Senior/Staff Security Researcher @Semgrep
All Others
Salary usd 190,000 - 3..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 2mths ago

[Hiring] Senior/Staff Security Researcher @Semgrep

2mths ago - Semgrep is hiring a remote Senior/Staff Security Researcher. 💸 Salary: usd 190,000 - 319,000 per year 📍Location: USA

Role Description

The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.

You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get:

  • A vast corpus of real-world code to prove out ideas.
  • A program analysis team building the engine itself.
  • Frontier models and compute to experiment at scale.
  • A platform to publish to one of the largest security audiences in the world.

You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.

You’ll help improve our products and build what comes next, across offerings like:

  • Semgrep Code : our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
  • Semgrep Workflows : a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
  • Semgrep Guardian : securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
  • Semgrep Multimodal : blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.

The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.

You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.

Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.

Qualifications

  • Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details.
  • Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
  • Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
  • A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
  • Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
  • Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
  • A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
  • Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
  • Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.

Requirements

  • Build detection at scale.
  • Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
  • Make LLMs viable for security-critical work.
  • Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
  • Push on hard problems in automated triage and validation.
  • Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
  • Build and defend quality with evals.
  • Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
  • Encode security judgment into tooling.
  • Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
  • Learn new territory fast.
  • Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
  • Prototype new products.
  • Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
  • Share your work.
  • Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
  • Lead and plan research with impact.
  • Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.

Benefits

  • Salary Range: $190,000 - $319,000 (Pay range will vary based on location)
  • Our compensation package includes equity and benefits in addition to salary.
  • We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire.
  • Benefits offerings vary by location to reflect local requirements and norms.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior/Staff Security Researcher @Semgrep
All Others
Salary usd 190,000 - 3..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,939+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later