United States Remote (Global) Full-time

Socket is hiring a Vulnerability Research Engineer

Responsibilities

  • Become proficient in internal workflows, tooling, and automated patching mechanisms
  • Lead remediation initiatives for high-severity vulnerabilities in npm dependencies
  • Increase patch output to support volume delivery of fixes weekly
  • Assist in identifying and ranking high-priority vulnerabilities for patching
  • Offer technical insights on patch prioritization based on ecosystem reach and user impact
  • Enhance automated systems used for generating and applying security patches
  • Design robust, scalable infrastructure for creating and distributing patches
  • Develop pipelines that detect vulnerabilities and automatically generate fixes
  • Build APIs and integrations to distribute vetted, secure package versions
  • Create testing frameworks and tools to ensure patch reliability and correctness
  • Collaborate with security analysts to investigate and resolve urgent vulnerabilities
  • Contribute to long-term technical planning for platform growth
  • Deliver fast and secure remediation paths for commonly used software libraries
  • Support broader efforts to strengthen software supply chain integrity

Benefits

  • Competitive salary ranges aligned with industry standards
  • Significant equity compensation offering
  • Extensive health coverage for employee and family (99% employer-paid)
  • Flexible vacation, holiday, and annual winter break for personal renewal
  • Paid leave for new parents
  • Primarily remote work environment with periodic in-person team gatherings

Compensation

Market competitive salary bands with meaningful equity program

Work Arrangement

Remote-first

Team

Quarterly team off-sites

Benefits

  • Comprehensive health benefits for you and your family (99% coverage)
  • Flexible time-off, holidays, and winter shutdown to rest & recharge
  • Paid parental leave
About company
Socket
Socket's mission is to help developers and security teams to ship faster and spend less time on security busywork. Thousands of organizations use Socket to safely discover, audit, and manage their open source code.
All jobs at Socket Visit website
Job Details
Department Engineering
Category security
Posted 7 months ago