Passa al contenuto principale

Semgrep

static analysis

An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.

Vedi le 13 posizioni aperteChiedi di Semgrep3 nuove posizioni questa settimana

Assume ora

13posizioni aperte+18%rispetto alla settimana scorsa

Semgrep sta assumendo?

Sì. Al 8 ottobre 2026, Semgrep ha 13 posizioni aperte su Metaintro. 5 sono state pubblicate negli ultimi 30 giorni.

Posizioni aperte

Prima le più recenti. Retribuzione mostrata quando l’annuncio la indica.

Andamento delle assunzioni

Quanto velocemente Semgrep apre nuove posizioni e con quale modalità di lavoro.

Nuove posizioni al mesePosizioni pubblicate per la prima volta nel mese

7
0
2
3
luglioagostosettembreottobre
ottobre: 3 nuove posizioni.

Modalità di lavoro delle posizioniQuota di posizioni aperte

42%
42%
17%
IbridoDa remotoNon indicato
Il 84% delle posizioni è ibrido o da remoto.

Clienti

Tutte le 14 aziende che Semgrep indica come clienti.

Clienti che assumono ora7

Casi di studio7

Cosa dicono i loro clienti

Citazioni di persone che lavorano presso i clienti di Semgrep.

“I became an advocate of Semgrep when we found an open source package where the vulnerability actually affected us in an exploitable way, and we would have otherwise missed it as part of the sea of noise in other tools.”

Rob Picard · Security Lead · Vanta

“While getting an awesome scanner like Semgrep Code for our SAST was great, Reachability Analysis via Semgrep Supply Chain was the cherry on top.”

Aleksandr Krasnov · Staff Security Engineer · Thinkific

““Getting the developers aligned on a SAST product and making them use it is the hardest part of the job for an AppSec Engineer. We were able to achieve this with Semgrep Code.””

Aleksandr Krasnov · Staff Security Engineer · Thinkific

““With Semgrep, we’ve not only cut scan times dramatically, we’ve also built a more automated, scalable AppSec program that meets our developers where they work.””

Mubasher Chaudhary · Application Security Engineer · SoSafe

““We treat engineers as partners, not just stakeholders. Semgrep helps us meet them where they are.””

SoSafe
Mostra altre 23 citazioni

““Now, developers see exactly what the issue is, right in the pull request. They know what to fix and why without switching tools,””

Mubasher Chaudhary · SoSafe

“Semgrep isn’t just another scanner,” says Tschammer. “It’s part of how we build.”

Tschammer · Synthesia

“Pairing Wiz with Semgrep gave us critical context, ” says Tschammer. “We’re no longer chasing noise. We can zero in on what’s actually reachable and prioritize what truly matters.”

Tschammer · Synthesia

“Everyone — security, engineering, leadership cares about velocity,” says Tschammer . “But it has to be safe. Semgrep gives us the confidence to move fast without cutting corners.”

Tschammer · Synthesia

“Semgrep helped us strike that balance. It gives developers just enough signal at the right moment without overwhelming them.”

O’Sullivan · Synthesia

“We discovered Semgrep through a mix of online research and peer feedback,” recalls Máirtín O’Sullivan, Staff Product Security Engineer. “We were immediately impressed by the transparency, the customization, and how quickly we could write new rules. But the real game-changer was reachability analysis. It helped us cut through the noise and focus on what actually mattered.”

Máirtín O’Sullivan · Staff Product Security Engineer · Synthesia

““With Semgrep, I trust that a critical finding will be relevant to us. It saves time and helps our developers focus on the issues that actually matter.””

Minh Nghiem · Senior Security Engineer · Homebase

“Semgrep Supply Chain has helped reduce the noise by 95%”

Khanh Le-Do · Security Software Engineer · Lyft

“The goal was not to ‘add another tool,’ but to implement high-quality, scalable security automation that fits naturally into how developers work.”

Yoni Weintrob · Chief Information Security Officer · Sola Security

“Semgrep empowers our developers with real-time security insights, cutting remediation time by 50% while seamlessly integrating into our workflow.”

Jakub Kneppo · Application Security Principal · Copper

“Semgrep lets us treat security and code quality as first-class priorities. The combination of customizable CI/CD configurations, custom rules, and finding policies gives us a SAST program that actually fits our codebase.”

Zach Rayburn · Staff Product Security Engineer · Cribl

““Semgrep did not just help us find issues. It helped us build the security program we always intended to have.””

Neil · ICE Services

““Semgrep gave us the context we needed to make good decisions.””

Greg · ICE Services

““Being able to answer leadership quickly with confidence and evidence is exactly the capability we set out to build.””

Neil · ICE Services

““It felt like having another reviewer on the PRs, not a blocker but a partner.””

Greg Parfitt · ICE Services

““Semgrep helped us understand our environment in a way we simply could not before.””

Neil · ICE Services

““Semgrep felt practical. It fit how our engineers already worked.””

Greg Parfitt · the Application Security Lead · ICE Services

““Our goal was not to bolt on security. It was to build a foundation that would support ICE for years to come.””

Neil Johnson · VP of Security · ICE Services

““We’ve seen measurable improvements in remediation time because findings are clearer, more actionable, and easier to prioritize. Developers now view the tool as part of their natural workflow rather than an external gate.””

Adrian Puente Zubiaur · Principal Security Engineer

““With Semgrep, that experience changed dramatically. The introduction of features like Assistant, which combines auto-triage noise filtering with clear remediation recommendations, has made findings far more actionable.””

Adrian Puente Zubiaur · Principal Security Engineer

““Onboarding Semgrep was straightforward, with quick integration into our pipelines. A pleasant surprise was the low barrier to writing custom rules, which gave the team early wins and built confidence in the program.””

Adrian Puente Zubiaur · Principal Security Engineer

““What drew me in early on was Semgrep's simplicity, transparency, and power, plus the sense that this was a company that truly cared, backed by a passionate community, compared to traditional security tools that often felt like black boxes.””

Adrian Puente Zubiaur · Principal Security Engineer

““Striking the right balance between speed and risk management requires more than just better tooling. It demands ongoing communication, empathy, and a culture where security is seen as an enabler rather than a blocker.””

Adrian Puente Zubiaur · Principal Security Engineer

Lanci e partner nell’IA

Cosa ha lanciato Semgrep e con chi collabora sull’IA.

  • LancioSemgrep Assistant component taggingSemgrep Assistant can categorize and tag findings based on the component they are found in.
  • LancioShadow AI rulesSemgrep has shipped 186 Shadow AI rules that surface LLM usage across a codebase.
  • LancioAI Security rulesSemgrep has shipped 27 AI Security rules covering prompt injection, unrestricted tool use, and data exfiltration.
  • LancioSemgrep GuardianSemgrep Guardian detects and resolves vulnerabilities in AI-generated code as it's written inside agentic coding tools.

Competenze richieste

Le più frequenti negli annunci aperti.

Competenze più richieste

  • CI/CD
  • Developer workflows
  • DevSecOps

Stack tecnologico

Librerie
Bootstrap
CDN
jsDelivr
Marketing
VWO
Marketo
Analisi
Google Tag Manager
Google Analytics 4
Sicurezza
OneTrust

Dati aziendali

Fondata
2017
Settore
static analysis
Settore (NAICS)
Informazione
Sito web
semgrep.dev

Posizioni per sede

Dove assume Semgrep. Scegli una città per vederne le posizioni.

Domande su Semgrep

Semgrep sta assumendo?
Sì. Al 8 ottobre 2026, Semgrep ha 13 posizioni aperte su Metaintro. 5 sono state pubblicate negli ultimi 30 giorni. La maggior parte riguarda Developer (4), Product/Project Management (3) e Customer Support (2).
Dove sta assumendo Semgrep?
Semgrep sta assumendo a San Francisco, Boston, United States, New York e The Hague, con il maggior numero di posizioni aperte a San Francisco.
Semgrep offre lavoro da remoto o ibrido?
Il 42% delle posizioni aperte è ibrido e il 42% da remoto.
Chi sono i clienti di Semgrep?
Semgrep indica 14 clienti, tra cui Lyft, Cribl, Tide, Vanta e Synthesia.
Quali competenze cerca Semgrep?
Le sue posizioni aperte richiedono più spesso CI/CD, Developer workflows e DevSecOps.
Ritorna alla navigazione