Full-Time

Staff Security Engineer

Socket

Socket

51-200 employees

Developer-focused platform securing software supply chains

No salary listed

Remote in USA

Remote

Category
IT & Security
Required Skills
Computer Networking
TypeScript
Vulnerability Analysis
SOC 2
penetration testing
Google Cloud Platform

Get referred to Socket

Find people who can refer or advise you

Requirements
  • You've owned security broadly at a growth-stage company, or you're a strong software engineer who's moved into security and is ready to own the function end-to-end.
  • You can ship production TypeScript.
  • You have breadth across security domains (AppSec, CloudSec, OpSec) and you're comfortable learning fast where gaps exist.
  • You're fluent in cloud infrastructure (we use GCP): VPCs, IAM, secret management, networking.
  • You're a self-directed operator who figures out what matters most and executes across many fronts without waiting to be told what to do. You move fast, find leverage, and get a lot done with a little.
  • You have the communication and teaching skills to make an entire engineering org care about security, not by blocking people, but by earning trust and making the secure path the easy path.
Responsibilities
  • Improve Socket's security posture across the board. Own, cloud infrastructure hardening, operational security, and IT security. Write code and build tooling that makes the secure path the default path for engineers. Roll out identity and access controls, close gaps across the stack, and continuously reduce risk.
  • Assess, prioritize, and drive the security roadmap. Figure out what matters most, balance quick wins with longer-term improvements, and execute across many fronts in parallel. You won't wait to be told what to work on. You'll develop a clear picture of where Socket's risks are and make steady progress against them.
  • Run incident response and external security operations. Build and run a 24/7 security incident response process. Own the security inbox, triage inbound vulnerability reports, manage pentests, and coordinate fixes. When you can fix something directly, you do.
  • Maintain compliance and drive new certifications. Maintain our existing SOC 2 compliance. Drive new certifications (ISO 27001, etc.) as needed for enterprise customers.
  • Raise security awareness and culture across the org. Train engineers to write more secure code. Run phishing simulations. Build trust with engineering teams so that security feels like an enabler, not a blocker. Make people want to do the right thing rather than resenting security as a tax.

Socket provides a developer-first security platform that protects software supply chains by securing open-source dependencies. It proactively detects and blocks malware and vulnerable packages in real time, integrating with developer workflows like GitHub so issues are surfaced as developers work. The product supports languages such as JavaScript, Python, and Go and offers a CLI and a browser extension to embed protection into existing toolchains. Unlike some security tools that scan after code is written or after deployment, Socket aims to stop threats before they are added to a codebase by embedding checks directly into developers’ workflows. The company's goal is to help organizations safely use open-source software by reducing the risk from compromised or outdated dependencies across the software development lifecycle.

Company Size

51-200

Company Stage

Series C

Total Funding

$124.6M

Headquarters

Wilmington, Delaware

Founded

2020

Get referred to Socket

Find people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Series C raised $60 million at a $1 billion valuation.[11]
  • Axios incident drove 2,000+ onboardings within 24 hours.[11]
  • Supports Java, Python, Go, JavaScript, and Ruby enterprise stacks.[15]

What critics are saying

  • Incumbents like Snyk, Mend, GitHub, and GitLab bundle similar checks.[9]
  • Behavioral detection misses slow-rolling malware and conditional payloads.[11][14]
  • High valuation demands rapid enterprise expansion and retention.

What makes Socket unique

  • Developer-first supply-chain security blocks malicious packages before download.[1][6]
  • Behavioral dependency analysis finds novel threats beyond CVE-only scanners.[11][14]
  • GitHub and CLI integrations fit PRs, installs, and CI workflows.[4][9]

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Health Insurance

Flexible Work Hours

Paid Holidays

Paid Parental Leave

Remote Work Options

Company Social Events

Growth & Insights and Company News

Headcount

6 month growth

2%

1 year growth

5%

2 year growth

9%
The Associated Press
Feb 17th, 2026
Socket adds PHP support with Composer and Packagist integration for supply chain security

Socket has announced support for the PHP ecosystem, integrating Composer and Packagist into its software supply chain security platform. PHP developers can now search packages, generate Software Bills of Materials from Composer projects, and detect supply chain risks across dependencies. PHP powers roughly 75% of websites with a known server-side language. Packagist hosts over 440,000 packages with more than 169 billion installations since 2012, and Composer downloads exceed 2 billion packages monthly. Socket's AI-powered platform detects zero-day threats, typosquatting, backdoors and obfuscated code beyond traditional vulnerability scanning. Package search and browsing are available immediately, whilst SBOM generation and security scanning are in experimental release. Socket protects 14,000 organisations and 1.2 million repositories, securing over 2 million commits monthly and identifying 1,000 supply chain attacks weekly.

Vulert Ltd
May 27th, 2025
Critical Warning: Over 70 npm and VS Code Packages Found Stealing Sensitive Data and Cryptocurrency

Security firm Socket recently revealed a massive campaign involving over 70 malicious npm and VS Code packages stealing data and crypto.

Crowdfund Insider
Apr 23rd, 2025
Supply Chain Software Security Firm Socket Acquires Coana

With the news following Socket's $40M Series B funding led by Abstract Ventures, Elad Gil and a16z, Zane Lackey, general partner at a16z, said "Socket's approach to open source security is simply better - it's proactive, precise, and built for how modern teams work.

GlobeNewswire
Apr 23rd, 2025
Socket Acquires Coana to Bring Best-in-Class Reachability Analysis to Modern SCA

Socket’s acquisition of Coana brings best-in-class reachability analysis to application security teams globally, cementing Socket’s position as the leader...

Ernold Media
Apr 15th, 2025
Masquerading payment npm package installs backdoor

Cybersecurity researchers at Socket have uncovered a malicious npm package that hijacks server control during payment transactions.