Our mission is to bring clarity and control to the world's most complex codebases. AI is accelerating code creation, but the infrastructure to understand, oversee, and evolve that code hasn't kept pace. Sourcegraph gives engineering organizations full visibility across their systems, precise context for their agents, and the ability to execute coordinated code changes at scale. As agentic development becomes the dominant engineering paradigm, we provide the context layer teams need to take control of their codebase.
With Code Search, Deep Search, MCP, and Agentic Batch Changes, we deliver on that mission today - giving engineering teams and their AI tools the cross-repo context to navigate massive codebases with confidence, and the ability to make changes across hundreds of repositories at once.
Companies like Stripe, Reddit, and Leidos rely on Sourcegraph to ship faster and with higher quality. We're backed by a16z, Sequoia, and Redpoint, and proud to operate as a globally distributed team that values high agency, direct communication, and customer love.
If you want to build the infrastructure that lets every engineering team - and every agent they deploy - operate on their codebase with confidence, join us.
🌎 While we hire almost anywhere in the world, we have a preference for someone to reside in the following locations for this role. However, if you feel qualified, we welcome you to apply regardless of location. No matter what, working hours must overlap with EST for at least 10 hours/week.
Preferred locations:
- Europe
As a Security Engineer, you will join our exceptional security team tasked with building world-class security into our product offerings by working on security operations, maintaining and improving our monitoring and alerting stack, participating in on-call and responding to security incidents, application security testing, bug bounty programs, and security reviews for both application and infrastructure security. You will proactively improve the security of our codebase, product, cloud, and customers' on-premise deployments. This is a generalist role where you will be primarily focused on Security Operations, but will also work across all facets of a security program.
Within one month, you will…
- Be onboarded to our alerting and monitoring stack
- Be able to participate in on-call rotations
- You will discover, fix, and mitigate infrastructure vulnerabilities by updating libraries, base images, and analyzing containers
Within three months, you will…
- Maintain internal systems, such as automations that assist in alert triaging
- You will work with other teams to triage, troubleshoot, and mitigate customer concerns and questions about our security
- You will enhance our application security with audits, best practices, code fixes, and continuous education
- You will perform reactive incident response if a security event occurs
- You and your manager will work together on a career plan with actionable goals
Within six months, you will…
- You will perform proactive research to detect new attack vectors
- You will perform threat modeling for existing and future applications
- You will assess and integrate new tools and technologies to improve our operational efficiencies
- You will help maintain compliance with SOC 2, ISO 27001 & GDPR standards
Equal parts engineer and security professional, you are excited about joining a team that is building a world-class security system trusted by some of the biggest tech companies in the world. You and your teammates are Sourcegraph’s first line of defense against bad actors using all the newest and dirtiest tricks to hack us and (more importantly) our customers. You want to be a part of the foundational team, the first steps we are taking to build something big, something trusted, something critical to software and our customers
Your skill-set:
- Practical experience reviewing SIEM alerts and participating in on-call rotations
- Practical experience securing SaaS applications as a security generalist, including infrastructure security, application security, and/or compliance
- Experience with Go, including writing and maintaining internal tooling along with code reviews
- Experience with Elastic stack and GCP
- Experience using and automating a wide range of defensive security tools
- Experience working across engineering teams to secure projects across the organization.
- You are high agency
- You communicate effectively in writing and documentation
Nice to haves:
- Experience developing software as an engineer (i.e., writing code and contributing directly to applications)
- Experience working in a startup environment
- Experience with TypeScript and Terraform
- Experience with Kubernetes
- Experience securing AI products
📊 This job is an IC3. You can read more about our job leveling philosophy in our Handbook.
Compensation💸 We pay above-market salaries because we want to hire exceptional people who can focus on building great products, not worrying about paying bills. As an open and transparent company, our compensation philosophy and pay bands are visible to every Sourcegraph teammate, and we strive to make our approach equitable, explainable, and competitive.
Your base salary is determined by the IC3 pay band for your location zone (1-4). Our pay bands are informed by market data and designed to ensure competitive compensation wherever you live. During the recruiting process, we'll discuss the range applicable to you based on job level, relevant skills, experience, qualifications, and location zone.
💰 The starting salary for the IC3 pay band in each zone is:
- Zone 2: $144,000 USD
- Zone 3: $108,000 USD
- Zone 4: $72,000 USD
📈 In addition to competitive cash compensation, we offer meaningful equity (because when Sourcegraph succeeds, we want you to succeed, too) and generous perks & benefits.
Interview processBelow is the interview process you can expect for this role (you can read more about the types of interviews in our Handbook). It may look like a lot of steps, but rest assured that we move quickly and the steps are designed to help you get the information needed to determine if we’re the right fit for you… Interviewing is a two-way street, after all!
We expect the interview process to take <5 hours in total.
👋 Introduction Stage - we have initial conversations to get to know you better…
- [20m] Recruiter Screen
- [45m] Hiring Manager Screen / Resume Deep Dive
🧑💻 Team Interview Stage - we then delve into your experience in more depth and introduce you to members of the team, including cross-functional partners…
- [60m] Technical Interview: General
- [60m] Technical Interview: Complex Problem Deep Dive
- [45m] Cross-functional Team Collaboration / Values
🎉 Final Interview Stage - we move you to our final round, where you gain a better understanding of our business and values holistically…
- [15m] Leadership
- We check references and conduct your background check
Please note - you are welcome to request additional conversations with anyone you would like to meet, but didn’t get to meet during the interview process.
You can learn more about what it is like to work at Sourcegraph by reading our handbook.
We are an ambitious team who are collectively working hard to build the most influential company in the world. You can read more about our culture, competitive compensation and benefits here.
Sourcegraph is an equal opportunity workplace; we welcome people from all backgrounds.
Sourcegraph participates in E-Verify for U.S. Employees.
Skills Required
- Practical experience reviewing SIEM alerts and participating in on-call rotations
- Practical experience securing SaaS applications (infrastructure, application security, and/or compliance)
- Experience with Go, including writing and maintaining internal tooling and performing code reviews
- Experience with Elastic Stack
- Experience with Google Cloud Platform (GCP)
- Experience using and automating a range of defensive security tools
- Experience working across engineering teams to secure projects
- Ability to communicate effectively in writing and documentation
- Familiarity with monitoring and alerting stacks and participating in alert triage
- Experience discovering, fixing, and mitigating infrastructure vulnerabilities (libraries, base images, containers)
- Willingness/ability to support compliance efforts (SOC 2, ISO 27001, GDPR)
- Overlap working hours with EST for at least 10 hours/week
- Experience developing software (writing code and contributing to applications)
- Experience in a startup environment
- Experience with TypeScript
- Experience with Terraform
- Experience with Kubernetes
- Experience securing AI products
Sourcegraph Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sourcegraph and has not been reviewed or approved by Sourcegraph.
-
Fair & Transparent Compensation — Compensation practices include published salary bands and a stated above‑market approach, which clarifies structures and expectations. Documentation outlines role, level, and location bands to make how pay is determined more explicit.
-
Healthcare Strength — Benefits include fully paid medical, dental, and vision coverage for employees in the US, UK, and Canada. This core health coverage is repeatedly highlighted as a strength for a remote‑first employer.
-
Parental & Family Support — Family support includes paid parental leave and substantial reimbursement for family‑planning services. These programs are prominently featured alongside other core benefits.
Sourcegraph Insights
What We Do
Sourcegraph is a code AI platform that makes it easy to read, write, and fix code–even in big, complex code bases. Meet our 2 products: Amp: Amp is the latest generation coding agent built for teams. Unlike previous generation agents that are geared towards lower token consumption to optimize for lower costs, Amp is built with an obsession toward best outcomes with unfettered access to tokens and tools. Amp is available both as a VS Code extension and as a CLI to meet the developers wherever they are. Code Search: Search your entire codebase—every code host and repository, at any scale—in a single place. Code Search makes it easy for developers to onboard to new codebases, understand code faster, and find & fix security risks.
Why Work With Us
We're developing the world's most advanced code AI platform with a team of brilliant across the globe. Our company values are the beliefs + principles that help us achieve our goals and build an inclusive team. We provide total rewards that are highly competitive and allow you to thrive both personally and professionally.
Gallery









