
Vulnerability Research Software Engineer
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States, +1 more country.
β’ Master the workflows, tools, and patching processes of Socket.
β’ Develop and sustain CLI tools utilized in customer environments.
β’ Implement integrations for package managers and manage edge cases specific to different ecosystems.
β’ Convert dependency and vulnerability workflows into dependable interfaces for developers.
β’ Troubleshoot implementation issues across Unix-based systems.
β’ Collaborate closely with the patch team to define tasks, resolve issues, and deliver practical enhancements.
β’ Contribute to frontend development using JavaScript, React, and TypeScript.
β’ Scale patch production to produce dozens or even hundreds of patches weekly.
β’ Develop and enhance automated patching infrastructure and tools.
β’ Create APIs and integrations to provide certified packages.
β’ Design tools for patch quality assurance and testing.
β’ Partner with security researchers to identify and address critical vulnerabilities.
β’ Provide developers with quick and safe remediation options for commonly used packages.
β’ Assist in securing the software supply chain for millions of developers.
β’ A minimum of 3 years of experience in software engineering focused on production systems.
β’ Strong expertise in Rust and Unix/Linux environments.
β’ Proficiency in Node.js, JavaScript, and TypeScript.
β’ Experience with package managers such as npm, yarn, and pnpm, along with the JavaScript ecosystem.
β’ A solid understanding of software security principles and vulnerability management.
β’ Experience in building and scaling APIs and data processing pipelines.
β’ Familiarity with automated testing, CI/CD, and deployment systems.
β’ Experience with security tools, vulnerability scanning, or patch management is preferred.
β’ Knowledge of challenges related to software supply chain security is preferred.
β’ Experience with other package ecosystems like Python or Go is preferred.
β’ Contributions to open source or experience in package maintenance is preferred.
β’ A background in DevSecOps or security engineering is preferred.
β’ Experience with high-throughput data processing systems is preferred.
β’ Meaningful equity program.
β’ Comprehensive health benefits for you and your family, covering 99% of costs.
β’ Flexible time-off policies, holidays, and winter shutdowns.
β’ Paid parental leave.
β’ Remote-first work culture.
β’ Quarterly team off-site events.
Shield AI
Netflix
Travoom
HeroSoftware GmbH - Shopify Apps
Get handpicked remote jobs straight to your inbox weekly.