
Who we are
Our mission is to bring clarity and control to the world's most complex codebases. AI is accelerating code creation, but the infrastructure to understand, oversee, and evolve that code hasn't kept pace. Sourcegraph gives engineering organizations full visibility across their systems, precise context for their agents, and the ability to execute coordinated code changes at scale.
With Code Search, Deep Search, MCP, and Agentic Batch Changes, we deliver on that mission today—giving engineering teams and their AI tools the cross-repo context to navigate massive codebases with confidence. Companies like Stripe, Reddit, and Leidos rely on Sourcegraph to ship faster and with higher quality. We're backed by a16z, Sequoia, and Redpoint, and proud to operate as a globally distributed team.
Hours & location
While we hire almost anywhere in the world, we have a preference for someone to reside in Europe for this role. However, if you feel qualified, we welcome you to apply regardless of location. Working hours must overlap with EST for at least 10 hours/week.
Why this job is exciting
As a Security Engineer, you will join our security team tasked with building world-class security into our product offerings. You will work on security operations, maintain and improve our monitoring and alerting stack, participate in on-call rotations, handle incident response, perform application security testing, run bug bounty programs, and execute security reviews across both application and infrastructure security. This is a generalist role primarily focused on Security Operations, but spanning all facets of our security program.
Milestones
Within one month, you will:
- Get onboarded to our alerting and monitoring stack.
- Participate in on-call rotations.
- Discover, fix, and mitigate infrastructure vulnerabilities by updating libraries, base images, and analyzing containers.
Within three months, you will:
- Maintain internal systems, such as automations that assist in alert triaging.
- Work with other teams to triage, troubleshoot, and mitigate customer concerns and questions about security.
- Enhance application security with audits, best practices, code fixes, and continuous education.
- Perform reactive incident response if a security event occurs.
- Work with your manager on a career plan with actionable goals.
Within six months, you will:
- Perform proactive research to detect new attack vectors.
- Perform threat modeling for existing and future applications.
- Assess and integrate new tools and technologies to improve operational efficiencies.
- Help maintain compliance with SOC 2, ISO 27001, and GDPR standards.
About you
Equal parts engineer and security professional, you are excited about joining a team that is building a world-class security system trusted by major tech companies.
Skill set
- Practical experience reviewing SIEM alerts and participating in on-call rotations.
- Practical experience securing SaaS applications as a security generalist, including infrastructure security, application security, and/or compliance.
- Experience with Go, including writing and maintaining internal tooling along with performing code reviews.
- Experience with the Elastic stack and GCP.
- Experience using and automating a wide range of defensive security tools.
- Experience working across engineering teams to secure projects across the organization.
- High agency with effective written communication and documentation skills.
Nice to haves
- Experience developing software as a dedicated engineer.
- Experience working in a startup environment.
- Experience with TypeScript and Terraform.
- Experience with Kubernetes.
- Experience securing AI products.
Level & Compensation
This position is an IC3 level role.
Starting base salary by location zone:
- Zone 2: $144,000 USD
- Zone 3: $108,000 USD
- Zone 4: $72,000 USD
In addition to base salary, we offer meaningful equity and generous benefits.
Interview process
- Recruiter Screen (20 mins)
- Hiring Manager Screen / Resume Deep Dive (45 mins)
- Technical Interview: General (60 mins)
- Technical Interview: Complex Problem Deep Dive (60 mins)
- Cross-functional Team Collaboration & Values (45 mins)
- Leadership Conversation (15 mins) & Reference / Background Check
Timezone overlap
UTC-5–-4
Benefits
Open to
Europe
Sign in to track applications and earn points.