Lead Security Engineer

coderabbit· Engineering
Apply Now ↗
🌍 Remote📍 San FranciscoFullTime💰 USD 180K–260K/yr

About this role

About CodeRabbit

CodeRabbit is an innovative research and development company focused on building extraordinarily productive human-machine collaboration systems. Our primary goal is to create the next generation of Gen AI-driven code reviewers: a symbiotic partnership between humans and advanced algorithms that significantly outperforms individual engineers. We combine language models with human ingenuity to push the boundaries of software development efficiency and quality.

Role Overview:

CodeRabbit is on a mission to empower developers with lean, high-performance tools—they move fast, and so do the threats. That's why we're looking for a battle-tested Lead Security Engineer who’s been in the trenches and can architect, harden, and defend our infrastructure, tooling, and ecosystem.

As our Lead Security Engineer, you’ll lead security engineering at CodeRabbit, infusing security into every layer of our product and infrastructure. You become the steward of resilience, incident response, and proactive defense at scale.

Responsibilities:

  • Own the security roadmap — craft and execute a strategic security engineering plan that aligns with CodeRabbit’s fast-paced engineering cadence.

  • Boost resilience — champion defense-in-depth tactics: threat modeling, secure design reviews, hardening, CI/CD integration.

  • Be Incident Commander — spearhead security incident response and recovery: triage, resolve, root cause, and turn those learnings into stronger systems.

  • Tools & automation — build or integrate security tooling (SAST, DAST, SIEM, EDR, monitoring) into the developer workflow without slowing delivery.

  • Embed security fluently — partner with engineering and product teams to bring secure practices early into planning and daily workflows.

  • Talent & culture — help to hire, coach, and mentor a scrappy, resilient security engineering team; elevate security awareness across the company.

  • Compliance & policy — establish security standards, frameworks, or processes that evolve as we scale—but remain lean and developer-friendly.

Qualifications:

  • Battle-tested experience: 8+ years in security engineering, incident response, or correlated fields—bonus if you've led through a major production breach or targeted attack.

  • Technical depth: Extensive experience with security across software and infrastructure—threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.

  • Strategic mindset: Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.

  • Praxis over theory: You’ve taken production systems down (intentionally or unintentionally) and built them back stronger.

  • Security in chaos: Experience in pressure situations—with clarity, direction, and calm.

  • Developer‑centric approach: You can speak fluent dev-tools, empathize with fast-moving teams, and secure them without slowing them down.

Bonus Points:

  • You’ve implemented DevSecOps tooling and orchestrated shift‑left security in developer pipelines.

  • You’ve recovered from (or prevented) a critical security event, and turned that into an engineering culture improvement.

  • Experience in a dev‑tools, SDK, or platform-heavy company.

  • Hacker mindset + operational discipline - pentests, disaster recovery, threat hunting, tooling, cloud environments.

  • Certifications like CISSP, CISM, CEH, or relevant cloud security certs.

Why Join Us?

  • Defend a Developer-First Future: At CodeRabbit, you’re not just protecting infrastructure—you’re securing the next evolution of developer tools. Help fortify a product that’s reshaping how code gets reviewed.

  • Real Authority & Ownership: You won’t be on the sidelines. As Lead Security Engineer, you’ll define the security roadmap, lead critical incident responses, and gain full ownership of outcomes—from threat modeling to hardened deployment.

  • Impact at Velocity: Join an agile, cross-functional squad of engineers, designers, and researchers. You’ll move fast but not recklessly - embedding security in every release without slowing delivery.

  • Build, Break, Rebuild Stronger: Ideal for someone battle-tested; someone who's faced breaches, recovered systems, and evolved engineering culture through adversity.

  • Grow and Lead: We're investing in you. This role offers ongoing leadership development, mentorship opportunities, and real ownership as you eventually scale your team and operations.

  • Compensation That Reflects Responsibility: We deliver a competitive package—salary, equity, and benefits—to match the importance and intensity of this role.

  • Hybrid Culture That Adapts to You: We collaborate in person in the Bay Area every week, but leave room for remote heads-down focus. It’s security, not surveillance.

Our Values

  • 🤝 Collaborative Humans: Prioritizing collective intelligence

  • 🚀 Fearless Innovators: Turning obstacles into growth opportunities

  • 💪 Persistent, Passionate Developers: Thriving on complex, long-term challenges

  • 🎯 Impact-Driven Creators: Crafting intuitive tools for developers

  • 🧠 Rapid Learners and Un-learners: Adapting quickly in our fast-paced technological world

Apply Now — If you're excited to build tools that blend intelligent systems with world-class software engineering, we'd love to meet you.

Frequently Asked Questions

What is the salary for the Lead Security Engineer role at coderabbit?
The listed salary for this Lead Security Engineer position at coderabbit is USD 180K–260K/yr. This is a remote FullTime role.
Is the Lead Security Engineer job at coderabbit remote?
Yes, this Lead Security Engineer position at coderabbit is remote, with team members based in San Francisco. You can work from home or anywhere in the supported regions.
Is the Lead Security Engineer role at coderabbit full-time or part-time?
This is listed as a FullTime position. It is posted as a Lead Security Engineer role in the Engineering department at coderabbit.
Which team or department does the Lead Security Engineer at coderabbit belong to?
This Lead Security Engineer position is part of the Engineering department at coderabbit. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Lead Security Engineer position at coderabbit?
Click the "Apply Now" button on this page. You will be redirected to coderabbit's official application portal hosted on ashby where you can submit your application directly.
When was the Lead Security Engineer job at coderabbit posted?
This Lead Security Engineer position at coderabbit was posted on Jan 7, 2026. Apply as soon as possible — early applications are often reviewed first.
Lead Security Engineer
coderabbit · 💰 USD 180K–260K/yr
Apply for this role ↗

You'll be redirected to coderabbit's official application page on Ashby ATS.