Vulnerability Research Engineer
at Socket
About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage
Job Overview
Published
Sep 15, 2026
Expires
Dec 14, 2026
Source
Socket
Region
IT
Type
Remote / Work From Home
Category
WFH
Seniority
Lead
Job Description
About Us Socket helps devs and security teams ship faster by cutting out security busywork.
Thousands of orgs use Socket to safely find, audit, and manage open source code.
Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!) Founded by Feross Aboukhadijeh , a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $ 125M in funding from top angels, operators, and security leaders.
About the Role Join Socket to build and scale our patching infrastructure that delivers secure, vetted packages to developers worldwide.
You’ll be at the forefront of supply chain security, creating patches for critical vulnerabilities and building the systems that help the entire open source ecosystem stay secure.
This role combines deep technical work with meaningful community impact that benefits the entire ecosystem.
As an early member of the Socket team, you’ll help shape how we scale this technology across the JavaScript ecosystem and beyond.
What You'll Do Master Socket workflows, tools, and patching processes Lead patching efforts for high-impact vulnerabilities across npm packages Scale patch production to dozens or hundreds of patches per week Help select and prioritize high-value patches Provide technical input on patch prioritization based on ecosystem and customer impact Build and improve automated patching infrastructure and tooling Design and implement scalable patch generation and delivery systems Develop automated vulnerability detection and patch creation workflows Build APIs and integrations to deliver certified packages Create tooling for patch quality assurance and testing Work with security researchers to understand and patch critical vulnerabilities Help shape the technical roadmap for expansion Give developers quick, safe remediation options for widely-used packages Help secure the software supply chain for millions of developers What You'll Bring Required: 3+ years of software engineering experience with production systems Strong proficiency in Node.js, JavaScript, and TypeScript Experience with package managers (npm, yarn, pnpm) and the JavaScript ecosystem Understanding of software security concepts and vulnerability management Experience building and scaling APIs and data processing pipelines Familiarity with automated testing, CI/CD, and deployment systems Preferred:
Experience with security tooling, vulnerability scanning, or patch management Knowledge of software supply chain security challenges Experience with other package ecosystems (Python, Go, Rust, etc.) Open source contributions or package maintenance experience Background in DevSecOps or security engineering Experience with high-throughput data processing systems Our Interview Process Informational with a member from our Talent Team Hiring Manager Interview Take-home problem Internal review of take-home Live review of take-home Debrief Final Interview with Feross References Decision/Offer Hiring is a big decision on both sides.
Read more about our Hiring Philosophy and how we approach the process at Socket.
Benefits
Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work.
We offer
Market competitive salary bands Meaningful equity program Comprehensive health benefits for you and your family (99% coverage) Flexible time-off, holidays, and winter shutdown to rest & recharge Paid parental leave Remote-first, with quarterly team off-sites At Socket, we Pursue Excellence:
We set ourselves apart by consistently delivering work of exceptional quality and distinction.
Move with urgency and focus
We prioritize swift, decisive action.
Think rigorously
We care about being right and it often takes reasoning from first principles to get there.
We value alternative perspectives and have constructive discussions.
Trust and amplify
We overtrust, always assume good intent, and give specific feedback to help each other improve.
Feel a strong sense of ownership
We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.
Are customer obsessed
We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.
Remote Work Guidelines & Career Insights
Practical advice for succeeding as a remote professional in this role.
Asynchronous Productivity
High-performing remote teams prioritize asynchronous communication. Document your progress clearly in tickets, maintain organized project repositories, and communicate status updates proactively without waiting for real-time meetings.
Home Office & Security
Ensure a private, quiet workstation with a reliable high-speed broadband connection (min 50 Mbps). Maintain compliance with employer cybersecurity policies by utilizing secure password managers, 2FA authentication, and authorized VPN services.
Resume & Application Tips
Tailor your CV specifically to the requirements of Vulnerability Research Engineer. Highlight quantifiable achievements from past roles (e.g. revenue growth, efficiency improvements, or software shipped) and showcase proven experience collaborating with remote teams.
Virtual Interview Prep
Test your video and audio hardware before virtual calls. Prepare concise STAR-format stories demonstrating how you manage time independently, handle conflicting priorities across different time zones, and solve complex problems autonomously.
Frequently Asked Questions
Key answers about the application process, remote setup, and compensation for Vulnerability Research Engineer.
Is the Vulnerability Research Engineer role 100% remote?+
Yes, this is a fully remote work-from-home position with Socket. You can collaborate asynchronously, manage project deliverables, and participate in virtual team meetings from your home office without daily commuting.
What qualifications and experience are needed for Vulnerability Research Engineer?+
Applicants are typically evaluated on relevant industry background, core capabilities, and self-management. Key requirements include strong English communication skills, independent problem-solving abilities, and familiarity with modern remote collaboration platforms like Slack, Zoom, and project management tools.
Who is eligible to apply for this job?+
This remote opening welcomes applications from IT and eligible remote regions. Candidates must ensure they meet the work authorization, residency, or independent contractor criteria required by Socket.
What is the salary and benefits package for Vulnerability Research Engineer?+
The expected compensation for this role is competitive compensation aligned with global remote market standards. In addition to base compensation, remote positions often provide flexible working hours, home office equipment stipends, and professional growth opportunities.
How do I apply and what should I prepare for the interview?+
Click the "Apply Now" button on this page to visit Socket's official application portal. Tailor your resume to highlight relevant achievements, and prepare to discuss your experience working productively in an asynchronous remote environment.
Related Skills & Keywords
Similar Remote Jobs
Application Security Engineer at Virtru — 100% Remote | Apply Now
Virtru
⚡ BMC Remedy/Helix Developer at General Dynamics Information Technology — 100% Remote | Apply Direct
General Dynamics Information Technology
⚡ Jira Lead Administrator at Contact Government Services — 100% Remote | Apply Direct
Contact Government Services
⚡ Home-Based Sales & Product Support Specialist at DCX PH — 100% Remote | Apply Direct
DCX PH
Explore More Remote Opportunities
Discover verified work-from-home positions by role, category, and regional hiring markets.
Popular Job Categories
Save this remote job alert.
Store your email with the current page context so you can keep track of similar remote opportunities and reuse this search later.
Search alerts are stored with your current page context so you can track similar jobs over time.
Ready to Apply?
Click the button below to apply on the employer's official website. Always verify job details before submitting personal information.