Logo
Semgrep

Staff AI Product Engineer, Code

Semgrep, Boston, New York, United States

Save Job

Overview

About Semgrep Semgrep is on a mission to make it expensive to exploit software. As the team behind the most popular SAST, we built the Semgrep AppSec Platform to deliver industry-leading code, dependency, and secrets scanning to enable organizations to ship secure code quickly without slowing down development.

With fast, customizable code analysis across large codebases, Semgrep helps teams catch vulnerabilities early and fix them faster. Leading companies like Snowflake, Plaid, Figma, Lyft, and Dropbox rely on Semgrep to secure their software. Semgrep is funded by top investors, including Felicis Ventures, Lightspeed Venture Partners, Menlo Ventures, Redpoint Ventures, and Sequoia Capital.

Role

As an AI product engineer on Semgrep’s Code team, you’ll apply cutting-edge AI/ML tools from industry leaders (e.g. OpenAI, Anthropic, Hugging Face, Amazon, Google) to build user-facing security tools that help developers write and ship secure software faster. Semgrep’s Code product improves the software developers create by identifying real vulnerabilities without slowing them down. You’ll learn about the application-security space, mentor other engineers, collaborate with product managers, security researchers, and application developers, and shape features our customers love. Your work will be key to making Semgrep the world’s leading code analysis project and trusted security platform.

Responsibilities

Integrate AI platform APIs into the Code product

Develop and refine LLM prompt chains for real developer use cases

Experiment with the latest AI/ML advances and determine how they can be productized

Evaluate and fine-tune ML models using human- and machine-generated data

Learn directly from users to understand their needs and deliver features that help them secure their code

Work on major product initiatives end-to-end, from design and prototyping through implementation and deployment

Contribute to technical discussions, roadmap planning, and mentoring within the team

Qualifications

8+ years of experience writing production software

Curiosity and a love of new technologies, especially AI/ML

Experience experimenting with GPT-4/GPT-5, Codex, Claude, or other LLMs; familiarity with ML algorithms and applied research

Comfort working in a fast-paced environment where prototypes are rapidly iterated or discarded

Strong Python skills (experience with other languages a plus)

Interest in prompt engineering, embeddings, and vector databases

Excitement about building for customers, iterating fast, and seeing solutions solve real developer problems

Excellent and proactive communication skills, both verbal and written

Projects you might work on

Building new detection capabilities that utilize fast, deterministic static analysis technologies within an autonomous LLM-driven agentic code analysis pipeline

Identifying causes of and solving for non-determinism in model output

Generating real-time, AI-powered remediation guidance for vulnerabilities in developers’ own code

Automatically drafting secure code suggestions that align with project context and frameworks

Building and orchestrating purpose-built custom agents for evaluating and triaging code security risks

Enhancing the IDE experience with AI-assisted security insights and explanations

Experimenting with AI-powered rule generation to help customers expand and tailor their Code product usage

Compensation Salary Range: $202,000 - $238,000

Our compensation package includes equity and benefits in addition to salary. Please note that the range listed is for someone based in the San Francisco Bay Area.

What We Offer Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. We generate internal compensation bands that are used when discussing and negotiating salaries and update them based on market data to ensure they’re above the average for comparable roles. We also invest in our employees’ well-being and long-term success with comprehensive health plans, generous vacation time, 401k, learning stipends, and more. Our benefits are for everyone, so that you’re taken care of, and we work with individuals to ensure they have what they need.

Who We Are We have people from France and the Philippines, physics and philosophy, formal methods research and full-fledged corporations. We’re new parents and new grads, aspiring authors and aspiring Americans, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. We believe respect and honesty go hand in hand, and prioritize both. Semgrep is an equal-opportunity employer seeking a diverse range of backgrounds. We value what you are — including your cultural heritage, socioeconomic status, age, race, gender, sexual orientation, disabilities. We value what matters to you — your family, religion, politics, and your weekend pursuits. If you’re exceptional in your role, believe in Semgrep’s mission, and share Semgrep’s values, you belong here.

Please Note: For US-based roles open to remote work, we are currently able to hire employees in the following states only: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Hampshire, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, and Washington.

Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Engineering and Information Technology

Industries

Software Development

#J-18808-Ljbffr