{"slug": "product-engineer-security-greptile", "title": "Product Engineer, Security — Greptile", "summary": "Greptile, an AI code review platform that reviews 5B lines of code monthly for 22,000+ customers, is hiring a Product Engineer, Security in San Francisco with a salary of $170k–300k/yr to build its security product from the ground up, including codebase scanning, a security-focused PR bot, and continuous pentesting. The company, which has raised $30M from Benchmark, Y Combinator, Paul Graham, and Initialized and scaled to eight figures in ARR, seeks candidates with security engineering experience and LLM-powered tooling expertise.", "body_md": "# Product Engineer, Security\n\n- Salary\n- $170k–300k/yr\n- Location\n- San Francisco\n- Work type\n- On-site\n- Posted\n- today\n- Verified live\n- today\n\n[Apply on company site (opens in new tab)](https://jobs.ashbyhq.com/greptile/6e55fc50-514a-47be-bb5a-5e68f2a5f5cf/application)\n\nGreptile is an AI code reviewer that catches bugs and anti-patterns in pull requests with complete context of the codebase. Hundreds of top software companies, from YC startups to big tech, and teams in finance, healthcare, and defense, use Greptile to merge PRs faster and catch more bugs.\n\nGreptile reviews 5B lines of code every month for 22,000+ customers. A new repo starts using Greptile every 2 minutes. We also uniquely offer self-hosted, air-gapped deployments for enterprises across defense, financial services, and healthcare.\n\nWe’re looking for a product engineer with strong security expertise to build Greptile’s security product from the ground up. You’ll work directly on the agents and infrastructure that help find, validate, reproduce, and fix vulnerabilities, turning security experience into specialized software that thousands of engineering teams will use every day.\n\nProblems we’re excited about\n\n- Security is the highest-stakes thing an AI reviewer can get right or wrong. What does a security product developers actually trust look like: codebase-wide scanning, a security-focused PR bot, continuous pentesting, or something nobody has built yet?\n- Coding standards can be idiosyncratic and are often poorly documented; can we build agents that learn them through osmosis like a new hire might?\n- Can we identify for each customer what types of PR feedback they do and don’t care about, perhaps using some sample efficient RL, in order to increase signal-to-noise ratio?\n- Some bugs are best caught by running the code, potentially against discerning AI-generated E2E tests. Can we autonomously deploy feature branches and use agents to parallel try to break the application to detect bugs?\n\nTrajectory\n\n- 22,000+ customers\n- 5B lines of code reviewed every month\n- Scaled from $0 to eight figures in ARR\n- Raised $30M from Benchmark, Y Combinator, Paul Graham, and Initialized\n\nTeam\n\n- We have assembled a small, talent dense team who have scaled critical functions at companies like Stripe, Google, Figma, etc.\n\nResponsibilities (in order of how much time you’ll likely spend on each)\n\n- Build Greptile’s security product from the ground up, including codebase scanning, a security-focused PR bot, continuous pentesting, and tools for code analysis, security testing, and vulnerability reproduction.\n- Improve how agents understand codebases, identify and investigate potential vulnerabilities, reproduce them, and give developers and coding agents the information they need to fix them.\n- Build testing and validation infrastructure where agents can detect and reproduce suspected vulnerabilities and verify fixes.\n- Integrate security findings into pull requests, CI pipelines, and existing engineering workflows.\n- Design, implement, test, and deploy full features. Talk to developers and security teams, iterate on their feedback, and improve reliability and performance across different types of codebases.\n\nQualifications\n\n- B.S. Computer Science or equivalent degree, undergraduate or higher\n- 1+ years of software or DevOps engineering experience\n- Experience with JavaScript/TypeScript\n- Security engineering or research experience through source-code auditing, offensive security work, application security engineering, original bug bounty findings, or strong CTF performance\n- Experience building security products or LLM-powered tools and agents is a strong plus\n\nYou will like this role if\n\n- You want to work on a product that thousands of developers rely on\n- The chaos of high growth and things breaking is exciting to you\n- You like being in an office every day around other smart people who are excited about what they’re building\n- You enjoy turning security theory into a product that helps other developers\n- You care about developer experience and want security tools to be informative and delightful to use\n- You specifically prefer working in-person over working remote", "url": "https://wpnews.pro/news/product-engineer-security-greptile", "canonical_source": "https://frontierroles.com/jobs/greptile-product-engineer-security-6dece0/", "published_at": "2026-09-08 21:50:54+00:00", "updated_at": "2026-09-09 04:20:22.796937+00:00", "lang": "en", "topics": ["ai-products", "ai-agents", "ai-safety"], "entities": ["Greptile", "Benchmark", "Y Combinator", "Paul Graham", "Initialized"], "alternates": {"html": "https://wpnews.pro/news/product-engineer-security-greptile", "markdown": "https://wpnews.pro/news/product-engineer-security-greptile.md", "text": "https://wpnews.pro/news/product-engineer-security-greptile.txt", "jsonld": "https://wpnews.pro/news/product-engineer-security-greptile.jsonld"}}