CodeRabbit

CodeRabbit

Lead Security Engineer

San Francisco

Sponsorship not specifiedDetected 195 days ago
CI/CDLLMsPenetration TestingSIEM

About the role

  • You become the steward of resilience, incident response, and proactive defense at scale.

Responsibilities

  • Own the security roadmap - craft and execute a strategic security engineering plan that aligns with CodeRabbit's fast-paced engineering cadence.
  • Boost resilience - champion defense-in-depth tactics: threat modeling, secure design reviews, hardening, CI/CD integration.
  • Tools & automation - build or integrate security tooling (SAST, DAST, SIEM, EDR, monitoring) into the developer workflow without slowing delivery.
  • Embed security fluently - partner with engineering and product teams to bring secure practices early into planning and daily workflows.
  • CodeRabbit is building the next generation of AI-native developer tooling - starting with code review.
  • Engineers here find problems before they're assigned, use AI as a core part of how they build, ship with judgment, and own outcomes from proposal to production.

Requirements

  • Technical depth: Extensive experience with security across software and infrastructure-threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.
  • Strategic mindset: Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.
  • Security in chaos: Experience in pressure situations-with clarity, direction, and calm.
  • Developer‑centric approach: You can speak fluent dev-tools, empathize with fast-moving teams, and secure them without slowing them down.
  • Experience in a dev‑tools, SDK, or platform-heavy company.
  • Extensive experience with security across software and infrastructure-threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.
  • Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.
  • Battle-tested experience: 8+ years in security engineering, incident response, or correlated fields-bonus if you've led through a major production breach or targeted attack.
  • Praxis over theory: You've taken production systems down (intentionally or unintentionally) and built them back stronger.
  • You've implemented DevSecOps tooling and orchestrated shift‑left security in developer pipelines.
  • You've recovered from (or prevented) a critical security event, and turned that into an engineering culture improvement.
  • Hacker mindset + operational discipline - pentests, disaster recovery, threat hunting, tooling, cloud environments.
  • Certifications like CISSP, CISM, CEH, or relevant cloud security certs.
  • WHY JOIN OUR ENGINEERING CULTURE?
  • CodeRabbit is building the next generation of AI-native developer tooling - starting with code review. We combine large language models with deep software engineering context to help teams ship faster, catch more bugs, and make better architectural decisions at scale.

Skills

  • CodeRabbit is on a mission to empower developers with lean, high-performance tools-they move fast, and so do the threats.

Benefits

  • 8+ years in security engineering, incident response, or correlated fields-bonus if you've led through a major production breach or targeted attack.

Company info

  • CodeRabbit is an innovative research and development company focused on building extraordinarily productive human-machine collaboration systems.
  • Our primary goal is to create the next generation of Gen AI-driven code reviewers:
  • a symbiotic partnership between humans and advanced algorithms that significantly outperforms individual engineers.
  • We combine language models with human ingenuity to push the boundaries of software development efficiency and quality.
  • We are a high-ownership engineering culture.

This listing is sourced directly from CodeRabbit's careers page and normalized into a canonical job model.