Full-Time

Senior Software Engineer

Socket

Socket

51-200 employees

Developer-focused platform securing software supply chains

No salary listed

Remote in USA

Remote

Remote-first; quarterly team off-sites.

Category
Software Engineering (1)
Required Skills
JavaScript
React.js
Node.js
Postgres
TypeScript
REST APIs
Requirements
  • You've worked on an early stage team in a 0-1 role and would like to get back to building the foundations again
  • Experience with designing and implementing production web applications
  • Experience with building and integrating APIs and relational databases like PostgreSQL
  • Proficiency with Node.js, JavaScript, React, and TypeScript
  • Not bound to a particular tech stack and can learn new technologies on-the-go
Responsibilities
  • Contribute to the development of the Socket web application end-to-end
  • Work with the design team to develop interfaces that abstract away complexities and deliver an elegant and delightful user experience
  • Write APIs to deliver data from multiple data sources
  • Extract and transform data from third party APIs
  • Help shape the roadmap and plan sprints that allow us to quickly deliver features and be agile to user feedback
  • Be a key part of hiring, including interviewing and providing input into team growth decisions
Desired Qualifications
  • Bonus points for experience with GraphQL
  • ElasticSearch
  • Headless browsers
  • data pipelines

Socket provides a developer-first security platform that protects software supply chains by securing open-source dependencies. It proactively detects and blocks malware and vulnerable packages in real time, integrating with developer workflows like GitHub so issues are surfaced as developers work. The product supports languages such as JavaScript, Python, and Go and offers a CLI and a browser extension to embed protection into existing toolchains. Unlike some security tools that scan after code is written or after deployment, Socket aims to stop threats before they are added to a codebase by embedding checks directly into developers’ workflows. The company's goal is to help organizations safely use open-source software by reducing the risk from compromised or outdated dependencies across the software development lifecycle.

Company Size

51-200

Company Stage

Series B

Total Funding

$64.6M

Headquarters

Wilmington, Delaware

Founded

2020

Simplify Jobs

Simplify's Take

What believers are saying

  • Secure Annex acquisition expands coverage to browser and IDE extensions.
  • PHP support via Composer unlocks 440,000 Packagist packages powering 75% of websites.
  • 400% revenue growth in 2024 with $40M Series B from a16z and Elad Gil.

What critics are saying

  • GitHub's free scanning erodes Socket's pricing power within 6-12 months.
  • Snyk dominates with 4M developers, undercutting Secure Annex strategy.
  • Secure Annex integration fails as one-person startup lacks product-market fit.

What makes Socket unique

  • Socket analyzes dependency behavior to detect 100 zero-day attacks weekly.
  • AI integrations with Anthropic and OpenAI generate precise vulnerability summaries.
  • Reachability analysis from Coana acquisition reduces false positives in SCA.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Socket who can refer or advise you

Benefits

Company Equity

Health Insurance

Flexible Work Hours

Paid Holidays

Paid Parental Leave

Remote Work Options

Company Social Events

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-1%

2 year growth

-2%
The Associated Press
Feb 17th, 2026
Socket adds PHP support with Composer and Packagist integration for supply chain security

Socket has announced support for the PHP ecosystem, integrating Composer and Packagist into its software supply chain security platform. PHP developers can now search packages, generate Software Bills of Materials from Composer projects, and detect supply chain risks across dependencies. PHP powers roughly 75% of websites with a known server-side language. Packagist hosts over 440,000 packages with more than 169 billion installations since 2012, and Composer downloads exceed 2 billion packages monthly. Socket's AI-powered platform detects zero-day threats, typosquatting, backdoors and obfuscated code beyond traditional vulnerability scanning. Package search and browsing are available immediately, whilst SBOM generation and security scanning are in experimental release. Socket protects 14,000 organisations and 1.2 million repositories, securing over 2 million commits monthly and identifying 1,000 supply chain attacks weekly.

Vulert Ltd
May 27th, 2025
Critical Warning: Over 70 npm and VS Code Packages Found Stealing Sensitive Data and Cryptocurrency

Security firm Socket recently revealed a massive campaign involving over 70 malicious npm and VS Code packages stealing data and crypto.

Crowdfund Insider
Apr 23rd, 2025
Supply Chain Software Security Firm Socket Acquires Coana

With the news following Socket's $40M Series B funding led by Abstract Ventures, Elad Gil and a16z, Zane Lackey, general partner at a16z, said "Socket's approach to open source security is simply better - it's proactive, precise, and built for how modern teams work.

GlobeNewswire
Apr 23rd, 2025
Socket Acquires Coana to Bring Best-in-Class Reachability Analysis to Modern SCA

Socket’s acquisition of Coana brings best-in-class reachability analysis to application security teams globally, cementing Socket’s position as the leader...

Ernold Media
Apr 15th, 2025
Masquerading payment npm package installs backdoor

Cybersecurity researchers at Socket have uncovered a malicious npm package that hijacks server control during payment transactions.