Full-Time

Threat Analyst

Socket

Socket

51-200 employees

Developer-focused platform securing software supply chains

Compensation Overview

$126k - $170k/yr

United States

Remote

Quarterly on-site team off-sites; remote-first with flexibility

Category
IT & Security (1)
Required Skills
Malware Analysis
reverse engineering
Git
Requirements
  • 3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience)
  • Technical experience across several areas of security operations, including investigations, incident response and management, digital forensics, malware analysis, reverse engineering, threat intelligence, threat hunting, and detection engineering
  • Excellent communication skills and the ability to assess the relevance and impact of threats
  • Experience building tools for automation, data collection, and threat hunting
  • Passion for open source and code
Responsibilities
  • Analyze numerous unique threats daily, maintaining a standard of quality that sets the industry benchmark for supply chain security
  • Author high-impact technical blog posts on malicious open source code packages and extensions, and publish deep-dive research pieces on malicious campaigns, threat actor profiles, novel attack vectors, and ecosystem-wide trends
  • Design and build automated scripts and tools to streamline malware analysis, enhancing our data collection, threat analysis, and threat hunting workflows
  • Partner with our engineering team to integrate your research into our core product, turning manual insights into scalable, real-time protection
  • Leverage expertise in open source software ecosystems to enhance security across package registries, browser extensions (Chrome/VS Code), and proactively monitor GitHub/GitLab for emerging malicious campaigns
  • Track APT (Advanced Persistent Threat) adversaries, characterizing various TTPs (Tactics, Techniques, and Procedures), capabilities, infrastructure, and campaigns
Desired Qualifications
  • Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket
  • Experience leveraging LLMs or AI-based tools for threat detection

Socket provides a developer-first security platform that protects software supply chains by securing open-source dependencies. It proactively detects and blocks malware and vulnerable packages in real time, integrating with developer workflows like GitHub so issues are surfaced as developers work. The product supports languages such as JavaScript, Python, and Go and offers a CLI and a browser extension to embed protection into existing toolchains. Unlike some security tools that scan after code is written or after deployment, Socket aims to stop threats before they are added to a codebase by embedding checks directly into developers’ workflows. The company's goal is to help organizations safely use open-source software by reducing the risk from compromised or outdated dependencies across the software development lifecycle.

Company Size

51-200

Company Stage

Series B

Total Funding

$64.6M

Headquarters

Wilmington, Delaware

Founded

2020

Simplify Jobs

Simplify's Take

What believers are saying

  • Secure Annex acquisition expands coverage to browser and IDE extensions.
  • PHP support via Composer unlocks 440,000 Packagist packages powering 75% of websites.
  • 400% revenue growth in 2024 with $40M Series B from a16z and Elad Gil.

What critics are saying

  • GitHub's free scanning erodes Socket's pricing power within 6-12 months.
  • Snyk dominates with 4M developers, undercutting Secure Annex strategy.
  • Secure Annex integration fails as one-person startup lacks product-market fit.

What makes Socket unique

  • Socket analyzes dependency behavior to detect 100 zero-day attacks weekly.
  • AI integrations with Anthropic and OpenAI generate precise vulnerability summaries.
  • Reachability analysis from Coana acquisition reduces false positives in SCA.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Socket who can refer or advise you

Benefits

Company Equity

Health Insurance

Flexible Work Hours

Paid Holidays

Paid Parental Leave

Remote Work Options

Company Social Events

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-1%

2 year growth

-2%
The Associated Press
Feb 17th, 2026
Socket adds PHP support with Composer and Packagist integration for supply chain security

Socket has announced support for the PHP ecosystem, integrating Composer and Packagist into its software supply chain security platform. PHP developers can now search packages, generate Software Bills of Materials from Composer projects, and detect supply chain risks across dependencies. PHP powers roughly 75% of websites with a known server-side language. Packagist hosts over 440,000 packages with more than 169 billion installations since 2012, and Composer downloads exceed 2 billion packages monthly. Socket's AI-powered platform detects zero-day threats, typosquatting, backdoors and obfuscated code beyond traditional vulnerability scanning. Package search and browsing are available immediately, whilst SBOM generation and security scanning are in experimental release. Socket protects 14,000 organisations and 1.2 million repositories, securing over 2 million commits monthly and identifying 1,000 supply chain attacks weekly.

Vulert Ltd
May 27th, 2025
Critical Warning: Over 70 npm and VS Code Packages Found Stealing Sensitive Data and Cryptocurrency

Security firm Socket recently revealed a massive campaign involving over 70 malicious npm and VS Code packages stealing data and crypto.

Crowdfund Insider
Apr 23rd, 2025
Supply Chain Software Security Firm Socket Acquires Coana

With the news following Socket's $40M Series B funding led by Abstract Ventures, Elad Gil and a16z, Zane Lackey, general partner at a16z, said "Socket's approach to open source security is simply better - it's proactive, precise, and built for how modern teams work.

GlobeNewswire
Apr 23rd, 2025
Socket Acquires Coana to Bring Best-in-Class Reachability Analysis to Modern SCA

Socket’s acquisition of Coana brings best-in-class reachability analysis to application security teams globally, cementing Socket’s position as the leader...

Ernold Media
Apr 15th, 2025
Masquerading payment npm package installs backdoor

Cybersecurity researchers at Socket have uncovered a malicious npm package that hijacks server control during payment transactions.