# Senior/Staff Security Researcher at Semgrep

- Company: Semgrep
- What the company does: An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions. Backed by Lightspeed, Sequoia and Felicis.
- Company website: https://semgrep.dev/
- Type: Startups
- Level: Senior
- Location: Remote - US
- Work setup: Remote
- Pay: $190K to $319K base salary per year (USD)
- Posted: 2026-07-24
- Apply by: 2026-10-08
- Apply: https://jobs.ashbyhq.com/semgrep/2cfe1f53-4665-432c-915d-b4e6459c4ad7
- Page: https://www.1752.vc/careers/jobs/semgrep-senior-staff-security-researcher/

## About the role

The way software gets secured is changing faster than at any point in Semgrep’s history. Code is increasingly written by AI agents, and the security work that used to live in researchers’ heads and runbooks is increasingly something we can encode, automate, and run at scale. Our security research team is building the systems that make that real, and we’re looking for a curious security researcher who wants to build them with us.

## What they're looking for

- Strong application security expertise: fundamental vulnerability classes, how they arise and manifest across languages and frameworks, and the ability to go deep into the details
- Experience finding vulnerabilities and explaining their impact and context to the developers responsible for fixing them (as a security researcher, consultant, security engineer)
- Genuine fluency writing and auditing code in two or more languages, enough to build tools and prototypes, not just read code
- A builder’s mindset: you’d rather automate a problem than do it by hand, and you get satisfaction from tooling that scales your impact many times over
- Real curiosity about, or hands-on experience with, applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, or LLM tool use), and clear-eyed judgment about where models help and where they don’t
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness

Tags: Engineering Org
