Senior/Staff Security Researcher
Core
Build automated security detection systems combining deterministic program analysis with AI/LLM reasoning to find and validate real-world vulnerabilities across codebases.
Role type
Senior/Staff Security Researcher (Applied AI & Program Analysis)
Builds
Semgrep Code (SAST engine), Semgrep Workflows (automated security pipelines), Semgrep Guardian (AI code security), Semgrep Multimodal
Domain
Application Security, Program Analysis, Applied AI/LLMs
Deliverable
production ML models | product features
Required skills
Application security expertise, vulnerability detection and explanation, fluency in 2+ programming languages, agentic workflow design, LLM evaluation and calibration, tooling development, autonomous project management
Preferred skills
Program analysis/compilers background, SAST tooling experience, distributed workflow systems, startup experience, security research publication
Technologies
LLMs, agentic workflows, prompt engineering, RAG, pydantic-ai, MCP, Kubernetes, Argo, Temporal
Responsibilities
Design and ship security workflows combining deterministic analysis with LLM reasoning, engineer agentic pipelines for security-critical tasks, build evaluation benchmarks for automated triage, encode security judgment into reusable tooling, prototype new security capabilities, publish research and share knowledge with the community
Seniority
Senior/Staff, hands-on IC with strategic direction