Socket
Threat Researcher
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 9 months ago · Added yesterday
Been open since 9 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
$126,000–$170,000
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Entry
Category
Software
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Us
Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!)
Founded by Feross Aboukhadijeh , a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $ 125M in funding from top angels, operators, and security leaders.
About the Role
Socket is looking for a Threat Researcher to join our growing Threat Intelligence Team. In this role, you’ll tackle cutting-edge threats in the software supply chain, leveraging our proprietary AI-based scanner and building tools to enhance malware analysis. You’ll secure open source ecosystems, strengthen threat detection across multiple programming languages, and conduct research that helps protect developers and organizations worldwide. This is not an entry-level position. This is a hands-on role for someone passionate about threat hunting, security research, automation, and turning insights into actionable defenses.
What You'll Do
Analyze numerous unique threats daily, maintaining a standard of quality that sets the industry benchmark for supply chain security.
Author high-impact technical blog posts on malicious open source code packages and extensions, and publish deep-dive research pieces on malicious campaigns, threat actor profiles, novel attack vectors, and ecosystem-wide trends.
Design and build automated scripts and tools to streamline malware analysis, enhancing our data collection, threat analysis, and threat hunting workflows.
Partner with our engineering team to integrate your research into our core product, turning manual insights into scalable, real-time protection.
Leverage expertise in open source software ecosystems to enhance security across package registries, browser extensions (Chrome/VS Code), and proactively monitor GitHub/GitLab for emerging malicious campaigns.
Track APT (Advanced Persistent Threat) adversaries, characterizing various TTPs (Tactics, Techniques, and Procedures), capabilities, infrastructure, and campaigns.
What You'll Bring
Required:
3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience).
Technical experience across several areas of security operations, including investigations, incident response and management, digital forensics, malware analysis, reverse engineering, threat intelligence, threat hunting, and detection engineering.
Excellent communication skills and the ability to assess the relevance and impact of threats.
Experience building tools for automation, data collection, and threat hunting.
Passion for open source and code.
Preferred:
Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket.
Experience leveraging LLMs or AI-based tools for threat detection.
Hiring is a big decision on both sides. Read more about our Hiring Philosophy and how we approach the process at Socket.
Benefits: Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work. We offer:
Requirements
- ·3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience).
- ·Excellent communication skills and the ability to assess the relevance and impact of threats.
- ·Experience building tools for automation, data collection, and threat hunting.
- ·Passion for open source and code.
- ·Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket.
Benefits
- ·Flexible time-off, holidays, and winter shutdown to rest & recharge
- ·Paid parental leave
- ·Remote-first, with quarterly team off-sites
- ·Pursue Excellence: We set ourselves apart by consistently delivering work of exceptional quality and distinction.
- ·Move with urgency and focus: We prioritize swift, decisive action.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Socket, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$126,000–$170,000 · You'll be taken to the employer's careers page.