--- title: 'Threat Researcher at Socket' canonical: 'https://feeny.ai/job/threat-researcher-socket-united-states-8ej5b58rxaxn' type: 'job' last_seen: '2026-09-10' --- # Threat Researcher at Socket - **Company:** Socket - **Location:** United States - **Compensation:** $126k–$170k - **Employment:** full-time - **Work type:** remote - **Posted:** 2025-12-23 - **Last confirmed live:** 2026-09-10 - **Apply:** https://jobs.ashbyhq.com/socket/7049663a-829f-4346-81ee-423d78a8589d ## Job description ## About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just [check out their tweets](https://socket.dev/love) to see for yourself!) Founded by [Feross Aboukhadijeh](https://www.linkedin.com/in/feross/), a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised [$](https://socket.dev/blog/series-b)[125M in funding](https://socket.dev/blog/series-c) from top angels, operators, and security leaders. ## About the Role Socket is looking for a Threat Researcher to join our growing Threat Intelligence Team. In this role, you’ll tackle cutting-edge threats in the software supply chain, leveraging our proprietary AI-based scanner and building tools to enhance malware analysis. You’ll secure open source ecosystems, strengthen threat detection across multiple programming languages, and conduct research that helps protect developers and organizations worldwide. This is not an entry-level position. This is a hands-on role for someone passionate about threat hunting, security research, automation, and turning insights into actionable defenses. ## What You'll Do - Analyze numerous unique threats daily, maintaining a standard of quality that sets the industry benchmark for supply chain security. - Author high-impact technical blog posts on malicious open source code packages and extensions, and publish deep-dive research pieces on malicious campaigns, threat actor profiles, novel attack vectors, and ecosystem-wide trends. - Design and build automated scripts and tools to streamline malware analysis, enhancing our data collection, threat analysis, and threat hunting workflows. - Partner with our engineering team to integrate your research into our core product, turning manual insights into scalable, real-time protection. - Leverage expertise in open source software ecosystems to enhance security across package registries, browser extensions (Chrome/VS Code), and proactively monitor GitHub/GitLab for emerging malicious campaigns. - Track APT (Advanced Persistent Threat) adversaries, characterizing various TTPs (Tactics, Techniques, and Procedures), capabilities, infrastructure, and campaigns. ## What You'll Bring Required: - 3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience). - Technical experience across several areas of security operations, including investigations, incident response and management, digital forensics, malware analysis, reverse engineering, threat intelligence, threat hunting, and detection engineering. - Excellent communication skills and the ability to assess the relevance and impact of threats. - Experience building tools for automation, data collection, and threat hunting. - Passion for open source and code. Preferred: - Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket. - Experience leveraging LLMs or AI-based tools for threat detection. Hiring is a big decision on both sides. Read more about our [Hiring Philosophy](https://socket.dev/hiring-philosophy)and how we approach the process at Socket. Benefits: Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work. We offer: - Market competitive salary bands - Meaningful equity program - Comprehensive health benefits for you and your family (99% coverage) - Flexible time-off, holidays, and winter shutdown to rest & recharge - Paid parental leave - Remote-first, with quarterly team off-sites At Socket, we - Pursue Excellence: We set ourselves apart by consistently delivering work of exceptional quality and distinction. - Move with urgency and focus: We prioritize swift, decisive action. - Think rigorously: We care about being right and it often takes reasoning from first principles to get there. We value alternative perspectives and have constructive discussions. - Trust and amplify: We overtrust, always assume good intent, and give specific feedback to help each other improve. - Feel a strong sense of ownership: We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains. - Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction. ## About Socket ## Company Overview - **One-liner**: Socket is a developer-first cybersecurity platform that proactively detects and blocks malicious packages in real time to prevent software supply chain attacks. - **Entity Type**: Private (venture-backed) - **Headquarters**: San Francisco, California, United States - **Founded**: 2021 - **Founders**: Feross Aboukhadijeh ## Core Business - Primary industry/industries: Cybersecurity, software supply chain security, open source risk management. - Target customers: B2B, serving developers and security teams across technology, media, healthcare, finance, and other industries; suitable for enterprises and SMBs alike. - Mission or purpose: To improve the security of the internet by helping developers ship faster and safely find, audit, and manage open source software at scale. ## Products & Services - **[Socket for GitHub](https://socket.dev)**: A GitHub app that scans pull requests for risky dependency additions and malicious updates before they merge. Detects malware, typosquats, HTTP dependencies, and more. (SaaS/integration) - **[Socket Firewall](https://socket.dev)**: A command-line tool that blocks malicious packages at install time (e.g., `$ sfw npm install`). Provides real-time scanning and protection during package installation. (CLI/agent) - **[Dependency Search](https://socket.dev)**: A search engine providing security insights, quality scores, maintenance ratings, vulnerability checks, and license info for millions of open source packages across npm, PyPI, and other registries. (Web tool/API) ## Market Standing - **Valuation/Market Cap**: Not publicly available. - **Key Metric**: Over 300,000 organizations protected; 11.6M+ code repositories protected; detects over 100 zero-day attacks every week. - **Notable Investors/Partners**: Backed by top-tier venture firms and industry leaders including Abstract Ventures, Elad Gil, Patrick Collinson, Zane Lackey (Ex-CEO of Signal Sciences), Haroon Meer (Thinkst), and others. - **Growth Signals**: Rapid adoption with 85+ (and growing) orgs explicitly shown; active hiring across 22+ roles; expanding product to keep pace with AI-generated code risks. ## Competitive Advantages - **Proactive, behavioral detection**: Unlike traditional security tools that rely on known vulnerability databases, Socket analyzes the actual behavior of packages to catch zero-day and novel threats before they cause harm. - **Developer-first workflow**: Integrates seamlessly into existing Git and CLI workflows (GitHub PRs, npm install) without disrupting developer velocity. - **Broad registry coverage**: Scans packages across npm, PyPI, and other major open source ecosystems, covering the 90% of modern codebases that come from open source. ## Strategic Focus - Deepening protection against AI-generated and rapidly changing open source dependencies. - Expanding detection capabilities to cover more registries and attack patterns. - Scaling the platform to serve both large enterprises and individual developers, with a continued emphasis on real-time, low-friction security. ## Why Work Here - **Culture**: Principles of learning, collaboration, transparency, experimentation, and passion. Team moves with urgency and trust, and is customer and feedback obsessed. - **Remote work**: Remote-first with core hours overlap; HQ office in San Francisco available but not required. - **Benefits**: Excellent health/dental/vision insurance (largely covered for you and dependents); unlimited time off; stock options; quarterly team offsites in beautiful locations; market-competitive salary benchmarking. - **Engineering culture**: Open source pedigree with founder Feross Aboukhadijeh (Node.js Foundation board, Stanford lecturer). Strong focus on shipping fast, secure software. ## Sources 1. [socket.dev](https://socket.dev) 2. [socket.dev/about](https://socket.dev/about) 3. [socket.dev/careers](https://socket.dev/careers) 4. [builtin.com](https://builtin.com/company/socket-0) ## Other roles at Socket - [Sales Development Representative](https://feeny.ai/job/sales-development-representative-socket-united-states-3fsh6np5x9ja) — United States - [Member of Technical Staff](https://feeny.ai/job/member-of-technical-staff-socket-united-states-5wjh976zb26r) — United States - [Compliance Engineering Lead](https://feeny.ai/job/compliance-engineering-lead-socket-united-states-92nf30x98zg0) — United States - [Sales Engineer, EMEA](https://feeny.ai/job/sales-engineer-emea-socket-united-kingdom-q0ye8kdbtz6e) — United Kingdom - [Social Media Manager](https://feeny.ai/job/social-media-manager-socket-remote-h4bf92mezhhc) - [Engineering Manager](https://feeny.ai/job/engineering-manager-socket-united-states-6cygm6zy309a) — United States - [Sales Engineer, Enterprise](https://feeny.ai/job/sales-engineer-enterprise-socket-united-states-was33jvdjrpe) — United States - [Sales Engineer, SMB](https://feeny.ai/job/sales-engineer-smb-socket-united-states-fz968t7dedry) — United States - [Technical Account Manager, Europe](https://feeny.ai/job/technical-account-manager-europe-socket-united-kingdom-b69ee41nmckg) — United Kingdom - [Channel & Partners Lead](https://feeny.ai/job/channel-partners-lead-socket-united-states-3n2cx50mjdxn) — United States