Jobless Developer
Greptile logo

Posted 26 days ago

Open

Security Engineer

San FranciscoOn-siteFull-time

AI Summary

Security Engineer at Greptile owns the company's security posture across product, infrastructure, and internal systems, consulting on risky code changes and architecture decisions, fixing pentest findings, managing the bug bounty program, and designing secure product and infrastructure improvements while working directly with engineers to embed security into the build process rather than treating it as a final review step.

About this role

We want to build agents that autonomously validate code changes. Today that looks like AI that reviews pull requests in GitHub, catching bugs and enforcing standards.

Greptile reviews 5B lines of code every month for 22,000+ customers.

Problems we’re excited about

• Coding standards can be idiosyncratic and are often poorly documented; can we build agents that learn them through osmosis like a new hire might?

• Can we identify for each customer what types of PR feedback they do and don’t care about in order to increase signal-to-noise ratio?

• Some bugs are best caught by running the code. Can we autonomously deploy feature branches and use agents to try to break the application?

• How do we secure a product that processes highly sensitive code across cloud, self-hosted, and air-gapped environments?

Trajectory

• 22,000+ customers

• 5B lines of code reviewed every month

• Scaled from $0 to eight figures in ARR

• Raised $30M from Benchmark, Y Combinator, Paul Graham, and Initialized

Team

• We have assembled a small, talent dense team who have scaled critical functions at companies like Stripe, Google, Figma, etc.

Responsibilities

• Own Greptile’s security posture across the product, infrastructure, and internal systems

• Consult on risky code changes and critical architecture decisions

• Fix pentest findings and patch reported vulnerabilities

• Manage our bug bounty program and coordinate vulnerability response

• Design, implement, test, and deploy secure product and infrastructure improvements

• Work directly with engineers to make security part of how we build, rather than a final review step

Qualifications

• B.S. Computer Science or equivalent degree, undergraduate or higher

• 3+ years of software engineering, DevOps, or security engineering experience

• Experience with JavaScript/TypeScript

• Deep knowledge of application, infrastructure, and cloud security

• Experience working on security-critical products and complex architectures

• Strong judgment when evaluating vulnerabilities, technical tradeoffs, and risk

You will like this role if

• You want to work on a product that thousands of developers rely on

• You want real ownership over the security of a fast-growing technical product

• The chaos of high growth and things breaking is exciting to you

• You like being in an office every day around other smart people who are excited about what they’re building

• You love solving very hard problems.

• You specifically prefer working in-person over working remote

Skills

Agent-based Security TestingApplication SecurityBug BountyCI/CDCloud SecurityCode Review AutomationDevOpsGitHubInfrastructure SecurityJavaScriptPentestSecure ArchitectureTypeScriptVulnerability Management

Explore related jobs

Browse these categories

Market data for security engineer roles

All reports →