Skip to content

Security Research Manager, Coverage Team

255k – 319kSan Francisco, CABoston, MANew York, NYDenver, COHybrid5+ YOE
Summary

Leads a team of security researchers to develop high-quality detection rules for secrets, code, and supply chain vulnerabilities. Drives roadmap, automation with AI, and improves coverage accuracy; requires 5+ years security tech lead experience and 2+ years people management.

About the role

Responsibilities

  • Hire, develop, and grow the team, cultivating a productive, engaging, diverse, and inclusive work environment that aligns with Semgrep's core values
  • Work closely with product management, sales, and product development teams across all product lines
  • Understand, measure, and elevate the velocity and quality of Semgrep detection rule delivery
  • Prioritize your team’s work and schedules, balancing current product needs with strategic research that will help scale the team through AI and automation
  • Contribute to the technical direction and to the research (depending on your profile)
  • Directly impact the security posture of many customers by improving the quality of our detection

Requirements

  • 2+ years experience as a People Manager
  • 5+ years experience as a Tech Lead in the Security space: App Sec Engineer, Security Researcher, Vulnerability Researcher, etc
  • Comfortable working in a fast-paced environments where prototypes are rapidly iterated or discarded
  • Comfortable tech leading and mentoring Security Researchers
  • Excellent proactive communication skills, both verbal and written
  • Fit in our low-ego high-impact culture
  • Excitement about building for customers, iterating fast, and seeing solutions solve real developer problems
  • Curiosity and a love of new technologies, especially AI/ML
  • Comfortable writing code, especially in Python or Rust

Example Projects

  • Improve and scale Semgrep’s automated pipelines for generating and validating high-confidence detection rules
  • Lead a team to identify and analyze vulnerability patterns (CVEs or from first-principle) across languages and ecosystems, and turn those into detection rules
  • Put in place unified measurements for performance of detection to ensure the best quality across our customers

Compensation

  • Estimated starting annual salary range: $255,200 to $319,000 USD
  • Total compensation may include equity, variable compensation, and benefits
Skills
PythonRustAIMLSecurity ResearchVulnerability ResearchDetection RulesAppSecAutomationSemgrep
Similar roles at this salary range
All Security Engineering jobs →
Fluidstack

Director of Security

Lead and build Fluidstack's global physical security program for AI data centers from the ground up, owning physical security architecture, vendor management, compliance, and GSOC operations.

300k – 400kSan Francisco, CA +2Security EngineeringOn-site8+ YOEESSACS
Crusoe

Staff Software Engineer, Security

Staff Security Software Engineer designing and building scalable security infrastructure, identity systems, and compliance automation platforms. Requires 8+ years software engineering experience with deep Kubernetes, Go/Rust, and cloud platform expertise.

215k – 260kSan Francisco, CASecurity EngineeringOn-site8+ YOEGoGCP
Scale AI

Software Engineer, Identity

Build and maintain identity infrastructure supporting authentication and authorization for enterprise AI systems. Requires 4+ years experience with IAM, ReBAC/ABAC/RBAC, and cloud platforms.

216k – 270kSan Francisco, CA +1Security EngineeringOn-site4+ YOEIAMJWT
Anthropic

Security Engineer, Detection & Response

Lead detection and response engineering efforts, building tooling and processes to monitor threats, investigate incidents, and coordinate responses across Anthropic's technology stack. Requires 5+ years in detection engineering, incident response, or threat hunting.

300k – 405kSan Francisco, CA +3Security EngineeringHybrid5+ YOESQLEDR
Grow Therapy

Staff Engineer, Security

Lead security engineering as the most senior hands-on engineer, shaping multi-year roadmap and building secure-by-default infrastructure including auth, data security, and vulnerability management.

220k – 240kNew York, NY +2Security EngineeringRemote7+ YOEData SecurityAuthorization