📍 Italy💼 WFH🏢 SocketSep 15, 2026
SO

Vulnerability Research Engineer

at Socket

About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage

Level: Lead
✨ Apply Now ↗Opens employer's official career page

Job Overview

Published

Sep 15, 2026

Expires

Dec 14, 2026

Source

Socket

Region

IT

Type

Remote / Work From Home

Category

WFH

Seniority

Lead

Job Description

About Us Socket helps devs and security teams ship faster by cutting out security busywork.

Thousands of orgs use Socket to safely find, audit, and manage open source code.

Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!) Founded by Feross Aboukhadijeh , a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $ 125M in funding from top angels, operators, and security leaders.

About the Role Join Socket to build and scale our patching infrastructure that delivers secure, vetted packages to developers worldwide.

You’ll be at the forefront of supply chain security, creating patches for critical vulnerabilities and building the systems that help the entire open source ecosystem stay secure.

This role combines deep technical work with meaningful community impact that benefits the entire ecosystem.

As an early member of the Socket team, you’ll help shape how we scale this technology across the JavaScript ecosystem and beyond.

What You'll Do Master Socket workflows, tools, and patching processes Lead patching efforts for high-impact vulnerabilities across npm packages Scale patch production to dozens or hundreds of patches per week Help select and prioritize high-value patches Provide technical input on patch prioritization based on ecosystem and customer impact Build and improve automated patching infrastructure and tooling Design and implement scalable patch generation and delivery systems Develop automated vulnerability detection and patch creation workflows Build APIs and integrations to deliver certified packages Create tooling for patch quality assurance and testing Work with security researchers to understand and patch critical vulnerabilities Help shape the technical roadmap for expansion Give developers quick, safe remediation options for widely-used packages Help secure the software supply chain for millions of developers What You'll Bring Required: 3+ years of software engineering experience with production systems Strong proficiency in Node.js, JavaScript, and TypeScript Experience with package managers (npm, yarn, pnpm) and the JavaScript ecosystem Understanding of software security concepts and vulnerability management Experience building and scaling APIs and data processing pipelines Familiarity with automated testing, CI/CD, and deployment systems Preferred:

Experience with security tooling, vulnerability scanning, or patch management Knowledge of software supply chain security challenges Experience with other package ecosystems (Python, Go, Rust, etc.) Open source contributions or package maintenance experience Background in DevSecOps or security engineering Experience with high-throughput data processing systems Our Interview Process Informational with a member from our Talent Team Hiring Manager Interview Take-home problem Internal review of take-home Live review of take-home Debrief Final Interview with Feross References Decision/Offer Hiring is a big decision on both sides.

Read more about our Hiring Philosophy and how we approach the process at Socket.

Benefits

Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work.

We offer

Market competitive salary bands Meaningful equity program Comprehensive health benefits for you and your family (99% coverage) Flexible time-off, holidays, and winter shutdown to rest & recharge Paid parental leave Remote-first, with quarterly team off-sites At Socket, we Pursue Excellence:

We set ourselves apart by consistently delivering work of exceptional quality and distinction.

Move with urgency and focus

We prioritize swift, decisive action.

Think rigorously

We care about being right and it often takes reasoning from first principles to get there.

We value alternative perspectives and have constructive discussions.

Trust and amplify

We overtrust, always assume good intent, and give specific feedback to help each other improve.

Feel a strong sense of ownership

We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.

Are customer obsessed

We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.

Remote Work Guidelines & Career Insights

Practical advice for succeeding as a remote professional in this role.

Asynchronous Productivity

High-performing remote teams prioritize asynchronous communication. Document your progress clearly in tickets, maintain organized project repositories, and communicate status updates proactively without waiting for real-time meetings.

🛡️

Home Office & Security

Ensure a private, quiet workstation with a reliable high-speed broadband connection (min 50 Mbps). Maintain compliance with employer cybersecurity policies by utilizing secure password managers, 2FA authentication, and authorized VPN services.

🎯

Resume & Application Tips

Tailor your CV specifically to the requirements of Vulnerability Research Engineer. Highlight quantifiable achievements from past roles (e.g. revenue growth, efficiency improvements, or software shipped) and showcase proven experience collaborating with remote teams.

💬

Virtual Interview Prep

Test your video and audio hardware before virtual calls. Prepare concise STAR-format stories demonstrating how you manage time independently, handle conflicting priorities across different time zones, and solve complex problems autonomously.

Frequently Asked Questions

Key answers about the application process, remote setup, and compensation for Vulnerability Research Engineer.

Is the Vulnerability Research Engineer role 100% remote?+

Yes, this is a fully remote work-from-home position with Socket. You can collaborate asynchronously, manage project deliverables, and participate in virtual team meetings from your home office without daily commuting.

What qualifications and experience are needed for Vulnerability Research Engineer?+

Applicants are typically evaluated on relevant industry background, core capabilities, and self-management. Key requirements include strong English communication skills, independent problem-solving abilities, and familiarity with modern remote collaboration platforms like Slack, Zoom, and project management tools.

Who is eligible to apply for this job?+

This remote opening welcomes applications from IT and eligible remote regions. Candidates must ensure they meet the work authorization, residency, or independent contractor criteria required by Socket.

What is the salary and benefits package for Vulnerability Research Engineer?+

The expected compensation for this role is competitive compensation aligned with global remote market standards. In addition to base compensation, remote positions often provide flexible working hours, home office equipment stipends, and professional growth opportunities.

How do I apply and what should I prepare for the interview?+

Click the "Apply Now" button on this page to visit Socket's official application portal. Tailor your resume to highlight relevant achievements, and prepare to discuss your experience working productively in an asynchronous remote environment.

Related Skills & Keywords

Similar Remote Jobs

🌐

Explore More Remote Opportunities

Discover verified work-from-home positions by role, category, and regional hiring markets.

Save this remote job alert.

Store your email with the current page context so you can keep track of similar remote opportunities and reuse this search later.

Search alerts are stored with your current page context so you can track similar jobs over time.

🚀

Ready to Apply?

Click the button below to apply on the employer's official website. Always verify job details before submitting personal information.

Vulnerability Research Engineer
Socket • Verified Remote
Apply Now