Sourcegraph Logo

Sourcegraph

Security Engineer [IC2-IC3]

Reposted 7 Days Ago
Remote
Hiring Remotely in USA
59K-144K
Mid level
Remote
Hiring Remotely in USA
59K-144K
Mid level
As a Security Engineer, you'll enhance security for Sourcegraph's products and infrastructure through vulnerability management, application security, and incident response, contributing to a world-class security team.
The summary above was generated by AI
Who we are

Our mission at Sourcegraph is to make it so that everyone can code, not just ~0.1% of the population.

Everything is changing in how software gets built, and Sourcegraph builds tools that make it easier at scale. Code Search helps devs explore and understand massive codebases. Amp, our agentic coding tool, dramatically accelerates the time it takes to write new code and tackle complex problems like migrating and transforming code.

We’re trusted by engineering teams at leading companies like Stripe, Uber, and Palo Alto Networks, and with $225M in funding from investors like a16z, Sequoia, and Redpoint, we are building the tools that will define the next era of enterprise software development. We’re a globally distributed team with a culture of high agency, direct communication, and deep love for developers.

If you want to work at the bleeding edge of software and do the most meaningful work of your career, join us.

Hours & location

🌎 While we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location. No matter what, working hours must overlap with Mountain Time for at least 20 hours/week.

Preferred locations:

  • North America
  • South America

We do not subscribe to “I do my best work when I work 40 hours a week.”  People we hire at Sourcegraph believe that building outstanding things means working very hard — smarter and more hours than the competition.


Why this job is exciting

As a Security Engineer, you will join our exceptional security team tasked with building world-class security into our product offerings by working on vulnerability management, application security testing and vulnerability scanning automation, bug bounty programs, and security reviews for both application and infrastructure security. You will proactively improve the security of our codebase, our product, our cloud, and our customers' on-premise deployments. 

Within one month, you will…

  • You will contribute to the team's goals and deliverables for securing the largest deployment of Sourcegraph (sourcegraph.com), enabling customers to upload private code repositories
  • You will discover, fix, and mitigate infrastructure vulnerabilities by updating libraries, base images, and analyzing containers
  • You will enhance our application security with audits, best practices, code fixes, and continuous education
  • You will perform reactive incident response if a security event occurs

Within three months, you will…

  • You will enhance our security measures and policies to support organizations on sourcegraph.com and ampcode.com
  • You will work with other teams to triage, troubleshoot and mitigate customer concerns and questions about our security
  • You and your manager will work together on a career plan with actionable goals

Within six months, you will…

  • You will work with other teams and engineers to implement secure coding guidelines and best practices
  • You will perform proactive research to detect new attack vectors
  • You will perform threat modeling for existing and future applications 
  • You will assess and integrate new tools and technologies to improve our operational efficiencies
  • You will help maintain compliance with SOC 2, ISO 27001 & GDPR standards

About you 

Equal parts engineer and security professional, you are excited about joining a team that is building a world class security system trusted by some of the biggest tech companies in the world.  You and your teammates are Sourcegraph’s first line of defense against bad actors using all the newest and dirtiest tricks to hack us and (more importantly) our customers.  You want to be a part of the foundational team, the first steps we are taking to build something big, something trusted, something critical to software and our customers

Your skill-set:

  • Practical experience securing SaaS applications, including infrastructure security, application security, and/or compliance
  • Experience using and automating a wide range of defensive security tools
  • Experience developing software as an engineer (i.e., writing code and contributing directly to applications)
  • Experience working across engineering teams to support secure coding across the organization.
  • You are high agency
  • You communicate effectively in writing and documentation

Nice to haves:

  • Experience working in a startup environment
  • Experience with Go, TypeScript, Terraform
  • Experience with Kubernetes, GCP
  • Experience securing AI products

Level

📊 This job is an IC2-IC3.  You can read more about our job leveling philosophy in our Handbook.


Compensation

💸 We pay you an above-average salary because we want to hire the best people who are fully focused on helping Sourcegraph succeed, not worried about paying bills. As an open and transparent company that values competitive compensation, our compensation ranges are visible to every single Sourcegraph teammate.

Your salary is determined by your pay band for the IC2-IC3 job level. For determining pay bands, we use a number of market and data-driven salary sources, along with your location zone, and target the high-end of the range to ensure we’re always paying above market regardless of where you live in the world. Both U.S. and international locations are divided into one of four zones, determined by the cost of labor index for each area. The salary for a successful candidate will be based on level, job-related skills, experience, qualifications, and location zone. Please note that the salaries below may be adjusted in the future.

💰 The target compensation for this role is based on the IC2-IC3 pay band for your zone. The start of the IC2-IC3 pay band for each zone is listed below:

IC2:

  • Zone 2: $118,800
  • Zone 3: $89,100
  • Zone 4: $59,400

IC3:

  • Zone 2: $144,000
  • Zone 3: $108,000
  • Zone 4: $72,000

Please speak with a recruiter for additional information regarding zone locations.

📈 In addition to our cash compensation, we offer equity (because when we succeed as a company, we want you to succeed, too) and generous perks & benefits.


Interview process 

Below is the interview process you can expect for this role (you can read more about the types of interviews in our Handbook). It may look like a lot of steps, but rest assured that we move quickly and the steps are designed to help you get the information needed to determine if we’re the right fit for you… Interviewing is a two-way street, after all! 

We expect the interview process to take <5 hours in total.

👋 Introduction Stage - we have initial conversations to get to know you better…

  • [20m] Recruiter Screen
  • [30m] Hiring Manager Screen
  • [60m] Resume Deep Dive / Technical Screen

🧑‍💻 Team Interview Stage - we then delve into your experience in more depth and introduce you to members of the team, including cross-functional partners…

  • [60m] Technical Interview: General
  • [60m] Technical Interview: Complex Problem Deep Dive
  • [45m] Cross-functional Team Collaboration / Values

🎉 Final Interview Stage - we move you to our final round, where you gain a better understanding of our business and values holistically…

  • [15m] Leadership with co-founder 
  • We check references and conduct your background check

Please note - you are welcome to request additional conversations with anyone you would like to meet, but didn’t get to meet during the interview process.


Learn more about us

You can learn more about what it is like to work at Sourcegraph by reading our handbook.

We are an ambitious team who are collectively working hard to build the most influential company in the world.  You can read more about our culture, competitive compensation and benefits here.

Sourcegraph is an equal opportunity workplace; we welcome people from all backgrounds. 

Sourcegraph participates in E-Verify for U.S. Employees.

Top Skills

GCP
Go
Kubernetes
Terraform
Typescript

Similar Jobs

37 Minutes Ago
Remote or Hybrid
Bozeman, MT, USA
123K-223K Annually
Mid level
123K-223K Annually
Mid level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
As a Territory Account Executive, you will engage with local merchants to sell Square's ecosystem, generate leads, close deals, and enhance brand presence in the community.
Top Skills: Salesforce
37 Minutes Ago
Remote or Hybrid
Little Rock, AR, USA
123K-223K Annually
Mid level
123K-223K Annually
Mid level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
The Territory Account Executive will engage with local sellers, sell Square solutions, build leads, and exceed sales goals while ensuring successful onboarding for clients.
Top Skills: Salesforce
37 Minutes Ago
Remote or Hybrid
Memphis, TN, USA
123K-223K Annually
Mid level
123K-223K Annually
Mid level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
The Territory Account Executive will drive sales, engage with local sellers, and build pipelines to enhance Square's brand in the community.
Top Skills: Salesforce

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account