A SaaS? tool that automates AI-assisted threat modeling, CI/CD security reviews, and threat intelligence correlation for engineering teams.
Added Jun 12, 2026
Last signal 1d ago
Security teams are being asked to secure fast-moving CI/CD pipelines, AI-assisted engineering workflows, and increasingly fragmented threat intelligence sources. The job signals point to a recurring need to turn vulnerability feeds, indicators of compromise, and threat modeling outputs into actionable guidance for both security teams and developers.
The product would ingest CI/CD metadata, vulnerability feeds, security tool findings, and threat intelligence indicators, then correlate them into prioritized risks and developer-ready remediation actions. It would provide AI-enabled security reviews and threat modeling workflows directly tied to code changes, pipelines, and detection playbooks.
Companies are explicitly hiring for AI-enabled security reviews, agentic engineering workflow security, and scalable analysis pipelines. As AI-assisted development enters production engineering, security review and threat intelligence workflows need more automation and tighter integration into CI/CD.
58
85% score confidenceTrend snapshot pending
No matched competitors yet
Showing 1-20 of 20 signals
Semgrep Workflows : a platform for programming security work (research, detect, validate, triage, fix, optimize) as reproducible pipelines that combine deterministic tools with AI agents and run at scale.
We're building out our security engineering function and looking for someone to own hands-on application security work across our product stack — secure SDLC, CI/CD security tooling, and growing into securing our AI product surfaces over time. Early-stage function: you'll have real scope to shape how we do this, not just execute an existing playbook. Own secure SDLC — SAST/DAST integration in CI/CD (Semgrep, CodeQL), vulnerability triage and remediation workflows.
Develop threat models and security controls that influence architecture and engineering decisions. Build security into CI/CD pipelines through automation, policy-as-code, and DevSecOps practices.
Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services Design and build AI agents throughout the SDLC for automated threat modeling during design, AI-driven secure code generation and review, and reducing AppSec toil
Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting. Build security workflows that run on AI plugins by default, so coverage checks and evidence collection happen automatically instead of by hand.
+17 more signals