Product Engineer, Security

Drive Capital

San Francisco (CA)

On-site

USD 140,000 - 200,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Greptile in San Francisco is hiring a Product Engineer, Security to build Greptile’s security product from the ground up, working on agents and infrastructure that help find, validate, reproduce, and fix vulnerabilities.

You will collaborate with security teams and developers to integrate findings into PRs and CI pipelines, and you will design, implement, test, and deploy full features across codebases.

Qualifications

  • B.S. Computer Science or equivalent degree.
  • 1+ years of software or DevOps engineering experience.
  • Experience with JavaScript/TypeScript.
  • Security engineering or research experience through source-code auditing, offensive security work, application security engineering, original bug bounty findings, or strong CTF performance.
  • Experience building security products or LLM-powered tools and agents is a strong plus.

Responsibilities

  • Build Greptile’s security product from the ground up, including codebase scanning, a security-focused PR bot, continuous pentesting, and tools for code analysis, security testing, and vulnerability reproduction.
  • Improve how agents understand codebases, identify and investigate potential vulnerabilities, reproduce them, and give developers and coding agents the information they need to fix them.
  • Build testing and validation infrastructure where agents can detect and reproduce suspected vulnerabilities and verify fixes.
  • Integrate security findings into pull requests, CI pipelines, and existing engineering workflows.
  • Design, implement, test, and deploy full features. Talk to developers and security teams, iterate on their feedback, and improve reliability and performance across different types of codebases.

Skills

JavaScript/TypeScript
Security engineering
DevOps engineering
LLM-powered tools
Product security

Education

B.S. Computer Science or equivalent

Job description

Product Engineer, Security

Greptile is an AI code reviewer that catches bugs and anti-patterns in pull requests with complete context of the codebase. Hundreds of top software companies, from YC startups to big tech, and teams in finance, healthcare, and defense, use Greptile to merge PRs faster and catch more bugs.

Greptile reviews 5B lines of code every month for 22,000+ customers. A new repo starts using Greptile every 2 minutes. We also uniquely offer self-hosted, air-gapped deployments for enterprises across defense, financial services, and healthcare.

We're looking for a product engineer with strong security expertise to build Greptile’s security product from the ground up. You'll work directly on the agents and infrastructure that help find, validate, reproduce, and fix vulnerabilities, turning security experience into specialized software that thousands of engineering teams will use every day.

Problems we're excited about
  • Security is the highest-stakes thing an AI reviewer can get right or wrong. What does a security product developers actually trust look like: codebase-wide scanning, a security-focused PR bot, continuous pentesting, or something nobody has built yet?

  • Coding standards can be idiosyncratic and are often poorly documented; can we build agents that learn them through osmosis like a new hire might?

  • Can we identify for each customer what types of PR feedback they do and don't care about, perhaps using some sample efficient RL, in order to increase signal-to-noise ratio?

  • Some bugs are best caught by running the code, potentially against discerning AI-generated E2E tests. Can we autonomously deploy feature branches and use agents to parallel try to break the application to detect bugs?

Trajectory
  • 22,000+ customers

  • 5B lines of code reviewed every month

  • Scaled from $0 to eight figures in ARR

  • Raised $30M from Benchmark, Y Combinator, Paul Graham, and Initialized

Team
  • We have assembled a small, talent dense team who have scaled critical functions at companies like Stripe, Google, Figma, etc.

Responsibilities (in order of how much time you'll likely spend on each)
  • Build Greptile’s security product from the ground up, including codebase scanning, a security-focused PR bot, continuous pentesting, and tools for code analysis, security testing, and vulnerability reproduction.

  • Improve how agents understand codebases, identify and investigate potential vulnerabilities, reproduce them, and give developers and coding agents the information they need to fix them.

  • Build testing and validation infrastructure where agents can detect and reproduce suspected vulnerabilities and verify fixes.

  • Integrate security findings into pull requests, CI pipelines, and existing engineering workflows.

  • Design, implement, test, and deploy full features. Talk to developers and security teams, iterate on their feedback, and improve reliability and performance across different types of codebases.

Qualifications
  • B.S. Computer Science or equivalent degree, undergraduate or higher

  • 1+ years of software or DevOps engineering experience

  • Experience with JavaScript/TypeScript

  • Security engineering or research experience through source-code auditing, offensive security work, application security engineering, original bug bounty findings, or strong CTF performance

  • Experience building security products or LLM-powered tools and agents is a strong plus

You will like this role if
  • You want to work on a product that thousands of developers rely on

  • The chaos of high growth and things breaking is exciting to you

  • You like being in an office every day around other smart people who are excited about what they're building

  • You enjoy turning security theory into a product that helps other developers

  • You care about developer experience and want security tools to be informative and delightful to use

  • You specifically prefer working in-person over working remote

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Greptile • San Francisco (CA)

On-site
USD 140,000 - 220,000
Senior Generalist Engineer
Senior Generalist Engineer

Drive Capital • San Francisco (CA)

On-site
USD 150,000 - 210,000
Customer Engineer
Customer Engineer

Greptile • San Francisco (CA)

On-site
USD 90,000 - 140,000
Forward Deployed Engineer
Forward Deployed Engineer

Greptile • San Francisco (CA)

On-site
USD 120,000 - 180,000
Infrastructure Engineer
Infrastructure Engineer

Greptile • San Francisco (CA)

On-site
USD 120,000 - 190,000
Staff Generalist Engineer
Staff Generalist Engineer

Drive Capital • San Francisco (CA)

On-site
USD 120,000 - 190,000
Research Engineer San Francisco
Research Engineer San Francisco

Greptile • San Francisco (CA)

On-site
USD 180,000 - 280,000
Relocation assistance up to $25K
Equity options
Forward Deployed Engineer San Francisco
Forward Deployed Engineer San Francisco

Greptile • San Francisco (CA)

On-site
USD 140,000 - 220,000
$140K – $220K salary
$40K – $100K equity
Up to $25K in relocation assistance
Senior Product Marketing Manager
Senior Product Marketing Manager

Drive Capital • San Francisco (CA)

On-site
USD 140,000 - 190,000
Product Manager San Francisco
Product Manager San Francisco

Greptile • San Francisco (CA), Northern (KY)

Hybrid
USD 120,000 - 180,000