CodeRabbit
Lead Security Engineer
San Francisco
Sponsorship not specifiedDetected 195 days ago
CI/CDLLMsPenetration TestingSIEM
About the role
- You become the steward of resilience, incident response, and proactive defense at scale.
Responsibilities
- Own the security roadmap - craft and execute a strategic security engineering plan that aligns with CodeRabbit's fast-paced engineering cadence.
- Boost resilience - champion defense-in-depth tactics: threat modeling, secure design reviews, hardening, CI/CD integration.
- Tools & automation - build or integrate security tooling (SAST, DAST, SIEM, EDR, monitoring) into the developer workflow without slowing delivery.
- Embed security fluently - partner with engineering and product teams to bring secure practices early into planning and daily workflows.
- CodeRabbit is building the next generation of AI-native developer tooling - starting with code review.
- Engineers here find problems before they're assigned, use AI as a core part of how they build, ship with judgment, and own outcomes from proposal to production.
Requirements
- Technical depth: Extensive experience with security across software and infrastructure-threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.
- Strategic mindset: Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.
- Security in chaos: Experience in pressure situations-with clarity, direction, and calm.
- Developer‑centric approach: You can speak fluent dev-tools, empathize with fast-moving teams, and secure them without slowing them down.
- Experience in a dev‑tools, SDK, or platform-heavy company.
- Extensive experience with security across software and infrastructure-threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.
- Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.
- Battle-tested experience: 8+ years in security engineering, incident response, or correlated fields-bonus if you've led through a major production breach or targeted attack.
- Praxis over theory: You've taken production systems down (intentionally or unintentionally) and built them back stronger.
- You've implemented DevSecOps tooling and orchestrated shift‑left security in developer pipelines.
- You've recovered from (or prevented) a critical security event, and turned that into an engineering culture improvement.
- Hacker mindset + operational discipline - pentests, disaster recovery, threat hunting, tooling, cloud environments.
- Certifications like CISSP, CISM, CEH, or relevant cloud security certs.
- WHY JOIN OUR ENGINEERING CULTURE?
- CodeRabbit is building the next generation of AI-native developer tooling - starting with code review. We combine large language models with deep software engineering context to help teams ship faster, catch more bugs, and make better architectural decisions at scale.
Skills
- CodeRabbit is on a mission to empower developers with lean, high-performance tools-they move fast, and so do the threats.
Benefits
- 8+ years in security engineering, incident response, or correlated fields-bonus if you've led through a major production breach or targeted attack.
Company info
- CodeRabbit is an innovative research and development company focused on building extraordinarily productive human-machine collaboration systems.
- Our primary goal is to create the next generation of Gen AI-driven code reviewers:
- a symbiotic partnership between humans and advanced algorithms that significantly outperforms individual engineers.
- We combine language models with human ingenuity to push the boundaries of software development efficiency and quality.
- We are a high-ownership engineering culture.
Apply directly at CodeRabbit →Create a free account for alerts like thisView CodeRabbit immigration profile
This listing is sourced directly from CodeRabbit's careers page and normalized into a canonical job model.