Full-Time

Senior Software Engineer-Security Workflows

Updated on 2/10/2025

Semgrep

Semgrep

51-200 employees

Vulnerability detection tool for software development

Enterprise Software
Cybersecurity

Compensation Overview

$176k - $207kAnnually

+ Equity + Benefits

Mid, Senior

Boston, MA, USA + 2 more

More locations: San Francisco, CA, USA | New York, NY, USA

Candidates are required to be in-office 2-3 days per week.

Category
Security Engineering
Software Engineering
Required Skills
Python
JavaScript
Postgres
Data Analysis

You match the following Semgrep's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • 4+ years of experience writing production software and building web applications
  • Experience with Python, Javascript, and Postgres
  • Experience with ClickHouse, or experience building reporting/analytics solutions
  • Excellent and proactive communication, both verbal and written
Responsibilities
  • Work on major product initiatives end-to-end, from user-research through design, implementation, and deployment
  • Help set technical and product direction, collaborating with the team to determine the future of the product, what features to build, and how to build them
  • Learn from users to understand their needs, build products to help keep them secure, and work with them to help them scale their security programs
  • Advocate for and develop intuitive, simple, robust APIs that solve a wide variety of complex problems using simple, elegant abstractions
  • Ensure continual, high-availability operation of services using modern site-reliability practices, including participation in an on-call rotation
  • Advise and mentor other engineers via thoughtful code reviews, planning discussions, technical documentation, and formal mentorship
Desired Qualifications
  • Excitement about building for customers, learning their needs, iterating fast, and seeing your solutions solve their core problems

Semgrep provides a software solution that helps security engineers and developers find and fix vulnerabilities in their code before it is deployed. The tool integrates into existing workflows, allowing teams to receive actionable insights that enhance their software development life cycle (SDLC). One of its standout features is the ability to significantly reduce false positives in vulnerability detection by up to 98% through reachability analysis, ensuring that only real threats are flagged. This focus on accuracy helps streamline the security process, making it easier for developers to trust the results and take action. Semgrep's tool is designed for speed, with average scan times under 5 minutes and median continuous integration (CI) scan times of just 10 seconds, which boosts overall productivity. The company aims to provide a reliable and efficient solution for engineering teams looking to enhance their security practices.

Company Stage

Series D

Total Funding

$187.7M

Headquarters

San Francisco, California

Founded

2017

Growth & Insights
Headcount

6 month growth

1%

1 year growth

0%

2 year growth

16%
Simplify Jobs

Simplify's Take

What believers are saying

  • Increased demand for integrated security solutions in CI/CD pipelines boosts Semgrep's market relevance.
  • The rise of supply chain attacks heightens the need for Semgrep's third-party dependency detection.
  • The shift towards DevSecOps aligns with Semgrep's focus on developer-friendly security tools.

What critics are saying

  • Increased competition from Snyk and GitHub's CodeQL could impact Semgrep's market position.
  • Over-reliance on funding rounds may lead to financial instability if future rounds falter.
  • Rapid technological changes in cybersecurity could render Semgrep's tools obsolete without innovation.

What makes Semgrep unique

  • Semgrep reduces false positives in vulnerabilities by up to 98% with reachability analysis.
  • The tool integrates seamlessly into existing workflows, enhancing SDLC processes for engineering teams.
  • Semgrep's average scan time is under 5 minutes, with a median CI scan time of 10 seconds.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

401(k) Retirement Plan

Professional Development Budget

Flexible Work Hours

Remote Work Options