Full-Time

Engineering Manager

Socket

Socket

51-200 employees

Developer-focused platform securing software supply chains

No salary listed

Remote in USA

Remote

Quarterly team off-sites are required or expected.

Category
Engineering Management (1)
Required Skills
JavaScript
TypeScript

Get referred to Socket

See people who can refer or advise you

Requirements
  • Experience leading engineering teams in a fast-moving environment where priorities and solutions are not always clearly defined.
  • The ability to step toward ambiguous or unowned problems, including the seams between teams.
  • Strong technical judgment and the ability to engage deeply in architectural discussions, understand trade-offs, and guide technical decisions.
  • Strong product sense, including the ability to talk directly to customers, absorb inputs from many sources, and determine how a product should work.
  • Communication that keeps other teams informed about the team’s goals, needs, and progress, while providing sufficient context for good decisions.
  • The ability to balance long-term technical investments with near-term business needs.
  • The ability to foster ownership, accountability, and continuous improvement among engineers.
Responsibilities
  • Lead and grow a high-performing team of engineers by building a culture of trust, ownership, and autonomy where people can do their best work, make decisions, and continue to develop.
  • Partner closely with engineering and go-to-market stakeholders to ensure the team solves the right problems.
  • Stay engaged with technical decisions and help the team reason through architecture, trade-offs, and complexity.
  • Improve work processes by identifying bottlenecks, refining processes, and automating toil.
  • Bring clarity to ambiguous problems by helping the team align on priorities, make thoughtful decisions, and maintain strong execution.
  • Balance long-term technical investments with near-term business needs to ensure sustainable, high-quality outcomes.
  • Foster a culture of ownership, accountability, and continuous improvement where engineers are empowered to lead and make decisions.
Desired Qualifications
  • Comfort working in a TypeScript/JavaScript ecosystem is a plus.
  • Experience managing in a remote environment, ideally with a globally distributed team.

Socket provides a developer-first security platform that protects software supply chains by securing open-source dependencies. It proactively detects and blocks malware and vulnerable packages in real time, integrating with developer workflows like GitHub so issues are surfaced as developers work. The product supports languages such as JavaScript, Python, and Go and offers a CLI and a browser extension to embed protection into existing toolchains. Unlike some security tools that scan after code is written or after deployment, Socket aims to stop threats before they are added to a codebase by embedding checks directly into developers’ workflows. The company's goal is to help organizations safely use open-source software by reducing the risk from compromised or outdated dependencies across the software development lifecycle.

Company Size

51-200

Company Stage

Series C

Total Funding

$124.6M

Headquarters

Wilmington, Delaware

Founded

2020

Get referred to Socket

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Socket raised $60 million at a $1 billion valuation on May 20, 2026.
  • Axios compromise drove over 2,000 organizations onto Socket within 24 hours.
  • Socket says it protects 14,000 organizations and 1.2 million repositories, accelerating enterprise adoption.

What critics are saying

  • GitHub, npm, and IDE vendors can copy pre-install controls, commoditizing Socket by 2027.
  • Attackers now target extensions and MCP servers, stretching Socket beyond package-centric defenses.
  • One major false negative before production exposure would kill trust among enterprise security buyers.

What makes Socket unique

  • Socket blocks malicious dependencies before installation, not after CVE disclosure.
  • Its 2026 Secure Annex acquisition extends coverage into browser extensions, IDEs, and MCP servers.
  • Socket combines AI analysis with human review across JavaScript, Python, Go, and PHP.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Health Insurance

Flexible Work Hours

Paid Holidays

Paid Parental Leave

Remote Work Options

Company Social Events

Growth & Insights and Company News

Headcount

6 month growth

5%

1 year growth

4%

2 year growth

10%
TechStartups
May 21st, 2026
AI security startup Socket hits $1B valuation after $60M raise to stop software supply chain attacks.

AI security startup Socket hits $1B valuation after $60M raise to stop software supply chain attacks. AI-generated code is flooding into enterprise software faster than security teams can review it, and investors are betting that startups capable of spotting threats before they reach production could become one of the hottest categories in cybersecurity. That bet is helping Socket join the unicorn club. The developer security startup announced Thursday it has raised $60 million in Series C funding at a $1 billion valuation. The round was led by Thrive Capital, with participation from Andreessen Horowitz (a16z), Abstract Ventures, and Capital One Ventures. Founded in 2020, Socket is trying to solve a growing problem inside modern software development. AI coding tools are helping engineers ship code faster than ever, though much of that code relies heavily on open-source packages pulled from outside repositories. That has created new openings for attackers targeting software supply chains. The company counts Anthropic, xAI, Replit, Cursor, Figma, Vercel, Gusto, Mercado Libre, and Cribl among its customers, as well as Fortune 100 companies in financial services and media. As AI speeds up coding, Socket raises $60M to stop malicious open-source threats. The timing of the raise reflects a broader shift happening across enterprise security. Software supply chain attacks have moved from a niche developer concern to a boardroom issue as organizations increasingly rely on open-source dependencies and AI-generated code. A recent OWASP Top 10:2025 community survey ranked software supply chain failures as the top concern among respondents. A separate 2025 Linux Foundation report found that only 36% of organizations evaluate the direct dependencies of open source software before introducing new components into production environments. Recent attacks have exposed how vulnerable the ecosystem has become. The compromise of Axios, one of the most widely used JavaScript packages, showed how quickly malicious code can spread once a dependency is poisoned. Socket said it identified the malicious dependency within six minutes and helped organizations block it before it entered production systems. The company added that more than 2,000 organizations onboarded to its platform within 24 hours of the incident. Socket's platform focuses on analyzing the behavior of open-source dependencies before they enter a company's codebase. Instead of relying entirely on public vulnerability databases that often surface threats only after disclosure, the company says its system detects suspicious behavior patterns in real time, including previously unseen attack techniques. The platform combines AI-assisted analysis with human review to flag malicious packages, prioritize exploitable vulnerabilities, and reduce dependency risk. "AI is changing how software gets built at every level," said Feross Aboukhadijeh, founder and CEO of Socket. "Teams are moving faster, more code is being generated, and more of what ends up in production now comes from outside the company. The hard part is keeping that speed without losing visibility into what's actually getting shipped, and that's where Socket comes in." Investors see the shift as part of a larger change in cybersecurity. Traditional vulnerability scanners were built for an era when threats moved slower, and security teams had more time to react after weaknesses became public. "Security is changing radically and rapidly," said Philip Clark, Partner at Thrive Capital. "Legacy tools were designed to react to known vulnerabilities and assumed there was sufficient time to prevent a breach. Today, AI models can identify vulnerabilities so well and so quickly that this is no longer an option. We need tools like Socket that can identify threats in third-party code before they enter production, and we believe there is no team better positioned to meet that demand." The funding comes as enterprises race to secure software pipelines increasingly shaped by AI-generated code, autonomous coding agents, and open-source libraries maintained outside corporate walls. Investors appear convinced that securing the software supply chain may become one of the defining cybersecurity battles of the AI era.

Bloomberg
May 20th, 2026
Security Firm Thwarting Nation-State Hackers Valued at $1 Billion

Socket, a cybersecurity startup that sells technology to help safeguard open-source code against hackers, has raised a new round of funding that values the company at $1 billion.

BankInfoSecurity
Apr 30th, 2026
Socket buys Secure Annex to expand supply-chain visibility.

Socket buys Secure Annex to expand supply-chain visibility. Combined Platform Spans Dependencies, Extensions, Developer Tools Michael Novinson (MichaelNovinson) - April 30, 2026 Socket purchased an extension security startup led by a longtime Tines manager to give organizations visibility and control across the entire development life cycle. The proposed deal will bring together San Francisco-based Socket's focus on application dependencies such as open-source libraries with Kansas City-area Secure Annex's concentration on browser and IDE extensions, said Socket founder and CEO Feross Aboukhadijeh. He said modern development workflows involve a continuous chain that includes code editors, artificial intelligence assistants, third-party packages and extensions. "When we started, we were very focused on application dependencies, your JavaScript, your Python, your Java and Secure Annex started from the extension perspective," Aboukhadijeh told ISMG. "John and his company were focused from the beginning on extensions, and I think bringing the two together gives us really good coverage across all the ecosystems that matter." Secure Annex, founded in November 2024 and counts Tuckner as its sole employee. He spent more than four years at Tines, where Tuckner created a team focused on security automation research. Tuckner led customer success engineering at Cyderes, was a principal solutions engineer at Optiv, an information security architect at Apria Healthcare and a security infrastructure engineer at H&R Block (see: Socket Acquires Startup Coana to Boost Code Risk Precision). How AI has changed supply-chain defense. Software supply-chain attacks are no longer confined to traditional package repositories such as npm, and are instead targeting a wide range of distribution channels, including Docker images, browser extensions and developer tools. This diversification of attack vectors significantly expands the risk landscape, and Socket aims to address this by extending coverage across multiple ecosystems, he said. "There's just so much more to this as AI is evolving," Tuckner said. "There's code extensions, there's AI skills, there's MCP servers that have just hit the scene over the past year. This problem was much bigger, but these teams are still all struggling with it. And in order for me to truly do what I set out to do, it might take a lot more funding or a lot more resources." AI enables automated analysis at a scale that was previously impossible, helping identify malicious packages and suspicious behavior more effectively, Aboukhadijeh said. AI is also changing who participates in software development, with citizen developers building and deploying code often without a deep understanding of security best practices, Tuckner said. "Traditionally, developers have almost unfettered access into the most sensitive information in companies," Tuckner said. "And now, given AI is here, it's turned everybody into a citizen developer and they're now also getting access into these very sensitive credentials." For some time, development workflows were moving entirely to the cloud, but the rise of AI-powered tools running locally has reversed that trend, with developers relying heavily on applications installed on their laptops, including code editors, extensions and AI assistants. Secure Annex plays a key role here by focusing on controlling what gets installed and executed at the endpoint level, Tuckner said. "There was a browser extension that was compromising crypto wallets that started with an npm attack," Tuckner said. "As I'm responding to a browser extension compromise, I'm finding that I need information about the npm space, which for us is paramount. Being able to tie that all together now in one platform will really help a lot of teams." Why Browsers and IDE extensions pose a security risk. Browsers and IDE extensions often appear benign and are trusted by default, yet they can have deep access to sensitive data and workflows. Marketplaces for extensions have historically been slow to detect and respond to malicious activity. The combined platform aims to address this by introducing pre-installation controls, helping organizations block or vet extensions before they're deployed. "I started Secure Annex about a year and a half ago on a very niche problem of browser extensions, and so I was very targeted," Tuckner said. "I see this as a problem in security that the larger players aren't addressing, and I think I can go out and solve this problem." MCP servers blur the line between developer tools and consumer applications, with both technical and non-technical users contributing to the software supply chain, Tuckner said. This convergence increases complexity and introduces new types of risk, including attacks that leverage natural language interactions with AI systems, Tuckner said. "MCP really is symbolic of this merging of both the developer and the consumer, and now that everybody is just contributing to the supply-chain software problem and the ecosystem," Tuckner said. "And so a lot of MCP servers are hosted on npm, but they might be used and supported by an IT team." Application security teams historically focused on code while IT security teams managed endpoints and infrastructure, but Aboukhadijeh said these distinctions are becoming less meaningful. Developer workflows now span both domains, making it difficult to assign clear ownership of security. As a result, clients are moving toward unified approaches that provide shared visibility and control across teams. "What buyers want increasingly is a common view of what third-party code and tools are being introduced, where they're running, what they're doing and whether they're safe to use," Aboukhadijeh said. "From our perspective, we just have to have the rightcapabilities, give people visibility, help them have controls and give them policies."

Associated Press
Feb 17th, 2026
Socket adds PHP support with Composer and Packagist integration for supply chain security

Socket has announced support for the PHP ecosystem, integrating Composer and Packagist into its software supply chain security platform. PHP developers can now search packages, generate Software Bills of Materials from Composer projects, and detect supply chain risks across dependencies. PHP powers roughly 75% of websites with a known server-side language. Packagist hosts over 440,000 packages with more than 169 billion installations since 2012, and Composer downloads exceed 2 billion packages monthly. Socket's AI-powered platform detects zero-day threats, typosquatting, backdoors and obfuscated code beyond traditional vulnerability scanning. Package search and browsing are available immediately, whilst SBOM generation and security scanning are in experimental release. Socket protects 14,000 organisations and 1.2 million repositories, securing over 2 million commits monthly and identifying 1,000 supply chain attacks weekly.

Vulert
May 27th, 2025
Critical Warning: Over 70 npm and VS Code Packages Found Stealing Sensitive Data and Cryptocurrency

Security firm Socket recently revealed a massive campaign involving over 70 malicious npm and VS Code packages stealing data and crypto.