Back to search
EngineeringOn-site

Product Engineer, Security

Greptile · On-site

Apply
Last seen by MeritLog September 11, 2026Source: AshbySource version: ashby-public-job-posting-v1

MeritLog read this listing from Greptile's Ashby job board and last checked it on September 11, 2026.

Source: the employer's Ashby job board. Open the original listing for current details.

Job details

Work model
On-site
Salary
$170K - $300K
Location
San Francisco

Hiring context

How this role compares at Greptile

Greptile has 18 live roles in MeritLog’s catalog across 6 job families, and 12 of them are in engineering. 18 of those listings publish a pay range, a disclosure rate of 100%.

This role's posted range of $170K - $300K sits above 65% of the 17 other Greptile roles quoted over the same currency and period.

Greptile concentrates this hiring in:

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

What the role asks for

What you'd do

  • You want to work on a product that thousands of developers rely on
  • The chaos of high growth and things breaking is exciting to you
  • You like being in an office every day around other smart people who are excited about what they’re building
  • You enjoy turning security theory into a product that helps other developers
  • You care about developer experience and want security tools to be informative and delightful to use
  • You specifically prefer working in-person over working remote

What they're asking for

  • B.S. Computer Science or equivalent degree, undergraduate or higherEducation
  • 1+ years of software or DevOps engineering experienceExperience
  • Experience with JavaScript/TypeScriptSkill
  • Security engineering or research experience through source-code auditing, offensive security work, application security engineering, original bug bounty findings, or strong CTF performanceSkill
  • Experience building security products or LLM-powered tools and agents is a strong plusSkill

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

PRODUCT ENGINEER, SECURITY Greptile is an AI code reviewer that catches bugs and anti-patterns in pull requests with complete context of the codebase. Hundreds of top software companies, from YC startups to big tech, and teams in finance, healthcare, and defense, use Greptile to merge PRs faster and catch more bugs. Greptile reviews 5B lines of code every month for 22,000+ customers. A new repo starts using Greptile every 2 minutes. We also uniquely offer self-hosted, air-gapped deployments for enterprises across defense, financial services, and healthcare. We’re looking for a product engineer with strong security expertise to build Greptile’s security product from the ground up. You’ll work directly on the agents and infrastructure that help find, validate, reproduce, and fix vulnerabilities, turning security experience into specialized software that thousands of engineering teams will use every day. PROBLEMS WE’RE EXCITED ABOUT - Security is the highest-stakes thing an AI reviewer can get right or wrong. What does a security product developers actually trust look like: codebase-wide scanning, a security-focused PR bot, continuous pentesting, or something nobody has built yet? - Coding standards can be idiosyncratic and are often poorly documented; can we build agents that learn them through osmosis like a new hire might? - Can we identify for each customer what types of PR feedback they do and don’t care about, perhaps using some sample efficient RL, in order to increase signal-to-noise ratio? - Some bugs are best caught by running the code, potentially against discerning AI-generated E2E tests. Can we autonomously deploy feature branches and use agents to parallel try to break the application to detect bugs? TRAJECTORY - 22,000+ customers - 5B lines of code reviewed every month - Scaled from $0 to eight figures in ARR - Raised $30M from Benchmark, Y Combinator, Paul Graham, and Initialized TEAM - We have assembled a small, talent dense team who have scaled critical functions at companies like Stripe, Google, Figma, etc. RESPONSIBILITIES (IN ORDER OF HOW MUCH TIME YOU’LL LIKELY SPEND ON EACH) - Build Greptile’s security product from the ground up, including codebase scanning, a security-focused PR bot, continuous pentesting, and tools for code analysis, security testing, and vulnerability reproduction. - Improve how agents understand codebases, identify and investigate potential vulnerabilities, reproduce them, and give developers and coding agents the information they need to fix them. - Build testing and validation infrastructure where agents can detect and reproduce suspected vulnerabilities and verify fixes. - Integrate security findings into pull requests, CI pipelines, and existing engineering workflows. - Design, implement, test, and deploy full features. Talk to developers and security teams, iterate on their feedback, and improve reliability and performance across different types of codebases. QUALIFICATIONS - B.S. Computer Science or equivalent degree, undergraduate or higher - 1+ years of software or DevOps engineering experience - Experience with JavaScript/TypeScript - Security engineering or research experience through source-code auditing, offensive security work, application security engineering, original bug bounty findings, or strong CTF performance - Experience building security products or LLM-powered tools and agents is a strong plus YOU WILL LIKE THIS ROLE IF - You want to work on a product that thousands of developers rely on - The chaos of high growth and things breaking is exciting to you - You like being in an office every day around other smart people who are excited about what they’re building - You enjoy turning security theory into a product that helps other developers - You care about developer experience and want security tools to be informative and delightful to use - You specifically prefer working in-person over working remote

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice