Vulnerability Research Engineer
Remote
Full Time
#Engineering
#Security
#Node.Js
#JavaScript
#TypeScript
#NPM
#API Development
At Socket, we are on a mission to help developers and security teams move faster by eliminating the burden of security busywork. Thousands of organizations, including industry leaders like Anthropic, xAI, Figma, and Vercel, rely on our platform to audit and manage open source code safely. Founded by Feross Aboukhadijeh, a veteran open source maintainer whose software sees over a billion downloads monthly, we have secured 125 million dollars in funding to redefine how the industry approaches supply chain security. We are looking for passionate individuals to join us in building a safer ecosystem for developers everywhere.
The role
We are seeking a Vulnerability Research Engineer to join our team on a full-time, remote basis. This is a mid-level position requiring approximately 24 months of professional experience. In this role, you will be at the heart of our mission, scaling the infrastructure that delivers vetted, secure packages to developers across the globe. You will combine deep technical expertise with a commitment to community impact, helping us shape the future of software supply chain security.
Core responsibilities
- Lead the effort to identify and patch high-impact vulnerabilities within the npm ecosystem, scaling our output to handle dozens or hundreds of patches every week.
- Design and build robust, automated infrastructure for patch generation, quality assurance, and delivery systems.
- Collaborate with security researchers to prioritize high-value patches and develop APIs that provide developers with safe, rapid remediation options.
Skills and experience
To succeed in this role, you should have a strong foundation in software engineering and a passion for security. We are looking for the following qualifications:
- At least 3 years of experience working with production-grade software systems.
- Deep technical proficiency in Node.js, JavaScript, and TypeScript.
- Hands-on experience with package managers like npm, yarn, or pnpm.
- A solid understanding of software security principles, vulnerability management, and API development.
- Familiarity with CI/CD pipelines, automated testing, and data processing workflows.
Compensation and benefits
We are committed to supporting our team members and their families through a comprehensive benefits package. Our perks include:
- Meaningful equity compensation to ensure you share in our success.
- Comprehensive medical insurance coverage.
- Generous paid time off, including holidays and a winter shutdown period.
- Supportive maternity and paternity leave policies.
- A remote-first work environment that encourages flexibility.
How to apply
If you are excited about securing the software supply chain and want to contribute to a high-growth team, we would love to hear from you. Our interview process is designed to be transparent and thorough, beginning with an informational chat with our talent team and moving through a technical assessment and interviews with our leadership. Please reach out to us through our careers portal to start the conversation and learn more about our hiring philosophy.




