Senior Security Engineer, Application Security
Trail of Bits- Full Time
- Senior (5 to 8 years)
Candidates should possess 8+ years of hands-on experience identifying, analyzing, and remediating security vulnerabilities across web applications, cloud infrastructure, and APIs, along with a proven track record of security research contributions such as CVE discoveries, security advisories, or published research. They should have a deep understanding of OWASP Top 10, secure coding practices, and common vulnerability classes, as well as application security testing methodologies (SAST, DAST, IAST) with familiarity of their strengths and limitations.
The Staff Security Advocate will partner with security researchers to investigate emerging security trends and patterns, transforming complex findings into easily understandable and actionable insights for security and developer audiences. They will build and maintain credibility as a trusted security voice by publishing original research, proof-of-concepts, and detailed analysis, and produce high-impact technical content including conference presentations, blog posts, video tutorials, and community engagement. The role involves establishing Semgrep as the go-to solution for secure coding by engaging authentically with security practitioners and software development teams, leading technical workshops and hands-on training sessions, cultivating relationships with influencers, and serving as the voice of the community within Semgrep, translating user pain points into product enhancement opportunities, and supporting internal teammates.
Vulnerability detection tool for software development
Semgrep offers a tool that helps security engineers and developers identify and fix vulnerabilities in their code before deployment. It integrates into existing workflows, providing actionable insights while significantly reducing false positives in open-source vulnerabilities by up to 98% through reachability analysis. The tool is designed for speed, with average scan times of less than 5 minutes, allowing teams to quickly address security issues. Semgrep aims to enhance the security of the software development life cycle, improving productivity and reducing technical debt.