JobBobsReal-time global job discoveryLive

Security Engineer [IC3]

Sourcegraph91 · Remote · 2026-08-04

executiveRemote
Apply on the employer's site

About this role

Who we are

Our mission is to bring clarity and control to the world's most complex codebases. AI is accelerating code creation, but the infrastructure to understand, oversee, and evolve that code hasn't kept pace. Sourcegraph gives engineering organizations full visibility across their systems, precise context for their agents, and the ability to execute coordinated code changes at scale. As agentic development becomes the dominant engineering paradigm, we provide the context layer teams need to take control of their codebase.

With Code Search, Deep Search, MCP, and Agentic Batch Changes, we deliver on that mission today - giving engineering teams and their AI tools the cross-repo context to navigate massive codebases with confidence, and the ability to make changes across hundreds of repositories at once.

Companies like Stripe, Reddit, and Leidos rely on Sourcegraph to ship faster and with higher quality. We're backed by a16z, Sequoia, and Redpoint, and proud to operate as a globally distributed team that values high agency, direct communication, and customer love.

If you want to build the infrastructure that lets every engineering team - and every agent they deploy - operate on their codebase with confidence, join us.

Hours & location

🌎 While we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location. No matter what, working hours must overlap with EST for at least 10 hours/week.

Preferred locations:

• Europe

Why this job is exciting

As a Security Engineer, you will join our exceptional security team tasked with building world-class security into our product offerings by working on security operations, maintaining and improving our monitoring and alerting stack, participating in on-call and responding to security incidents, application security testing, bug bounty programs, and security reviews for both application and infrastructure security. You will proactively improve the security of our codebase, product, cloud, and customers' on-premise deployments. This is a generalist role where you will be primarily focused on Security Operations, but will also work across all facets of a security program.

Within one month, you will…

• Be onboarded to our alerting and monitoring stack

• Be able to participate in on-call rotations

• You will discover, fix, and mitigate infrastructure vulnerabilities by updating libraries, base images, and analyzing containers

Within three months, you will…

• Maintain internal systems, such as automations that assist in alert triaging

• You will work with other teams to triage, troubleshoot, and mitigate customer concerns and questions about our security

• You will enhance our application security with audits, best practices, code fixes, and continuous education

• You will perform reactive incident response if a security event occurs

• You and your manager will work together on a career plan with actionable goals

Within six months, you will…

• You will perform proactive research to detect new attack vectors

• You will perform threat modeling for existing and future applications

• You will assess and integrate new tools and technologies to improve our operational efficiencies

• You will help maintain compliance with SOC 2, ISO 27001 & GDPR standards

About you

Equal parts engineer and security professional, you are excited about joining a team that is building a world-class security system trusted by some of the biggest tech companies in the world. You and your teammates are Sourcegraph’s first line of defense against bad actors using all the newest and dirtiest tricks to hack us and (more importantly) our customers. You want to be a part of the foundational team, the first steps we are taking to build something big, something trusted, something critical to software and our customers

Your skill-set:

• Practical experience reviewing SIEM alerts and participating in on-call rotations

• Practical experience securing SaaS applications as a security generalist, including infrastructure security, application security, and/or compliance

• Experience with Go, including writing and maintaining internal tooling along with code reviews

• Experience with Elastic stack and GCP

• Experience using and automating a wide range of defensive security tools

• Experience working across engineering teams to secure projects across the…

Skills asked for

Similar jobs

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.