Senior/Staff Security Researcher
Job description
Senior/Staff Security Researcher
About the role
Semgrep is transforming how software security is handled, especially as AI plays a larger role in code creation. We are seeking a motivated security researcher to help build the automated systems that will define the future of secure development. You will have the freedom to define your research path and directly impact security teams globally by translating your findings into practical solutions.
Key facts
What you'll do
Develop scalable security detection methods by combining deterministic analysis techniques like taint tracking and reachability with large language model (LLM) reasoning to identify vulnerabilities across various programming languages and frameworks.
Enhance the reliability of LLMs for security-sensitive tasks by creating precise, cost-effective, and trustworthy agentic pipelines and prompts that are grounded in deterministic code context.
Address the challenge of bridging the gap between identifying a potential finding and confirming its validity and relevance to developers, enabling broad workflow execution and efficient validation.
Construct benchmarks and evaluation frameworks using real customer codebases to accurately measure the effectiveness of security workflows.
Translate security expertise, including vulnerability patterns and sanitization logic, into reusable and versioned code that can be applied across different software ecosystems.
Quickly learn and adapt to new programming languages, frameworks, and technologies, understanding how vulnerabilities manifest and developing detection strategies.
Collaborate with Engineering and Product teams to conceptualize, prototype, and validate new product features, demonstrating a strong understanding of customer needs.
Share your research findings through publications, presentations, and educational materials for the broader security community.
Lead and strategize research initiatives by identifying industry trends and emerging threats, and translating these into impactful work for Semgrep's products and the security field.
Requirements
Possess deep knowledge of application security fundamentals, including common vulnerability classes, their origins, and manifestations across diverse languages and frameworks.
Demonstrate experience in discovering vulnerabilities and effectively communicating their impact and context to development teams, either as a researcher, consultant, or security engineer.
Exhibit proficiency in writing and reviewing code in at least two programming languages, sufficient for building tools and prototypes.
Adopt a builder's mentality, prioritizing automation and scalable solutions to amplify impact.
Show genuine curiosity or practical experience with applied AI/LLMs, including agentic workflows, prompt engineering, Retrieval Augmented Generation (RAG), evaluation methods, or LLM tool usage, with a balanced perspective on their capabilities and limitations.
Have experience building or managing LLM/agent systems in production environments, including familiarity with tools like pydantic-ai, MCP, multi-provider orchestration, evaluation frameworks, and considerations for cost and latency.
Exhibit a strong drive for continuous learning and enthusiasm for tackling unfamiliar technologies.
Operate effectively with autonomy, capable of defining and executing on ambiguous problems with clear ownership of outcomes.
Enjoy sharing knowledge through writing, presentations, and teaching, both internally and externally.
Nice to have
Background in program analysis or compilers, including experience with Abstract Syntax Trees (ASTs), Intermediate Representations (IRs), call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
Previous experience with Static Application Security Testing (SAST) tools or Semgrep itself, whether as a user, competitor, or contributor.
Familiarity with distributed or durable workflow systems, graph databases, or cloud-native infrastructure such as Kubernetes, Argo, or Temporal.
Experience working in fast-paced startup environments or similar teams within larger organizations.
A history of publishing or presenting security research at conferences or in academic venues.
Experience in training or fine-tuning smaller language models for security or code-related tasks, including data curation, fine-tuning, and evaluation, particularly in scenarios where sensitive code cannot be shared with third-party providers.
Skills & tools
Application Security, Vulnerability Research, LLMs, Agentic Workflows, Prompt Engineering, RAG, Evaluation Frameworks, LLM Tool Use, Python, Go, Java, JavaScript, C/C++, Static Analysis, Taint Analysis, Reachability Analysis, Program Analysis, Compiler Internals, SAST, Kubernetes, Argo, Temporal, Graph Databases.
Practical notes
This role is open to remote work within the US. We can currently hire employees in the following states: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin. Our compensation includes salary, equity, and benefits. We offer a comprehensive benefits program designed to support employee well-being and long-term success, which varies by location to meet local requirements and norms.