Product Engineer, Security
Build Greptile’s security product, including code scanning, vulnerability detection and reproduction, security-focused pull-request workflows, and agent infrastructure. The role requires a computer science degree, software or DevOps experience, JavaScript/TypeScript expertise, and hands-on security experience.
About the job
Responsibilities
- Build Greptile’s security product from the ground up, including codebase scanning, a security-focused pull-request bot, continuous penetration testing, and tools for code analysis, security testing, and vulnerability reproduction.
- Improve how agents understand codebases, identify and investigate potential vulnerabilities, reproduce them, and provide developers and coding agents with information to fix them.
- Build testing and validation infrastructure that detects and reproduces suspected vulnerabilities and verifies fixes.
- Integrate security findings into pull requests, CI pipelines, and existing engineering workflows.
- Design, implement, test, and deploy full features.
- Collaborate with developers and security teams, iterate based on feedback, and improve reliability and performance across different codebases.
Requirements
- Bachelor’s degree in Computer Science or an equivalent undergraduate or higher degree.
- 1+ years of software or DevOps engineering experience.
- Experience with JavaScript and TypeScript.
- Security engineering or research experience through source-code auditing, offensive security, application security engineering, original bug bounty findings, or strong CTF performance.
- Preference for working in person in an office environment.
Nice-to-haves
- Experience building security products.
- Experience building LLM-powered tools and agents.
Compensation
- Annual salary range: $170,000–$300,000.
Skills
JavaScript, TypeScript, Security Engineering, DevOps, Source-Code Auditing, Offensive Security, Application Security, Bug Bounty, Ctf, Llm Agents, CI/CD
Similar jobs
Security Engineering jobsBuild and operate corporate security controls across identity, endpoints, SaaS applications, and automation. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.
Security engineer responsible for detection engineering, investigations, incident response, identity and access management, and preventative security controls across corporate and production environments. Requires 2+ years of security engineering experience, programming ability, and familiarity with cloud and defensive security tooling.
Security Engineer focused on application and platform security, security reviews, threat modeling, vulnerability management, and secure development practices. The role requires at least two years of relevant experience, programming ability, and familiarity with cloud security technologies.
Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.
Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.