ago
·San Francisco, California, United States·$230k - $385k/year
In OfficeNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerBashPythonIntellectual PropertyLinuxKubernetes
OpenAIOpenAI - Offensive Security Engineer, Agent Security5mo ago
·San Francisco, California, United States·$278k - $490k/year
In OfficeNASeniorCloud ComputingArtificial IntelligenceData AnalyticsSecurity EngineerStorytellingPerformance ReviewsReportingAzureKubernetes
supabasesupabase - Product Security Engineer2mo ago
·Remote - Anywhere·Equity
RemoteWWDeveloper ToolsSoftwareSecurity EngineerCloseKubernetes
GitLabGitLab - Staff Infrastructure Security Engineer (APAC, EMEA)3mo ago
·Remote - APAC; Remote, EMEA·Equity
RemoteNAStaffCloud ComputingSecurity EngineerAWSAzureGCPKubernetesTeam Leadership
SmarterDxSmarterDx - Staff Security Engineer1w ago
·Remote - USA·$230k - $250k/year
RemoteNAStaffCloud ComputingArtificial IntelligenceSecurity EngineerStaff EngineerAWSTerraformGoPythonTypeScriptKubernetesHelmClaudeMentoring
OpenAIOpenAI - Principal Security Engineer, Infrastructure Security2mo ago
·United States·$278k - $490k/year
In OfficeNAPrincipalCloud ComputingArtificial IntelligenceSecurity EngineerPrincipalAWSAzureKubernetes

Browse more by category

Show 376 moreSecurity EngineerShow 110 moreSenior ResearcherShow 1,578 moreKubernetesShow 122 moreTemporalShow 2,525 moreClose
Privacy·Terms··Contact·FAQ·Wagey on X