This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Socket is looking for a Threat Analyst to join our growing Threat Research Team. In this role, you’ll tackle cutting-edge threats in the software supply chain, leveraging our proprietary AI-based scanner and building tools to enhance malware analysis. You’ll secure open source ecosystems, strengthen threat detection across multiple programming languages, and conduct research that helps protect developers and organizations worldwide. This is not an entry-level position. This is a hands-on role for someone passionate about threat hunting, security research, automation, and turning insights into actionable defenses.
Job Responsibility:
Analyze numerous unique threats daily, maintaining a standard of quality that sets the industry benchmark for supply chain security
Author high-impact technical blog posts on malicious open source code packages and extensions, and publish deep-dive research pieces on malicious campaigns, threat actor profiles, novel attack vectors, and ecosystem-wide trends
Design and build automated scripts and tools to streamline malware analysis, enhancing our data collection, threat analysis, and threat hunting workflows
Partner with our engineering team to integrate your research into our core product, turning manual insights into scalable, real-time protection
Leverage expertise in open source software ecosystems to enhance security across package registries, browser extensions (Chrome/VS Code), and proactively monitor GitHub/GitLab for emerging malicious campaigns
Track APT (Advanced Persistent Threat) adversaries, characterizing various TTPs (Tactics, Techniques, and Procedures), capabilities, infrastructure, and campaigns
Requirements:
3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience)
Technical experience across several areas of security operations, including investigations, incident response and management, digital forensics, malware analysis, reverse engineering, threat intelligence, threat hunting, and detection engineering
Excellent communication skills and the ability to assess the relevance and impact of threats
Experience building tools for automation, data collection, and threat hunting
Passion for open source and code
Nice to have:
Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket
Experience leveraging LLMs or AI-based tools for threat detection
What we offer:
Equity
Health insurance
Vacation time
Holidays
Paid parental leave
Market competitive salary bands
Meaningful equity program
Comprehensive health benefits for you and your family
Flexible time-off, holidays, and winter shutdown to rest & recharge