← All roles
S

Vulnerability Research Software Engineer

Socket · Engineering · Mid · 10d ago

✓

Anyone, anywhere in the world can apply.

WorldwideAny timezoneRustNode.jsTypeScriptSecurity

Direct from the employer's own careers page

Who can apply

Read straight from the listing, so you know before you spend time on it.

Anywhere in the world

Anyone, anywhere in the world can apply.

Async-first
The listing doesn't promise async-first working.
Contractor / B2B
No mention of hiring international contractors or invoicing.
Global stipend
No home office or equipment budget mentioned.
Annual retreat
Socket holds quarterly team off-sites.

Read from the listing automatically. Always confirm the details with the company before you accept an offer.

About the role

In this role, you will help build and scale Socket's patching infrastructure to deliver secure, vetted packages to developers worldwide. You will tackle challenging CLI work, handle package-manager integrations across ecosystems like npm, yarn, and pnpm, and translate dependency and vulnerability workflows into reliable developer-facing interfaces. As an early member of the team, you will collaborate closely with security researchers to understand critical vulnerabilities and scale automated patch production.

What you'll do

  • Build and maintain CLI tooling and package-manager integrations in customer Unix-based environments.
  • Scale patch production to dozens or hundreds of vetted patches per week.
  • Build and improve automated patching infrastructure, APIs, and tooling for patch QA and testing.
  • Debug implementation issues across Unix-based environments and handle ecosystem-specific edge cases.
  • Work closely with security researchers to understand and patch critical vulnerabilities across open source packages.
  • Contribute to frontend experiences using JavaScript, React, and TypeScript.

What you bring

  • 3+ years of software engineering experience with production systems.
  • Strong proficiency in Rust and Unix/Linux environments.
  • Proficiency in Node.js, JavaScript, and TypeScript.
  • Experience with package managers (npm, yarn, pnpm) and the JavaScript ecosystem.
  • Understanding of software security concepts and vulnerability management.
  • Experience building and scaling APIs and data processing pipelines.

About Socket

Founded by Feross Aboukhadijeh, Socket helps developers and security teams safely find, audit, and manage open source code to secure software supply chains. Backed by $125M in funding, Socket is trusted by major tech organizations including Anthropic, xAI, Figma, and Vercel.

View Socket profile & open roles →

Get new verified roles in your inbox — no account needed.

Unsubscribe any time. See our Privacy Policy.