Socket (socket.dev) Logo

Socket (socket.dev)

Threat Analyst

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Junior
Remote
Hiring Remotely in United States
Junior
As a Threat Analyst at Socket, you'll analyze threats, automate workflows, author research, and collaborate with engineering for security enhancements.
The summary above was generated by AI
Who we are

Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers — from Anthropic to xAI, and Figma to Vercel — love Socket (just check out their tweets to see for yourself!)


Founded by Feross Aboukhadijeh, a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $65M in funding from top angels, operators, and security leaders.

About the Role

Socket is looking for a Threat Analyst to join our growing Threat Research Team. In this role, you’ll tackle cutting-edge threats in the software supply chain, leveraging our proprietary AI-based scanner and building tools to enhance malware analysis. You’ll secure open source ecosystems, strengthen threat detection across multiple programming languages, and conduct research that helps protect developers and organizations worldwide. This is not an entry-level position. This is a hands-on role for someone passionate about threat hunting, security research, automation, and turning insights into actionable defenses.

What You'll Do
  • Analyze numerous unique threats daily, maintaining a standard of quality that sets the industry benchmark for supply chain security.

  • Author high-impact technical blog posts on malicious open source code packages and extensions, and publish deep-dive research pieces on malicious campaigns, threat actor profiles, novel attack vectors, and ecosystem-wide trends.

  • Design and build automated scripts and tools to streamline malware analysis, enhancing our data collection, threat analysis, and threat hunting workflows.

  • Partner with our engineering team to integrate your research into our core product, turning manual insights into scalable, real-time protection.

  • Leverage expertise in open source software ecosystems to enhance security across package registries, browser extensions (Chrome/VS Code), and proactively monitor GitHub/GitLab for emerging malicious campaigns.

  • Track APT (Advanced Persistent Threat) adversaries, characterizing various TTPs (Tactics, Techniques, and Procedures), capabilities, infrastructure, and campaigns.

What You'll Bring

Required:

  • 3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience).

  • Technical experience across several areas of security operations, including investigations, incident response and management, digital forensics, malware analysis, reverse engineering, threat intelligence, threat hunting, and detection engineering.

  • Excellent communication skills and the ability to assess the relevance and impact of threats.

  • Experience building tools for automation, data collection, and threat hunting.

  • Passion for open source and code.

Preferred:

  • Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket.

  • Experience leveraging LLMs or AI-based tools for threat detection.

As we know how important clarity is when looking for a new role, we've put together a read-me about the Interview Process at Socket, should you be invited for an interview.

At Socket, we
  1. Pursue Excellence: We set ourselves apart by consistently delivering work of exceptional quality and distinction.

  2. Move with urgency and focus: We prioritize swift, decisive action.

  3. Think rigorously: We care about being right and it often takes reasoning from first principles to get there. We value alternative perspectives and have constructive discussions.

  4. Trust and amplify: We overtrust, always assume good intent, and give specific feedback to help each other improve.

  5. Feel a strong sense of ownership: We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.

  6. Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.

Top Skills

AI
JavaScript
Typescript

Similar Jobs

10 Days Ago
Remote or Hybrid
11 Locations
100K-155K Annually
Senior level
100K-155K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The role involves executing threat hunting operations, delivering high-impact intelligence briefings, and building partnerships with customers to enhance security against advanced threats.
Top Skills: CloudElastic StackHumioLinuxmacOSMitre Att&CkSplunkWindows
13 Days Ago
Easy Apply
Remote
2 Locations
Easy Apply
114K-131K Annually
Senior level
114K-131K Annually
Senior level
Software
The Threat Detection and Response Analyst identifies, investigates, and mitigates advanced threats while collaborating with teams to enhance security measures and compliance.
Top Skills: AlienvaultAws GuarddutyAzure DefenderCrowdstrikeEdrElasticPowershellPythonSIEM
13 Days Ago
Easy Apply
Remote
2 Locations
Easy Apply
114K-127K Annually
Senior level
114K-127K Annually
Senior level
Information Technology
As a Threat Detection and Response Analyst, you will identify, investigate, and mitigate advanced threats, enhance detection capabilities, and collaborate with teams to ensure compliance with security policies.
Top Skills: AlienvaultAws GuarddutyAzure DefenderCrowdstrikeEdrElasticPowershellPythonSIEM

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account