Senior/Staff Security Researcher
Job Description
ABOUT SEMGREP Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog. Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev. ABOUT THE ROLE The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us. You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer. You’ll help improve our products and build what comes next, across offerings like: - Semgrep Code https://semgrep.dev/products/semgrep-code/: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
- Semgrep Workflows https://semgrep.dev/products/semgrep-workflows/: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
- Semgrep Guardian https://semgrep.dev/products/semgrep-guardian/: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
- Semgrep Multimodal https://semgrep.dev/products/semgrep-multimodal/: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
- Make LLMs viable for security-critical work.
- Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
- Build and defend quality with evals.
- Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn new territory fast.
- Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
- Share your work.
- Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.
- Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer).
- Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code.
- A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over.
- Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t.
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
- A strong desire to keep learning, and excitement (not reluctance) when handed an unfamiliar language, framework, or technology.
- Comfort operating with autonomy: you can take an ambiguous problem, break it into milestones, drive it forward, and own the outcome without close oversight.
- Enjoyment in sharing what you learn, through writing, talks, and teaching, inside and outside Semgrep.
- Experience with SAST tooling or Semgrep itself (as a user, competitor, or contributor).
- Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
- Experience at fast-paced startups, or on similarly minded teams inside larger companies.
- A track record of publishing or presenting security research.
- Experience training or fine-tuning small/local language models for security or code tasks (data curation, fine-tuning, evaluation), especially where sensitive code can't be sent to third-party providers.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.