About the job
About Us
At Socket, we're revolutionizing the way developers and security teams approach open source code. Our platform streamlines the process of safely identifying, auditing, and managing open source packages, allowing teams to focus on innovation rather than security busywork. Trusted by industry leaders, including Anthropic, xAI, Figma, and Vercel, Socket is quickly becoming a favorite among developers worldwide. Want to see what our clients think? Check out their testimonials!
Founded by Feross Aboukhadijeh, a prominent figure in the open source community with software downloaded over a billion times monthly, Socket has successfully raised $65M in funding from esteemed investors and security experts.
About the Role
We are seeking a passionate Vulnerability Research Engineer to join our team. In this role, you will be pivotal in developing and scaling our patching infrastructure, delivering secure and vetted packages to developers around the globe. You will play a critical role in enhancing supply chain security by creating patches for key vulnerabilities and building systems that support the entire open source ecosystem.
As an early member of the Socket team, you will have the opportunity to influence the direction of our technology and help us expand its reach across the JavaScript ecosystem and beyond.
What You'll Do
Become an expert in Socket's workflows, tools, and patching processes.
Lead initiatives to patch high-impact vulnerabilities within npm packages.
Scale patch production to accommodate dozens or hundreds of patches weekly.
Assist in selecting and prioritizing high-value patches.
Provide technical insights on patch prioritization based on ecosystem and customer impact.
Build and enhance automated patching infrastructure and tooling.
Design and implement scalable systems for patch generation and delivery.
Develop automated workflows for vulnerability detection and patch creation.
Create APIs and integrations for delivering certified packages.
Establish tooling for patch quality assurance and testing.
Collaborate with security researchers to identify and address critical vulnerabilities.

