Summary
Endor Labs is building an Application Security platform to navigate the complexities of modern software. They are looking for a Member of Technical Staff focused on program analysis and machine learning for code, contributing to static analysis tools and evolving their SCA and SAST platforms.
Responsibilities
- Contribute to our existing suite of static analysis tools, helping improve precision, recall, coverage, and performance across supported languages
- Help evolve our SCA and SAST platforms, shaping how we detect vulnerabilities, analyze dependencies, and prioritize risk across the software supply chain
- Participate in machine-learning experiments for SCA and SAST, from problem framing and dataset work through evaluation and the path from prototype to production
- Contribute to our program-analysis infrastructure, which includes call graph construction, data-flow and taint analysis, and language-specific analyzers
- Work with product and engineering to help shape parts of the technical roadmap for analysis and ML-for-code work
- Collaborate with engineers across the team through design discussions, code reviews, and hands-on pairing
- Opportunities to represent Endor Labs externally—e.g., talks at technical conferences, meetups, or industry events—if that's something you enjoy
- Engage with customers when needed—triaging findings, explaining analysis behavior, and turning field feedback into product improvements
- Help identify and address performance bottlenecks, reliability issues, and technical debt across the analysis stack
Skills
- Some exposure to program analysis or static analysis (e.g., call graphs, data-flow or taint analysis, abstract interpretation, symbolic execution) or to ML for code (e.g., vulnerability detection, code representation learning, program repair, code embeddings, reachability prediction, LLM-based code understanding). Deep expertise in one area is great; a working familiarity and eagerness to learn is also welcome
- A software engineering background—industry experience, research, open source, or a mix
- Comfort working in at least one of Java, Python, or Go, and the ability to ship production-quality code (or the trajectory to get there quickly)
- Some relevant experience in software engineering or a related field. We're open to a range of backgrounds and career stages, from early-career engineers through experienced ICs
- A product mindset—you care about building things that work well for users, not just technically interesting code
- Good communication and collaboration skills. You can work through technical trade-offs with teammates and explain your thinking clearly
- Interest in giving talks at technical conferences, workshops, or industry events, or in engaging directly with customers. Neither is required
- Familiarity with AppSec, DevSecOps, or software supply chain security
- Experience with ML systems in production (training pipelines, evaluation frameworks, model serving, feedback loops)
- Contributions to open-source static analysis tools, program analysis frameworks, or security research
- Experience at an early-stage startup or as a founding engineer
- Experience building developer-facing products or platforms
Qualifications
Must Haves
- Some exposure to program analysis or static analysis (e.g., call graphs, data-flow or taint analysis, abstract interpretation, symbolic execution) or to ML for code (e.g., vulnerability detection, code representation learning, program repair, code embeddings, reachability prediction, LLM-based code understanding). Deep expertise in one area is great; a working familiarity and eagerness to learn is also welcome
- A software engineering background—industry experience, research, open source, or a mix
- Comfort working in at least one of Java, Python, or Go, and the ability to ship production-quality code (or the trajectory to get there quickly)
- Some relevant experience in software engineering or a related field. We're open to a range of backgrounds and career stages, from early-career engineers through experienced ICs
- A product mindset—you care about building things that work well for users, not just technically interesting code
- Good communication and collaboration skills. You can work through technical trade-offs with teammates and explain your thinking clearly
Nice to Haves
- Interest in giving talks at technical conferences, workshops, or industry events, or in engaging directly with customers. Neither is required
- Familiarity with AppSec, DevSecOps, or software supply chain security
- Experience with ML systems in production (training pipelines, evaluation frameworks, model serving, feedback loops)
- Contributions to open-source static analysis tools, program analysis frameworks, or security research
- Experience at an early-stage startup or as a founding engineer
- Experience building developer-facing products or platforms
Benefits
- Commission targets
- Restricted stock units
- Bonuses