ForgeApply · Job listing
Senior/Staff Security Researcher
Semgrep
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
ABOUT SEMGREP
Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it’s written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog.
Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev http://semgrep.dev.
ABOUT THE ROLE
The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.
You'll set your own research direction, and by working directly with our customers you'll ship that research to security teams of all shapes and sizes worldwide, making an impact well beyond shipping a product. You'll have what most researchers never get: a vast corpus of real-world code to prove out ideas, a program analysis team building the engine itself, frontier models and compute to experiment at scale, and a platform to publish to one of the largest security audiences in the world. You'll blend application security, program analysis, and applied AI to make our customers and the security community safer.
You’ll help improve our products and build what comes next, across offerings like:
- Semgrep Code https://semgrep.dev/products/semgrep-code/: our SAST engine, pairing deterministic analysis for classic vulnerability classes with AI-powered reasoning to surface deeper, cross-file flaws with fewer false positives.
- Semgrep Workflows https://semgrep.dev/products/semgrep-workflows/: a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
- Semgrep Guardian https://semgrep.dev/products/semgrep-guardian/: securing AI-generated code at the moment it’s written, catching vulnerabilities, malicious packages, and secrets across coding agents like Claude Code, Cursor, and Windsurf.
- Semgrep Multimodal https://semgrep.dev/products/semgrep-multimodal/: blending AI reasoning with rule-based detection to cut false positives and learn from triage decisions over time.
The harder problem underneath is one you’d help solve: making automated detection you can actually trust. That means grounding it in real program analysis (taint, reachability, precise code context), so every finding is reproducible and traceable to evidence in the code, not a guess.
You’ll meet developers and security professionals across organizations from small startups to large enterprises. You’ll work in a transparent culture where you can see and influence the decisions that make a company successful, and you’ll help establish security research as a true peer to Engineering, Product, and Design, not a downstream QA function.
Prior experience in a fast-paced tech environment helps, but we care more about your curiosity, security instincts, and appetite for building than your pedigree. If this excites you but you don’t meet every requirement, apply anyway.
WHAT YOU’LL DO
- Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks.
- Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code.
- Push on hard problems in automated triage and validation. Help close the gap between “a finding exists” and “this finding is real and worth a developer’s time,” so we can run workflows broadly and validate results at scale rather than by weeks of manual review.
- Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good.
- Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection.
- Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user.
- Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community.
- Lead and plan research with impact. Set the d
Ready to apply to Semgrep?
Apply in about a minuteSimilar jobs
- Senior Security Researcher — Clarityinnovates · USA
- Senior Security Researcher — Human · Remote
- Senior Security Researcher — Censys · Remote
- Senior/Staff Security Engineer — Pomelocare · Remote
- Senior Security Research Scientist — Censys · Remote
- Senior Staff Security Engineer — Formenergy · Berkeley, CA
- Principal / Staff Security Engineer — Aidashinc · Palo Alto, California, United States
- Senior/Staff Infrastructure Security Engineer — Abridge · Remote
More like this: More jobs at Semgrep · Browse all jobs