Socket
Vulnerability Research Engineer
AMER
Sponsorship not specifiedDetected 238 days ago
JavaScriptTypeScriptPythonGoRustSwiftNode.jsCI/CDRESTCybersecurityFigmaSupply ChainTest AutomationResearch
About the role
- As an early member of the Socket team, you'll help shape how we scale this technology across the JavaScript ecosystem and beyond.
Responsibilities
- Lead patching efforts for high-impact vulnerabilities across npm packages
- Build and improve automated patching infrastructure and tooling
- Design and implement scalable patch generation and delivery systems
- Develop automated vulnerability detection and patch creation workflows
- Build APIs and integrations to deliver certified packages
- Create tooling for patch quality assurance and testing
Requirements
- 3+ years of software engineering experience with production systems
- Strong proficiency in Node.js, JavaScript, and TypeScript
- Experience with package managers (npm, yarn, pnpm) and the JavaScript ecosystem
- Familiarity with automated testing, CI/CD, and deployment systems
Nice to have
- Experience with security tooling, vulnerability scanning, or patch management
- Knowledge of software supply chain security challenges
- Experience with other package ecosystems (Python, Go, Rust, etc.)
- Open source contributions or package maintenance experience
- Background in DevSecOps or security engineering
- Experience with high-throughput data processing systems
- Informational with a member from our Talent Team
- Hiring Manager Interview
Compensation
- Market competitive salary bands
Benefits
- Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work.
- Meaningful equity program
- Comprehensive health benefits for you and your family (99% coverage)
- Flexible time-off, holidays, and winter shutdown to rest & recharge
- Paid parental leave
Company info
- Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets https://socket.dev/love to see for yourself!)
- Founded by Feross Aboukhadijeh https://www.linkedin.com/in/feross/, a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $ https://socket.dev/blog/series-b125M in funding https://socket.dev/blog/series-c from top angels, operators, and security leaders.
- Socket helps devs and security teams ship faster by cutting out security busywork.
- Thousands of orgs use Socket to safely find, audit, and manage open source code.
- Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets https://socket.dev/love to see for yourself!)
- We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.
- We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.
- Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.
This listing is sourced directly from Socket's careers page and normalized into a canonical job model.