Full-Time

Head of Design

Confirmed live in the last 24 hours

Semgrep

Semgrep

51-200 employees

Vulnerability detection tool for software development

No salary listed

Senior, Expert

San Francisco, CA, USA

The role requires coming into the office 2 days a week.

Category
Product & UX/UI Design
UI/UX & Design
Required Skills
UI/UX Design
Product Management
Requirements
  • A deep UX background, with a bias for action—you’d ship a wireframe if it meant achieving 100% task success
  • Experience at a world-class product company (e.g., Dropbox, Figma, Facebook) with a track record of delivering concrete, measurable outcomes
  • Strong product thinking—you can work as seamlessly with PMs as you do with designers
  • A data-driven approach to design, always optimizing for user success
  • Excitement about using AI and new technologies to accelerate design and iteration
Responsibilities
  • Lead and grow our design team (currently two designers), fostering a high-performance culture
  • Define and execute a UX strategy that drives measurable improvements in product adoption and user success
  • Ensure design and product remain tightly aligned by actively participating in product management team meetings
  • Maintain a proactive, strategic approach—less than 10% of the team’s work should be reactive to engineering requests
  • Deliver at least two major product metric improvements per quarter
  • Own the UX for core product workflows, optimizing for speed, efficiency, and task success
  • Conduct user research and translate insights into UX flow diagrams and low-fidelity wireframes
  • Collaborate with PMs to define and measure in-product success outcomes
  • Continuously iterate on UX flows based on real-world usage data
  • Leverage AI and other cutting-edge tools to accelerate rapid prototyping and testing
Desired Qualifications
  • Prior experience in a fast-paced, tech environment is helpful

Semgrep provides a software solution that helps security engineers and developers find and fix vulnerabilities in their code before it is deployed. The tool integrates into existing workflows and ticketing systems, offering actionable insights that allow developers to trust and act on the results. A standout feature of Semgrep is its ability to significantly reduce false positives in open-source vulnerabilities by up to 98% through reachability analysis, ensuring that only real threats are flagged. The tool is designed for speed, with average scan times of less than 5 minutes and median CI scan times of just 10 seconds, which enhances productivity for engineering teams. Semgrep's goal is to streamline the software development life cycle (SDLC) by providing a reliable and efficient way to secure code, ultimately reducing technical debt and speeding up delivery times.

Company Size

51-200

Company Stage

Series D

Total Funding

$193M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Increased demand for DevSecOps tools aligns with Semgrep's offerings.
  • Growing trend of shift-left security practices benefits Semgrep's early vulnerability detection.
  • Rising adoption of open-source security tools boosts Semgrep's market penetration.

What critics are saying

  • Increased competition in the code analysis market could dilute Semgrep's market share.
  • Rapid technological changes may outstrip Semgrep's ability to update its tools.
  • Economic downturns could challenge Semgrep's subscription-based model affecting customer retention.

What makes Semgrep unique

  • Semgrep reduces false positives in vulnerabilities by up to 98% with reachability analysis.
  • The tool integrates seamlessly into existing workflows and ticketing systems for developers.
  • Average scan time is under 5 minutes, with median CI scan time at 10 seconds.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

401(k) Retirement Plan

Professional Development Budget

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

14%
Silicon Valley Journals
Feb 5th, 2025
Semgrep Raises $100M Series D Funding Round

Semgrep, a leading application security platform, has secured $100 million in Series D funding, led by Menlo Ventures with participation from existing

Semgrep
Apr 19th, 2023
Semgrep, a code & supply chain security search engine, raises Series C

Announcing our $53M Series C led by Lightspeed Venture Partners

R2C
May 11th, 2022
R2c launched DeepSemgrep for Java and Ruby on May 11th 22'.

Recognizing the value of deeper vulnerability detection, today R2c is announcing DeepSemgrep for Java and Ruby.

R2C
Oct 21st, 2021
R2c is developing Semgrep

When R2c began developing Semgrep that was its main focus, and R2c knew that lightweight static analysis, based on syntax-aware matching, would excel at enforcing secure defaults.

TechCrunch
Jul 7th, 2021
r2c raises $27M to scale its security-focused code analysis service

This morning r2c, a startup building a SaaS service around the Semgrep open-source project, announced that it has closed a $27 million Series B. Felicis led the round, which the company said was a pre-emptive deal.