Startups · AI

Product Engineer, Security

Greptile · San Francisco · On-site

← All jobs
About Greptile

AI Code Reviews that understand your entire codebase. Automate PR reviews, catch bugs faster, improve code quality with AI-driven analysis. Try Greptile free! Backed by Y Combinator.

About the role

Build Greptile’s security product from the ground up, including codebase scanning, a security-focused PR bot, continuous pentesting, and tools for code analysis, security testing, and vulnerability reproduction. Improve how agents understand codebases, identify and investigate potential vulnerabilities, reproduce them, and give developers and coding agents the information they need to fix them.

What they're looking for

  • B.S. Computer Science or equivalent degree, undergraduate or higher
  • 1+ years of software or DevOps engineering experience
  • Experience with JavaScript/TypeScript
  • Security engineering or research experience through source-code auditing, offensive security work, application security engineering, original bug bounty findings, or strong CTF performance
  • Experience building security products or LLM-powered tools and agents is a strong plus
More about this role

Greptile is an AI code reviewer that catches bugs and anti-patterns in pull requests with complete context of the codebase. Hundreds of top software companies, from YC startups to big tech, and teams in finance, healthcare, and defense, use Greptile to merge PRs faster and catch more bugs.

Greptile reviews 5B lines of code every month for 22,000+ customers. A new repo starts using Greptile every 2 minutes. We also uniquely offer self-hosted, air-gapped deployments for enterprises across defense, financial services, and healthcare.

We’re looking for a product engineer with strong security expertise to build Greptile’s security product from the ground up. You’ll work directly on the agents and infrastructure that help find, validate, reproduce, and fix vulnerabilities, turning security experience into specialized software that thousands of engineering teams will use every day.

Security is the highest-stakes thing an AI reviewer can get right or wrong. What does a security product developers actually trust look like: codebase-wide scanning, a security-focused PR bot, continuous pentesting, or something nobody has built yet?

Coding standards can be idiosyncratic and are often poorly...

Read the full posting on Greptile's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.