
Senior/Staff Security Researcher
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Arizona, +20 more states.
• Develop scalable detection mechanisms. Design and implement security workflows that integrate deterministic analysis (such as taint analysis, reachability, and static slicing) with LLM reasoning to identify genuine vulnerabilities (including SSRF, IDOR, injection, authentication gaps, supply-chain risks, and more) across diverse languages and frameworks.
• Enable LLMs for security-critical tasks. Create agentic pipelines and prompts that are accurate, cost-efficient, and reliable: atomic, well-defined steps anchored in deterministic contexts, focusing on hallucination, confidence calibration, and the visibility of sensitive code to various models.
• Tackle challenging issues in automated triage and validation. Assist in bridging the gap between 'a finding exists' and 'this finding is valid and merits a developer’s attention,' allowing us to implement workflows widely and validate results at scale rather than relying on extensive manual reviews.
• Ensure quality through evaluations. Design benchmarks and evaluation cycles based on real customer codebases, moving beyond synthetic datasets to genuinely assess the effectiveness of a workflow.
• Integrate security reasoning into tools. Model vulnerability categories, taint sources/sinks/sanitizers, and security attributes as reusable, version-controlled logic that scales across different ecosystems.
• Rapidly adapt to new domains. Immerse yourself in unfamiliar languages, frameworks, and technologies, understand how vulnerabilities emerge in those contexts, and translate that knowledge into effective detection strategies.
• Prototype innovative products. Collaborate with Engineering and Product teams to ideate, prototype, and validate new capabilities, writing tangible (even if not always production-ready) code, with a strong focus on customer and user needs.
• Share your insights. Write blog posts, deliver presentations, create cheat sheets and workshops, and represent Semgrep’s research to the broader community.
• Lead and strategize impactful research. Determine the research direction based on industry trends, emerging threats, and future developments, transforming that vision into initiatives that advance our products and the wider security landscape.
• Solid application security knowledge: understanding fundamental vulnerability categories, their origins and manifestations across various languages and frameworks, along with the capability to delve into intricate details.
• Proven experience in identifying vulnerabilities and communicating their implications and contexts to the developers tasked with remediation (in roles such as security researcher, consultant, or security engineer).
• Proficient fluency in writing and auditing code in two or more programming languages, sufficient to create tools and prototypes, not merely to read code.
• A builder’s mindset: you prefer to automate challenges rather than tackle them manually, deriving satisfaction from tools that significantly enhance your impact.
• A genuine curiosity about or hands-on experience with applied AI/LLMs (including agentic workflows, prompt engineering, RAG, evaluations, or LLM tool utilization), along with a discerning perspective on where models are beneficial and where they fall short.
• Experience in developing or managing LLM/agent systems in production environments: such as pydantic-ai, MCP, multi-provider orchestration, evaluation frameworks, and awareness of cost/latency factors.
• A strong inclination towards continuous learning, and enthusiasm (not hesitation) when tackling an unfamiliar language, framework, or technology.
• Comfort in working autonomously: you can decompose ambiguous problems into manageable milestones, drive progress, and take ownership of outcomes without close supervision.
• Enjoyment in sharing your knowledge through writing, presentations, and teaching, both within and outside of Semgrep.
• Our compensation package encompasses equity and benefits in addition to salary.
• We prioritize our employees’ well-being and long-term success through a competitive benefits program that aligns with market standards and meets or exceeds local requirements across all hiring regions.
• Benefits offerings vary by location to align with local norms and regulations.
Corteva Agriscience
Fortive
Cummins Inc.
Corteva Agriscience
Get handpicked remote jobs straight to your inbox weekly.