--- title: 'Product Manager: Security at CodeRabbit' canonical: 'https://feeny.ai/job/product-manager-security-coderabbit-bengaluru-6e07wzx2h36n' type: 'job' last_seen: '2026-09-09' --- # Product Manager: Security at CodeRabbit - **Company:** [CodeRabbit](https://feeny.ai/companies/coderabbit) - **Location:** Bengaluru, India - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-08-20 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.ashbyhq.com/coderabbit/b351f245-b5e5-458b-bd1e-0baa9dcfca72 ## Job description ## ABOUT CODERABBIT CodeRabbit is the leading AI code review platform, trusted by more than 17,000 customers and 150,000 open-source projects, conducting over 2 million code reviews each week. We build the symbiotic partnership between developers and AI that makes shipping fast software safe again, reviewing every pull request, IDE change, and CLI commit so teams can move quickly without breaking things. We are a fast-moving, well-funded company, fresh off a $143M Series C at a $1.5B valuation — building Agentic Change Management, the control layer for software changes created by humans and agents. As AI writes more of the world's code, the bottleneck moves from implementation to judgment and helping human judgment scale is exactly the problem we exist to solve. ## ROLE OVERVIEW We're hiring a strong, hands-on Product Manager to own CodeRabbit's security product: the AI-driven scanner that hunts for real vulnerabilities across entire codebases and surfaces security findings directly in pull request reviews. The product combines LLM-based vulnerability hunting with static analysis, secrets detection, infrastructure-as-code checks, and dependency and supply-chain analysis, and grades every finding for exploitability and severity before a customer ever sees it. This is a high-ownership IC role. One thing we're firm on: you must come from the security space. This product lives or dies on security judgment - what a true positive looks like, what severity a finding deserves, and what an AppSec team actually needs before it will trust a scanner. ## WHAT YOU'LL OWN ## PRODUCT DIRECTION & ROADMAP - Own the security product end to end: deep codebase scans, security findings in pull request reviews, and everything in between - Decide which vulnerability classes, scanner capabilities, and languages we invest in next across SAST, secrets detection, infrastructure-as-code misconfiguration, and dependency and supply-chain analysis - Define what good detection means as a product: the precision, recall, and noise bar a finding must clear before a customer sees it ## THE FINDINGS EXPERIENCE - Own how findings are presented, triaged, and resolved: severity and exploitability grading, dismissal and feedback loops, remediation flows, and reporting - Treat every false positive as a trust problem, not a tuning detail — the goal is a scanner developers believe, not one they mute - Turn detection-quality evidence (benchmarks, evaluations, real-world results) into product decisions and customer-facing proof ## THE SECURITY BUYER - Own the AppSec and CISO persona alongside our developer users: what security teams need to evaluate, trust, and roll out the product across an organization - Partner with Sales on enterprise security evaluations and competitive positioning in the code security market - Shape pricing and packaging of the security offering with Growth and Finance ## DETECTION QUALITY AS A PRODUCT METRIC - Work daily with the engineers building the agentic scanning pipeline; bring the customer and market view to detection priorities - Own the quality bar for what ships: hold detection changes to benchmark evidence, and make precision-versus-coverage tradeoffs deliberately rather than by default ## WHO YOU ARE - 5–8 years in the security space: product management at a security vendor, or hands-on security work (application security, penetration testing, vulnerability research, detection engineering) that you carried into product. We're hiring security depth, not adjacent experience - Product management experience with deeply technical products, ideally at a B2B SaaS or developer tools company - Practical knowledge of real vulnerability classes and how they're exploited — enough to challenge a severity call, judge a disputed false positive, and hold your own with security engineers and customers' AppSec teams - You know the security tooling landscape (SAST, DAST, secrets scanning, IaC, software composition analysis) and exactly why developers distrust most of it - Technically fluent. You can read code, understand APIs, and have detailed conversations with engineers without a translator - You write well and communicate precisely. PRDs and tickets you've written are things you're proud of - Comfortable with ambiguity; can move from fuzzy problem to clear spec without hand-holding - Low ego, high ownership. You care about the outcome more than the credit ## NICE TO HAVE - A hands-on practitioner past: CVEs, bug bounty history, CTFs, or pentest findings with your name on them - Experience shipping products built on LLMs or agentic systems, or well-formed judgment about where they help and where they fail - Direct vendor-side experience in the code security market (SAST, ASPM, or software composition analysis) - Working knowledge of Git platforms (GitHub, GitLab, Bitbucket, ADO) as a power user or PM ## WHAT THIS ISN'T We'll be upfront: this isn't a compliance-checkbox product, and it isn't a GTM-only role. The hard problems here are detection quality, trust, and making security findings genuinely actionable for developers - deep, technical, judgment-heavy product work in one of the fastest-moving areas of AI. What it is: one of the biggest product bets we're making. As AI writes more of the world's code, someone has to catch what it gets wrong, and we intend to be the ones developers and security teams both trust to do it. ## OUR VALUES 🤝 Collaborative Humans: Prioritizing collective intelligence 🚀 Fearless Innovators: Turning obstacles into growth opportunities 💪 Persistent, Passionate Developers: Thriving on complex, long-term challenges 🎯 Impact-Driven Creators: Crafting intuitive tools for developers 🧠 Rapid Learners and Un-learners: Adapting quickly in our fast-paced technological world ## WHAT WE OFFER - Work on cutting-edge technology with real-world impact - Collaborative and innovative environment - Competitive salary, equity, and benefits - Professional development opportunities To apply, submit your resume and relevant project samples or GitHub profiles. CodeRabbit is an equal-opportunity employer committed to diversity and inclusion. ## About CodeRabbit ## Company Overview - **One-liner**: CodeRabbit is an AI‑powered platform that automates the first pass of code reviews, providing context‑aware, human‑like feedback to help development teams ship faster and catch more bugs. - **Entity Type**: Private (Series B; total funding $79.61M; last round $60M in October 2025) - **Headquarters**: San Francisco, United States (also reported as Walnut Creek, California – conflicting reports) - **Founded**: 2023 - **Founders**: Harjot Gill (CEO) is the primary founder; other co‑founders are not publicly disclosed. ## Core Business - **Primary industries**: Software Development, AI‑powered Developer Tools - **Target customers**: B2B, serving Engineering teams across SMB and Enterprise (15,000+ customers including The Economist, Life360, ConsumerAffairs, Hasura) - **Mission / purpose**: “Revolutionize how code reviews are done” – enabling teams to move fast while maintaining code quality. ## Products & Services - **CodeRabbit AI Review (SaaS / API)**: An AI‑powered code review agent that integrates with GitHub, GitLab, and other platforms. It provides line‑by‑line feedback, code suggestions, architectural diagrams, unit‑test generation, docstring creation, and a “Chat with CodeRabbit” feature. Supports custom guidelines, path/AST‑based instructions, and learns from developer feedback (“Learnings”). ## Market Standing - **Valuation / Market Cap**: Not publicly disclosed (private company) - **Key Metric**: **Total Funding** – $79.61 million raised (Series B led by Scale Venture Partners at $60M, October 2025) - **Notable Investors / Partners**: Scale Venture Partners (lead, Series B), CRV (lead, Series A), Engineering Capital, Harmony Partners, NVentures (NVIDIA), and 8+ other investors. - **Growth Signals**: - Headcount: 154 employees, **+363.6% year‑over‑year**. - Customer base grew to 15,000+. - SOC 2 Type II certified; GDPR compliant. - Acquired FluxNinja in 2024. - Claimed as “Most installed AI App” (quote attributed to Jensen Huang, NVIDIA CEO) on homepage. - Active job postings: **39** (yearly increase of +550%). ## Competitive Advantages - **Continuous learning**: AI agent improves over time by incorporating developer feedback in natural language. - **Deep context**: Uses Codegraph, MCP servers, linked issues (Jira, Linear), and web queries to understand dependencies across files. - **Noise reduction**: 40+ linters and security scanners are integrated while false positives are filtered out. - **Customizability**: Entire review workflow can be configured via a YAML file, including custom checks and coding guidelines. - **Security‑first**: End‑to‑end encryption, zero data retention post‑review, independent SOC 2 Type II audits. ## Strategic Focus - **Expand pre‑merge checks** and finishing touches (e.g., custom checks in natural language). - **Deepen IDE & CLI integration** to review code even before PRs are created. - **Enterprise growth**: Hiring senior sales roles (Enterprise AE, Sales Manager) and expanding into EMEA and APAC markets (e.g., South Korea). - **Continuous improvement** of AI agent through user feedback and expanded external context sources. ## Why Work Here - **Culture**: Described as fast‑paced, innovation‑driven, collaborative, and impact‑oriented. Values: fearless & innovative, persistent & passionate, impact‑driven. - **Work model**: Hybrid/office‑first (San Francisco office with daily catered lunch); remote roles may be available for some positions. - **Compensation & perks** (from careers page): - Unlimited PTO - Premium medical, dental, vision coverage - 401(k) for U.S. hires - Stock options (high growth potential) - Monthly commuter stipend - Learning & development stipend - **Employee sentiment**: 3.8/5 on LinkedIn (11 reviews), with Compensation at 4.2, Career growth at 4.1, and Culture at 3.8. - **Engineering culture**: Technical team makes up 28% of headcount; employees use and improve the AI tool themselves; strong emphasis on shipping fast without breaking things. ## Sources 1. [coderabbit.ai/careers](https://coderabbit.ai/careers) 2. [coderabbit.ai](https://coderabbit.ai/) 3. [cbinsights.com/company/coderabbit](https://www.cbinsights.com/company/coderabbit) 4. [linkedin.com/company/coderabbitai](https://www.linkedin.com/company/coderabbitai) 5. [jobs.ashbyhq.com/coderabbit](https://jobs.ashbyhq.com/coderabbit) ## Other roles at CodeRabbit - [Regional Vice President, Sales - Northeast](https://feeny.ai/job/regional-vice-president-sales-northeast-coderabbit-bengaluru-hkpnkryexkzt) — Bengaluru, India - [Product Manager - All Levels](https://feeny.ai/job/product-manager-all-levels-coderabbit-san-francisco-ayja997n2dqp) — San Francisco, CA - [Product Designer](https://feeny.ai/job/product-designer-coderabbit-san-francisco-zbb23fes7k1g) — San Francisco, CA - [Visual Designer](https://feeny.ai/job/visual-designer-coderabbit-san-francisco-754xdckkq0st) — San Francisco, CA - [Design Engineer](https://feeny.ai/job/design-engineer-coderabbit-san-francisco-z436m5fapszn) — San Francisco, CA - [Office Coordinator - Boston](https://feeny.ai/job/office-coordinator-boston-coderabbit-boston-12wxq0pm9k31) — Boston, MA - [Content & Enablement Specialist](https://feeny.ai/job/content-enablement-specialist-coderabbit-boston-h30ktf0cn9hj) — Boston, MA - [Enterprise Customer Success Manager, Americas](https://feeny.ai/job/enterprise-customer-success-manager-americas-coderabbit-san-francisco-pmd9047jxbmr) — San Francisco, CA - [Commercial Field Engineer – Post-sales](https://feeny.ai/job/commercial-field-engineer-post-sales-coderabbit-london-96barc7gjnec) — London, United Kingdom - [Sales Development Representative (SDR) - San Francisco](https://feeny.ai/job/sales-development-representative-sdr-san-francisco-coderabbit-san-francisco-8f9daa6b6d8d) — San Francisco, CA