Full-Time

Staff Security Advocate

Security Advocacy

Posted on 8/12/2025

Semgrep

Semgrep

201-500 employees

Static code vulnerability scanning for SDLC

Compensation Overview

$147.5k - $199.5k/yr

+ Equity + Benefits

Remote in USA

Remote

US-based roles open to remote work are available in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Hampshire, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, and Washington.

Category
IT & Security (1)
Required Skills
Python
JavaScript
Java
Go
Requirements
  • 8+ years of hands-on keyboard experience identifying, analyzing, and remediating security vulnerabilities across web applications, cloud infrastructure, and APIs.
  • Proven track record of security research contributions such as CVE discoveries, security advisories, or published research.
  • Deep understanding of OWASP Top 10, secure coding practices, and common vulnerability classes as well as application security testing methodologies (SAST, DAST, IAST) with familiarity of strengths and limitations.
  • Strong programming skills in multiple languages commonly used in enterprise development (Python, JavaScript, Java, Go, etc.).
  • Experience with modern development workflows and methodologies including CI/CD pipelines, containerization, infrastructure as code, cloud deployment, and generative AI.
  • Ability to translate complex technical concepts into business value or user-friendly explanations.
  • Exceptional written and verbal communication abilities with a portfolio of technical content delivered to technical audiences.
  • Proven public speaking experience at industry conferences, meetups, or similar events.
  • Experience building and nurturing technical communities through contributions, organization, and online engagement.
  • Be able to speak with compassion and empathy to everybody from the CTO/CISO to Software Developer/Intern/Security Engineer.
  • Previous developer relations role such as a developer advocate, technical evangelist, or similar public-facing community position.
Responsibilities
  • Partner with security researchers to investigate emerging security trends and patterns, transforming complex findings into easily understandable and actionable insights that resonate with security and developer audiences.
  • Build and maintain credibility as a trusted security voice by publishing original research, proof-of-concepts, and detailed analysis.
  • Amplify discoveries and messages through compelling story narratives and real-world demonstrations.
  • Address critical security education gaps within developer and security ecosystems.
  • Produce high-impact technical content including conference presentations, in-depth blog posts, video tutorials, and short-form community engagement on social channels and forums.
  • Establish Semgrep as the go-to solution for secure coding by engaging authentically with security practitioners and software development teams wherever they are.
  • Lead technical workshops and hands-on training sessions that demonstrate practical security risks and remediation using Semgrep tools.
  • Cultivate relationships with other influencers within DevSecOps and AppSec communities to expand your reach and gather intelligence.
  • Support internal teammates to be the best version of themselves by sharing your knowledge and best practices across functions.
  • Serve as the voice of the community within Semgrep, translating user pain points and opportunities into product enhancement opportunities.
  • Support engineering and product teams to beta test and provide comprehensive user experience feedback.
Desired Qualifications
  • Prior experience in a fast-paced, tech environment is helpful.

Semgrep provides a security scanning tool that helps software teams identify vulnerabilities in code before production. It works by analyzing code with Semgrep OSS and Pro Engine and integrates into developers’ workflows and ticketing systems for actionable insights. It reduces noise by using reachability analysis to cut false positives from open-source vulnerabilities by up to 98% and achieves fast scans—average under 5 minutes with a 10-second median CI scan. Its goal is to help engineering teams ship secure software faster by continuously finding and fixing vulnerabilities during the SDLC.

Company Size

201-500

Company Stage

Series D

Total Funding

$193M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Menlo Ventures leads $100M Series D in February 2025 for AI expansion.
  • Cathy Polinsky hired as co-CTO in 2025 scales hybrid LLM engineering.
  • OpenAI program selection secures Snowflake, Figma, Dropbox customers.

What critics are saying

  • Snyk siphons SCA revenue via superior GitHub and IDE integrations.
  • GitHub Copilot free scanning commoditizes Semgrep within 18-24 months.
  • Microsoft AI investments embed security in Copilot, destroying standalone demand.

What makes Semgrep unique

  • Semgrep Multimodal combines AI reasoning and rule-based analysis for 8x more vulnerabilities.
  • Semgrep cuts false positives 98% with reachability analysis on third-party dependencies.
  • Semgrep delivers scans in under 5 minutes, median CI at 10 seconds.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

401(k) Retirement Plan

Professional Development Budget

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

2%

2 year growth

0%
The Associated Press
Mar 19th, 2026
Semgrep launches Multimodal, combining AI with rule-based analysis to find 8x more vulnerabilities

Semgrep has launched Semgrep Multimodal, a code security system combining AI reasoning with rule-based analysis for vulnerability detection, triage and remediation. The system finds up to eight times more true positives whilst cutting noise by 50% compared to foundation models alone, and has discovered dozens of zero-day vulnerabilities at customer sites. Built on Semgrep Workflows, the framework enables security teams to automate processes using deterministic tools and AI. Traditional rule-based scanners excel at catching known vulnerabilities but struggle with business logic flaws, whilst LLMs alone produce high false positive rates. Semgrep Multimodal addresses both dimensions by pairing precise programme analysis with LLM reasoning. Semgrep Multimodal is available today, with custom workflows accessible via private beta. Companies including Snowflake, Figma and Dropbox use Semgrep's platform.

Silicon Valley Journals
Feb 5th, 2025
Semgrep Raises $100M Series D Funding Round

Semgrep, a leading application security platform, has secured $100 million in Series D funding, led by Menlo Ventures with participation from existing

Semgrep
Apr 19th, 2023
Semgrep, a code & supply chain security search engine, raises Series C

Announcing our $53M Series C led by Lightspeed Venture Partners

r2c
May 11th, 2022
R2c launched DeepSemgrep for Java and Ruby on May 11th 22'.

Recognizing the value of deeper vulnerability detection, today R2c is announcing DeepSemgrep for Java and Ruby.

r2c
Oct 21st, 2021
R2c is developing Semgrep

When R2c began developing Semgrep that was its main focus, and R2c knew that lightweight static analysis, based on syntax-aware matching, would excel at enforcing secure defaults.

INACTIVE