Socket

Socket

Vulnerability Research Engineer

AMER

Sponsorship not specifiedDetected 238 days ago
JavaScriptTypeScriptPythonGoRustSwiftNode.jsCI/CDRESTCybersecurityFigmaSupply ChainTest AutomationResearch

About the role

  • As an early member of the Socket team, you'll help shape how we scale this technology across the JavaScript ecosystem and beyond.

Responsibilities

  • Lead patching efforts for high-impact vulnerabilities across npm packages
  • Build and improve automated patching infrastructure and tooling
  • Design and implement scalable patch generation and delivery systems
  • Develop automated vulnerability detection and patch creation workflows
  • Build APIs and integrations to deliver certified packages
  • Create tooling for patch quality assurance and testing

Requirements

  • 3+ years of software engineering experience with production systems
  • Strong proficiency in Node.js, JavaScript, and TypeScript
  • Experience with package managers (npm, yarn, pnpm) and the JavaScript ecosystem
  • Familiarity with automated testing, CI/CD, and deployment systems

Nice to have

  • Experience with security tooling, vulnerability scanning, or patch management
  • Knowledge of software supply chain security challenges
  • Experience with other package ecosystems (Python, Go, Rust, etc.)
  • Open source contributions or package maintenance experience
  • Background in DevSecOps or security engineering
  • Experience with high-throughput data processing systems
  • Informational with a member from our Talent Team
  • Hiring Manager Interview

Compensation

  • Market competitive salary bands

Benefits

  • Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work.
  • Meaningful equity program
  • Comprehensive health benefits for you and your family (99% coverage)
  • Flexible time-off, holidays, and winter shutdown to rest & recharge
  • Paid parental leave

Company info

  • Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets https://socket.dev/love to see for yourself!)
  • Founded by Feross Aboukhadijeh https://www.linkedin.com/in/feross/, a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $ https://socket.dev/blog/series-b125M in funding https://socket.dev/blog/series-c from top angels, operators, and security leaders.
  • Socket helps devs and security teams ship faster by cutting out security busywork.
  • Thousands of orgs use Socket to safely find, audit, and manage open source code.
  • Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets https://socket.dev/love to see for yourself!)
  • We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.
  • We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.
  • Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.

This listing is sourced directly from Socket's careers page and normalized into a canonical job model.