Drew Dennison is a seasoned software leader and co-founder serving as CTO of Semgrep, with 14 years of experience building security-focused developer tools and products from idea to production. He blends deep hands-on engineering—contributing to Semgrep’s core analyzer and its widely used open-source rules registry—with product and people leadership honed at Palantir and through an EIR stint at Redpoint. Drew’s work sits at the intersection of static analysis, application security, and pragmatic developer workflows, exemplified by rule contributions that surface subtle vulnerabilities like Django CSRF and catastrophic regex backtracking. He holds an S.B. in EECS from MIT and brings a founder’s curiosity and operational rigor to scaling both code and teams in the San Francisco Bay Area.
14 years of coding experience
6 years of employment as a software developer
S.B. Electrical Engineering and Computer Science, S.B. Electrical Engineering and Computer Science at Massachusetts Institute of Technology
Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.
Role in this project:
Security Engineer
Contributions:31 reviews, 131 commits, 148 PRs in 2 years 9 months
Contributions summary:Drew primarily contributed to the development of security rules within the Semgrep rules repository. Their work included identifying and implementing rules to detect potential vulnerabilities, such as those related to Django's CSRF protection, Flask route handling, and code that might lead to catastrophic backtracking. The user also added rules to identify potential code smells. The user also added rules for detecting potential code smells and security vulnerabilities within python projects.
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Role in this project:
Back-end Developer
Contributions:19 releases, 37 reviews, 528 commits in 1 year 9 months
Contributions summary:Drew's primary contribution focused on updating types and cleaning up dictionary logic within the `sgrep.py` file. They also performed a refactoring task by applying "blacken" formatting, indicating a focus on code style and maintainability. The user's work revolved around the core functionality of the Semgrep tool, as seen from the modifications in `sgrep.py`. These changes likely improved the tool's efficiency or accuracy in identifying code vulnerabilities.
looklinterpythonr2cjavascript
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.