- Workplace
- Remote
- Employment
- Full time
- Level
- Staff
- Posted
- 5 months ago
About this role
About Us
Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!)
Founded by Feross Aboukhadijeh, a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $125M in funding from top angels, operators, and security leaders.
About the Role
We’re hiring a Security Engineer to help define and scale our security program. This is an IC role with broad ownership across application security, infrastructure, corporate security, and detection engineering. You’ll work hands-on alongside the engineering team, writing code, building internal tooling, and driving meaningful security improvements as we grow.
Socket is a security company, and our internal security posture matters both for protecting the company and for the credibility of what we sell. This role is a rare combination: full ownership of a critical function, a company with real traction, and a deeply relevant problem space. As Socket grows, so will the security function, and you'll shape what that looks like.
What You'll Do
Improve Socket's security posture across the board. Own, cloud infrastructure hardening, operational security, and IT security. Write code and build tooling that makes the secure path the default path for engineers. Roll out identity and access controls, close gaps across the stack, and continuously reduce risk.
Assess, prioritize, and drive the security roadmap. Figure out what matters most, balance quick wins with longer-term improvements, and execute across many fronts in parallel. You won't wait to be told what to work on. You'll develop a clear picture of where Socket's risks are and make steady progress against them.
Run incident response and external security operations. Build and run a 24/7 security incident response process. Own the security inbox, triage inbound vulnerability reports, manage pentests, and coordinate fixes. When you can fix something directly, you do.
Maintain compliance and drive new certifications. Maintain our existing SOC 2 compliance. Drive new certifications (ISO 27001, etc.) as needed for enterprise customers.
Raise security awareness and culture across the org. Train engineers to write more secure code. Run phishing simulations. Build trust with engineering teams so that security feels like an enabler, not a blocker. Make people want to do the right thing rather than resenting security as a tax.
What You'll Bring
You've owned security broadly at a growth-stage company, or you're a strong software engineer who's moved into security and is ready to own the function end-to-end.
You can ship production TypeScript. When the engineering org is heads-down on product work, you unblock yourself by writing code, standing up tooling, and modifying infrastructure rather than filing tickets and waiting.
You have breadth across security domains (AppSec, CloudSec, OpSec) and you're comfortable learning fast where gaps exist.
You're fluent in cloud infrastructure (we use GCP): VPCs, IAM, secret management, networking.
You're a self-directed operator who figures out what matters most and executes across many fronts without waiting to be told what to do. You move fast, find leverage, and get a lot done with a little.
You have the communication and teaching skills to make an entire engineering org care about security, not by blocking people, but by earning trust and making the secure path the easy path.
We know how important clarity is when looking for a new role, so we've put together a read-me about the Interview Process at Socket.
Benefits: Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work. We offer:
Market competitive salary bands
Meaningful equity program
Comprehensive health benefits for you and your family (99% coverage)
Flexible time-off, holidays, and winter shutdown to rest & recharge
Paid parental leave
Remote-first, with quarterly team off-sites
At Socket, we
Pursue Excellence: We set ourselves apart by consistently delivering work of exceptional quality and distinction.
Move with urgency and focus: We prioritize swift, decisive action.
Think rigorously: We care about being right and it often takes reasoning from first principles to get there. We value alternative perspectives and have constructive discussions.
Trust and amplify: We overtrust, always assume good intent, and give specific feedback to help each other improve.
Feel a strong sense of ownership: We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.
Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.
As published by Socket.dev. Applications are handled on their site.
Skills this posting mentions
About Socket.dev
Socket is a cybersecurity platform that protects companies from software supply chain attacks. Companies use Socket to protect their software applications and critical services from malware and security threats originating in open source code.
All 24 openings at Socket.devOne click, then it is written
Apply to Socket.dev with a resume written for this role.
Queue Staff Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Socket.dev’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Socket.dev
See all- 6 weeks ago
- 7 weeks ago
- 8 weeks ago
- 2 months ago
- 2 months ago
- 3 months ago
Similar roles elsewhere
See more- Today
Senior Security Engineer, Incident Response Team (Australia)
GitLabRemote, AustraliaRemote
SeniorEngineering - Today
Intermediate Security Engineer, Security Incident Response Team (SIRT)
GitLabRemote, AustraliaRemote
Engineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Socket.dev publishes. Refolk is not the employer and does not handle their hiring. Applications go to Socket.dev directly.