Threat Researcher
Remote
Full Time
#Security
#Engineering
#Research
#Malware Analysis
#Threat Intelligence
#Reverse Engineering
#Digital
#Incident Response
#Automation
#TypeScript
#JavaScript
At Socket, we help developers and security teams ship software faster by removing the burden of security busywork. Thousands of organizations, including industry leaders like Anthropic, xAI, Figma, and Vercel, rely on our platform to audit and manage their open source code safely. Founded by Feross Aboukhadijeh, a prominent open source maintainer whose software sees over a billion downloads monthly, we have secured 125 million dollars in funding from top-tier investors and security experts to continue building the future of supply chain security.
What is this role?
We are looking for a Threat Researcher to join our growing Threat Intelligence team. This is a full-time, remote position designed for a mid-level professional with at least 24 months of experience. You will be at the forefront of our efforts to combat software supply chain threats, using our proprietary AI-based scanner to protect developers and organizations across the globe.
What will you do?
- Analyze unique threats on a daily basis to maintain the high quality standards that define our approach to supply chain security.
- Publish high-impact research, including technical blog posts on malicious open source packages and deep dives into novel attack vectors and ecosystem trends.
- Design and develop automated tools and scripts to streamline our malware analysis, data collection, and threat hunting workflows.
What makes you a great fit?
To succeed in this role, you should have a strong background in security operations and a passion for open source software. We are looking for someone who brings the following:
- At least 3 years of professional experience alongside a degree in computer science or engineering, or equivalent practical expertise.
- Proven technical skills in malware analysis, reverse engineering, digital forensics, incident response, and threat intelligence.
- Experience building automation tools to aid in data collection and threat hunting.
- Strong communication skills and the ability to evaluate the impact of emerging threats.
- Familiarity with TypeScript or JavaScript is highly preferred, as is experience using AI or LLMs for threat detection.
What's in it for you?
We provide a supportive environment designed to help you thrive both professionally and personally. Our benefits package includes:
- Meaningful equity compensation.
- Comprehensive medical insurance coverage.
- Flexible paid time off to ensure you can rest and recharge.
- Generous maternity and paternity leave policies.
- A remote-first work environment supported by regular company retreats.






