This job ad has been posted over 40 days ago! (*)


Software Engineer, Semgrep (Open-Source) Full-time

Published at 2021-11-02 - Viewed: 1734 times - r2c (Worldwide/Remote)

About r2c
Our mission is to make world-class software security available to everyone. This means building program analysis tools that are open source, easy to use, powerful, and fast. It also means building a team with security expertise and a passion for great developer experiences. Most of all, it means working with honesty and respect in a diverse community of dreamers and builders. We’ve redefined static analysis tooling by committing to all of these, and turned our project, Semgrep, into an essential safeguard for code at Snowflake, Dropbox, and more.

About the role
As a software engineer at r2c, you’ll join our mission by building a new category of security tools — indispensable, easy-to-use applications that developers will use to secure their work. You will be joining a team that is directly responsible for the open-source Semgrep tool: https://github.com/returntocorp/semgrep, and will ship features that make it easier for developer teams to integrate Semgrep into their existing workflows.

Along the way, you will work with a dedicated group of full-stack, backend, and infrastructure engineers, as well as security researchers and program-analysis developers. You’ll learn from and meet with developers and security professionals at organizations ranging from single-person startups to social-media giants. You will attend lunch and learns from all over the company – learning about backend, infrastructure, and full-stack paradigms as well as sales and product ideas. And, as a member of our team, you’ll be a part of the decisions that make an early-stage startup successful. Every feature you build will have an impact on our users’ lives and your own. We’re excited to go on this journey with you.

You will

  • Design and ship new features in the open-source Semgrep tool and Semgrep rule registry
  • Work with our users, query our aggregated metrics, and run experiments to help understand and improve core Semgrep workflows
  • Work closely with our static analysis and security research teams in making Semgrep more powerful
  • Collaborate with your team through thoughtful code reviews, design discussions, and demos

You are ideal for this role if you have

  • A bachelor’s degree in Computer Science, similar technical field of study, or equivalent practical experience
  • Experience in one dynamic language like Python, Ruby, Javascript, or PHP
  • A passion for software security and developer enablement

Some example projects that you might work on include

  • Adapt semgrep to run in CI workflows
  • Improve the runtime performance of Semgrep
  • Build authenticated rule upload and download to registry CDN
  • Build tag and search functionality over registry to improve discovery of rules in registry
  • Build features that enable deterministic offline running (thinkyarn lockbut for Semgrep rules)
  • Build seamless VSCode and IntelliJ Semgrep integrations

What we offer
Our goal is to competitively and fairly compensate every r2cer with a system that equally rewards those who are vocal and those who are less comfortable making demands during the final steps of the hiring process. To that end, we generate internal compensation bands that are used when discussing and negotiating salaries. We update these based on market data to make sure they’re above the average for comparable roles.

We also invest in our employees’ well-being and long term success with comprehensive health plans, generous vacation time, 401k matching, learning stipends, and more. Our benefits are for everyone, so that you’re taken care of, and we work with individuals to make sure they have what they need, whether that’s quiet work space, adjusted hours, or any other accommodation.

Who we are
We have people from France and the Philippines, physics and philosophy, formal methods research and full fledged corporations. We’re new parents and new grads, aspiring authors and aspiring Americans, dog lovers and dogfooders. We get together often to bike, bake, and meet up in parks. In our interactions, we believe respect and honesty go hand in hand, and prioritize both.

r2c is an equal-opportunity employer seeking a diverse range of backgrounds. We value who you are — including your cultural heritage, your socioeconomic status, your age, your race, your gender, your sexual orientation, your disabilities. We value what’s vitally important to you — your family, your religion, your politics. We value what you love in this world — your music, your weekend pursuits. We believe in welcoming varied professional backgrounds, educations, and interests. If you’re exceptional in your role, believe in r2c’s mission, and treat r2c’s values as your own, you belong here.

You will need working proficiency and communication skills in verbal and written English. We work as a hybrid on-site / remote organization. r2c primarily works in the Pacific, Eastern, and Central EU time zones.

To apply, please email your resume to margaret@returntocorp.com and include FOSS JOBS in your subject line


Recent jobs at r2c:


« More jobs in programmers