Full-Time

Senior Engineering Manager

AI Workflows

Semgrep

Semgrep

201-500 employees

Static code vulnerability scanning for SDLC

Compensation Overview

$197k - $288k/yr

+ Equity + Variable compensation

San Francisco, CA, USA

Hybrid

Three or more days on-site per week required at the San Francisco office.

Category
Engineering Management (1)
Required Skills
LLM
Cybersecurity

Get referred to Semgrep

See people who can refer or advise you

Requirements
  • At least 3 years of experience leading software engineering teams.
  • Familiarity with agile development principles and iterative milestone development.
  • Expertise in two of the following areas is ideally preferred: public SDK or API design and support, data workflow orchestration such as Metaflow or Argo Workflows, or applying artificial intelligence to cybersecurity problems.
Responsibilities
  • Lead a team of 3–5 engineers while making individual technical contributions.
  • Work with the team, product management, and engineering leadership to craft the team’s strategic direction and a quarter-over-quarter roadmap.
  • Define team goals in team meetings, track execution of short-term goals week over week, and provide vision for the future of the product.
  • Coach a senior engineer to develop the skills needed to lead and mentor other engineers through increasingly difficult projects.
  • Make direct technical contributions to deliver new features and gain a strong understanding of the team’s work.
Desired Qualifications
  • Expertise in two of the following three areas: public SDK or API design and support, data workflow orchestration such as Metaflow or Argo Workflows, or applying artificial intelligence to cybersecurity problems.

Semgrep provides a security scanning tool that helps software teams identify vulnerabilities in code before production. It works by analyzing code with Semgrep OSS and Pro Engine and integrates into developers’ workflows and ticketing systems for actionable insights. It reduces noise by using reachability analysis to cut false positives from open-source vulnerabilities by up to 98% and achieves fast scans—average under 5 minutes with a 10-second median CI scan. Its goal is to help engineering teams ship secure software faster by continuously finding and fixing vulnerabilities during the SDLC.

Company Size

201-500

Company Stage

Series D

Total Funding

$193M

Headquarters

San Francisco, California

Founded

2017

Get referred to Semgrep

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Semgrep raised $100 million in February 2025, funding AI and GTM expansion.
  • Replit expanded Semgrep integration on August 11, 2026, exposing Semgrep to AI builders.
  • Semgrep launched Multimodal in March 2026, claiming 8x more true positives and dozens of zero-days.

What critics are saying

  • GitHub Advanced Security and Snyk Code commoditize Semgrep's core scanning by 2026.
  • Semgrep Multimodal relies on beta workflows; production buyers delay purchases until proven.
  • If AI-generated code security becomes platform-native, Semgrep's standalone category loses urgency.

What makes Semgrep unique

  • Semgrep pairs rule-based static analysis with AI reasoning; Multimodal targets business logic flaws.
  • Semgrep runs across any Git platform, unlike GitHub Advanced Security's GitHub-only workflow.
  • Semgrep's open-source roots and customizable YAML rules keep adoption low-friction for developers.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

401(k) Retirement Plan

Professional Development Budget

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Associated Press
Aug 11th, 2026
Semgrep and Replit deepen partnership to secure AI-generated code at scale

Semgrep has expanded its partnership with Replit to embed real-time security analysis into AI-native development workflows. The code security company has integrated Semgrep Guardian's secrets and credentials detection directly into Replit's newly launched Security Center. The collaboration addresses security challenges posed by AI-generated code, which can create and propagate vulnerabilities across multiple files in seconds. Traditional security reviews struggle to keep pace with AI agents that can scaffold complete applications in minutes. The integration provides inline security scanning, real-time vulnerability detection, and in-workflow remediation guidance. It leverages Replit Agent's LLM reasoning to filter out up to 93.3% of false positives from static analysis results. The expanded integration is now available to all Replit Security Center users with no additional setup required. Companies including Snowflake, Figma, Lyft, and Dropbox currently use Semgrep's security platform.

Yahoo Finance
May 6th, 2026
Semgrep hires Cathy Polinsky as co-CTO to tackle AI-generated code security challenges

Semgrep, a code security company, has appointed Cathy Polinsky as co-CTO and VP of engineering. Polinsky brings over 20 years of engineering leadership experience from Yahoo, Salesforce, Stitch Fix, Shopify and DataGrail, including two previous CTO roles. The hire comes as AI-generated code increasingly floods enterprise codebases. Semgrep was recently selected as one of four companies for OpenAI's Trusted Access for Cyber programme. Polinsky will oversee the entire engineering organisation, including product engineering, security research and technical support. She joins co-founder and co-CTO Drew Dennison in a dual structure where Dennison leads technical vision and AI strategy whilst Polinsky scales the engineering team. Polinsky will also oversee development of Semgrep's hybrid LLM offering, which combines static analysis with AI models to detect vulnerabilities.

Associated Press
Mar 19th, 2026
Semgrep launches Multimodal, combining AI with rule-based analysis to find 8x more vulnerabilities

Semgrep has launched Semgrep Multimodal, a code security system combining AI reasoning with rule-based analysis for vulnerability detection, triage and remediation. The system finds up to eight times more true positives whilst cutting noise by 50% compared to foundation models alone, and has discovered dozens of zero-day vulnerabilities at customer sites. Built on Semgrep Workflows, the framework enables security teams to automate processes using deterministic tools and AI. Traditional rule-based scanners excel at catching known vulnerabilities but struggle with business logic flaws, whilst LLMs alone produce high false positive rates. Semgrep Multimodal addresses both dimensions by pairing precise programme analysis with LLM reasoning. Semgrep Multimodal is available today, with custom workflows accessible via private beta. Companies including Snowflake, Figma and Dropbox use Semgrep's platform.

SVJ Media Ltd.
Feb 5th, 2025
Semgrep Raises $100M Series D Funding Round

Semgrep, a leading application security platform, has secured $100 million in Series D funding, led by Menlo Ventures with participation from existing

Semgrep
Apr 19th, 2023
Semgrep, a code & supply chain security search engine, raises Series C

Announcing our $53M Series C led by Lightspeed Venture Partners