Skip to main content
Back to jobs

Security Research Manager, Coverage Team

External
semgrep logoSemgrep · San Francisco
$255K–$319K/yrFull-timeRemote4mo ago
AndroidApplication SecurityLessMentoringMovePython
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

You will lead the team of Security Researchers responsible for driving the coverage through rules for Secrets, Code, and Supply Chain: across all of our products. This team owns: Writing high-quality detection rules Advancing research and automation to make rule writing faster and more accurate Measuring and improving the overall quality and coverage of detections As the Manager of the Security Research Coverage team, you'll report to the Head of Security Research. You'll set the roadmap, partner with Product Management to focus on the most impactful detection areas, and drive continuous improvements in both accuracy and breadth of our vulnerability coverage. Success in this role means leading a team that delivers world-class detections, scales rule generation through automation and AI, and pushes the boundaries of what modern vulnerability research can achieve. You will: Hire, develop, and grow the team, cultivating a productive, engaging, diverse, and inclusive work environment that aligns with Semgrep's core values Work closely with product management, sales, and product development teams across all product lines Understand, measure, and elevate the velocity and quality of Semgrep detection rule delivery Prioritize your team's work and schedules, balancing current product needs with strategic research that will help scale the team through AI and automation Contribute to the technical direction and to the research (depending on your profile) Directly impact the security posture of many customers by improving the quality of our detection You are ideal for this role if you have: 2+ years experience as a People Manager 5+ years experience as a Tech Lead in the Security space: App Sec Engineer, Security Researcher, Vulnerability Researcher, etc Comfortable working in a fast-paced environments where prototypes are rapidly iterated or discarded Comfortable tech leading and mentoring Security Researchers Excellent proactive communication skills, both verbal and written Fit in our low-ego high-impact culture Excitement about building for customers, iterating fast, and seeing solutions solve real developer problems Curiosity and a love of new technologies, especially AI/ML Comfortable writing code, especially in Python or Rust Some example projects you might work on include: Improve and scale Semgrep's automated pipelines for generating and validating high-confidence detection rules Lead a team to identify and analyze vulnerability patterns (CVEs or from first-principle) across languages and ecosystems, and turn those into detection rules. Example: Improve supply chain reachability product for a given language, Code product can report security issues that cross the Android JNI interfaces, etc. Put in place unified measurements for performance of detection to ensure the best quality across our customers The estimated starting annual salary range for this position is $255,200 to $319,000 USD. The actual base salary will be determined based on a number of factors, which may include job-related skills, relevant experience, qualifications, location, internal equity, and market data. In addition to base salary, total compensation may include equity, variable compensation, and benefits. We view equity as a meaningful part of our compensation philosophy and a way for employees to share in the long-term value they help create. Compensation ranges are reviewed regularly and may be adjusted as the role, individual performance, or market conditions evolve. What we offer (FTE only) Our goal is to competitively and fairly compensate every Semgrep employee with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate

Benefits

Equity / stock options

Additional Information

About Semgrep Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real issues before they ship, powered by security that learns as they build. Semgrep secures code as it's written and provides guardrails that pave the road for developers to move fast and stay secure. Built for builders and trusted by security, Semgrep lives where developers work, delivering fixes without breaking flow, and giving security teams visibility, control, and confidence. Semgrep gets smarter as you build, with AI that learns your context to cut false positives and prioritize reachable vulnerabilities, validated by 95% of security reviewers across 6M+ findings. Semgrep makes zero false positives a reality with AppSec teams triaging 80% fewer false positives across Code and Supply Chain, dramatically shrinking the backlog. Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by leading organizations, including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev .


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at semgrep? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect