Senior Security Engineer, Application Security
Trail of Bits- Full Time
- Senior (5 to 8 years)
Semgrep is on a mission to make it expensive to exploit software. As the team behind the most popular SAST, we built the Semgrep AppSec Platform to deliver industry-leading code, dependency, and secrets scanning to enable organizations to ship secure code quickly without slowing down development.
With fast, customizable code analysis across large codebases, Semgrep helps teams catch vulnerabilities early and fix them faster. Leading companies like Snowflake, Plaid, Figma, Lyft, and Dropbox rely on Semgrep to secure their software.
Semgrep is funded by top investors, including Felicis Ventures, Lightspeed Venture Partners, Menlo Ventures, Redpoint Ventures, and Sequoia Capital.
The Semgrep Security Advocacy team drives awareness and preference for Semgrep within both application security and software development communities. A Security Advocate will educate teams on secure coding, activate them through delightful product onboarding experiences, and encourage community champions to become force-multipliers that amplify our messages. We work extremely hard but also bring the fun to cross-functional.
This role is remote friendly, with some travel expected.
Prior experience in a fast-paced, tech environment is helpful, but we are more interested in your curiosity and passion for learning and technical skills than your pedigree. So if this opportunity excites you but you don’t meet the exact requirements, apply anyway!
Security Research & Thought Leadership
Content Creation
Community Building & Evangelism
Product Feedback Loop
Technical Security Expertise
Software Development & Tools
Vulnerability detection tool for software development
Semgrep offers a tool that helps security engineers and developers identify and fix vulnerabilities in their code before deployment. It integrates into existing workflows, providing actionable insights while significantly reducing false positives in open-source vulnerabilities by up to 98% through reachability analysis. The tool is designed for speed, with average scan times of less than 5 minutes, allowing teams to quickly address security issues. Semgrep aims to enhance the security of the software development life cycle, improving productivity and reducing technical debt.