Senior Full Stack Software Engineer
Job description
About the role
You will architect and deliver the full lifecycle of features that power Semgrep's code security platform for builders. You will translate abstract product requirements into reliable frontend interfaces and robust backend services while maintaining a fast and reliable user experience. You will partner daily with designers and product managers to iterate on flows that help AppSec professionals and developers achieve their security goals with confidence. You will own the end-to-end implementation of features across our TypeScript and React frontend and our Python, Flask, and SQLAlchemy backend. You will ensure these systems scale gracefully as we grow rapidly this year, balancing performance, reliability, and developer experience. You will contribute to a codebase that learns as users build, reducing false positives and prioritizing reachable vulnerabilities through intelligent, context-aware systems. You will help make zero false positives a reality by enabling AppSec teams to triage significantly fewer false positives across Code and Supply Chain.
Key facts
What you'll do
Investigate and refine user workflows to transform complex security data into clear, actionable insights within the Semgrep interface.
Collaborate with security experts to codify new detection rules and translate them into intuitive configuration options for diverse users.
Design and implement resilient backend services that process analysis results, manage findings, and support scalable rule evaluation.
Optimize frontend performance to ensure rapid rendering of large codebases and dense security findings without compromising interactivity.
Instrument critical user journeys to capture telemetry that informs product decisions and improves the reliability of the developer experience.
Partner with cross-functional teams to define and maintain data contracts between frontend, backend, and third-party integrations.
Lead the implementation of end-to-end feature delivery, coordinating with design, security, and infrastructure teams to meet release goals.
Evaluate and integrate emerging patterns in code analysis to keep Semgrep at the forefront of static and semantic security detection.
Champion quality and reliability by writing tests, improving observability, and driving fixes that prevent regressions in production.
Mentor junior engineers by providing clear technical direction and examples that uphold Semgrep's engineering standards and product values.
Contribute to architectural decisions that balance tradeoffs between performance, security, correctness, and developer ergonomics.
Help define and evolve the technical vision for the product, ensuring alignment with long-term strategic objectives for code security.
Support the deployment and operation of features in Kubernetes environments on AWS, maintaining high availability and rapid rollback capabilities.
Engage with the community and internal stakeholders to gather feedback and translate it into concrete improvements across the stack.
Requirements
You possess a Bachelor's or Master's degree in Computer Science, Engineering, or a related technical field, or equivalent practical experience.
You have 5 or more years of professional software engineering experience building and shipping products.
You demonstrate mastery of modern frontend frameworks, particularly React, and fluency in TypeScript for building type-safe, maintainable user interfaces.
You exhibit strong proficiency in Python, with experience in asynchronous programming patterns and integration with web frameworks like Flask.
You understand relational database design and are comfortable writing complex queries using SQLAlchemy or similar ORMs.
You have hands-on experience with containerization and orchestration tools, especially Docker and Kubernetes, in production environments.
You are comfortable working in cloud environments, with proven experience deploying and operating services on AWS.
You show consistent ability to debug intricate issues across frontend and backend layers while maintaining system stability.
You communicate clearly and respectfully with both technical and non-technical stakeholders, articulating tradeoffs and rationale.
You embrace Semgrep's mission of building security tools that empower invention without friction and align with our core values.
Nice to have
Experience contributing to open source projects at scale.
Familiarity with security tooling, code analysis, or static application security testing concepts.
Knowledge of CI/CD pipelines and infrastructure as code practices.
Exposure to formal methods or program analysis research.
Practical notes
This is a hybrid role with the expectation you'll join us 3+ days per week in our San Francisco, New York, Boston or Denver offices depending on team. Remote employment will be considered for exceptional candidates as well.
Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan,