
51 - 200 employés
Fondée en 2017
🔒 Cybersecurity
☁️ SaaS
Cybersecurity • SaaS
Semgrep est une entreprise spécialisée dans la sécurité des applications qui propose une plateforme AppSec SaaS concentrée sur les tests de sécurité des applications statiques (SAST), l'analyse de composition logicielle (SCA) pour les vulnérabilités de la chaîne d'approvisionnement et la détection de secrets. Elle combine un balayage rapide par règles conscientes du code, des règles communautaires et gérées, ainsi que des recommandations de triage et des correctifs alimentés par l'IA pour réduire les faux positifs et intégrer des retours sur la sécurité dans les flux de travail des développeurs et les pipelines CI/CD. Les produits et le moteur de Semgrep sont conçus pour aider les équipes d'ingénierie et de sécurité à automatiser, étendre et opérationnaliser la sécurité à travers les organisations.
🕒 il y a 1 mois
🌵 Arizona, California, +19 états de plus – Distant
💵 $190 000 - $319 000 / an
⏰ Temps Plein
🟠 Senior
👮♂️ Cybersécurité / Ingénieur Sécurité
👻 Score fantôme 3%
🗣️🇺🇸🇬🇧 Anglais requis
Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

51 - 200 employés
Fondée en 2017
🔒 Cybersecurity
☁️ SaaS
Cybersecurity • SaaS
Semgrep est une entreprise spécialisée dans la sécurité des applications qui propose une plateforme AppSec SaaS concentrée sur les tests de sécurité des applications statiques (SAST), l'analyse de composition logicielle (SCA) pour les vulnérabilités de la chaîne d'approvisionnement et la détection de secrets. Elle combine un balayage rapide par règles conscientes du code, des règles communautaires et gérées, ainsi que des recommandations de triage et des correctifs alimentés par l'IA pour réduire les faux positifs et intégrer des retours sur la sécurité dans les flux de travail des développeurs et les pipelines CI/CD. Les produits et le moteur de Semgrep sont conçus pour aider les équipes d'ingénierie et de sécurité à automatiser, étendre et opérationnaliser la sécurité à travers les organisations.
• Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks. • Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code. • Push on hard problems in automated triage and validation. Help close the gap between 'a finding exists' and 'this finding is real and worth a developer’s time,' so we can run workflows broadly and validate results at scale rather than by weeks of manual review. • Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good. • Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems. • Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection. • Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user. • Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community. • Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
• Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details. • Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer). • Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code. • A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over. • Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t. • Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness. • A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology. • Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight. • Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
• Our compensation package includes equity and benefits in addition to salary. • We invest in our employees’ well-being and long-term success through a competitive, market-aligned benefits program that meets or exceeds local market standards across all of the regions in which we hire. • Benefits offerings vary by location to reflect local requirements and norms.
Postuler Maintenant🕒 il y a 1 mois
Senior Security Engineer embedded with JLL’s Falcon AI team. Securing agent identity, MCP integrations, permissions, and production code.
🇺🇸 États-Unis – Télétravail
💵 $200 000 - $225 000 / an
⏰ Temps Plein
🟠 Senior
👮♂️ Cybersécurité / Ingénieur Sécurité
🗣️🇺🇸🇬🇧 Anglais requis
Cloud
Cyber Security
🕒 il y a 1 mois
Cybersecurity Engineering Lead protecting clients' digital assets from cyber threats via designing, implementing, and maintaining security solutions. Collaborating with teams on various projects including compliance and risk management.
🇺🇸 États-Unis – Télétravail
💵 $130 000 - $180 000 / an
⏰ Temps Plein
🟠 Senior
👮♂️ Cybersécurité / Ingénieur Sécurité
🗣️🇺🇸🇬🇧 Anglais requis
🕒 il y a 1 mois
Senior Director of Managed Services leading networking and security teams at Advizex. Responsible for managing high-performance teams and overseeing complex enterprise environments.
🇺🇸 États-Unis – Télétravail
💵 $175 000 - $275 000 / an
⏰ Temps Plein
🟠 Senior
👮♂️ Cybersécurité / Ingénieur Sécurité
🗣️🇺🇸🇬🇧 Anglais requis
🕒 il y a 1 mois
Senior Cybersecurity Engineer responsible for enhancing security across AWS, Kubernetes, and CI/CD at Indico. Collaborating with CISO and CTO to implement technical controls.
🇺🇸 États-Unis – Télétravail
💰 €22 000 000 Series B en 2020-12
⏰ Temps Plein
🟠 Senior
👮♂️ Cybersécurité / Ingénieur Sécurité
🗣️🇺🇸🇬🇧 Anglais requis
🕒 il y a 1 mois
Sr. Security Engineer owning Datadog SIEM detection and incident response. Securing Solace’s U.S. healthcare advocacy platform in a HIPAA-regulated environment.
🇺🇸 États-Unis – Télétravail
⏰ Temps Plein
🟠 Senior
👮♂️ Cybersécurité / Ingénieur Sécurité
🦅 Parrain de Visa H1B
🗣️🇺🇸🇬🇧 Anglais requis