Threat Analyst
Analyzes software supply chain threats using AI scanners, conducts malware analysis and threat hunting, builds automation tools, and integrates research into products to protect open source ecosystems. Requires 3+ years in security operations and master's degree.
About the job
What You'll Do
- Analyze numerous unique threats daily, maintaining a standard of quality that sets the industry benchmark for supply chain security.
- Author high-impact technical blog posts on malicious open source code packages and extensions, and publish deep-dive research pieces on malicious campaigns, threat actor profiles, novel attack vectors, and ecosystem-wide trends.
- Design and build automated scripts and tools to streamline malware analysis, enhancing our data collection, threat analysis, and threat hunting workflows.
- Partner with our engineering team to integrate your research into our core product, turning manual insights into scalable, real-time protection.
- Leverage expertise in open source software ecosystems to enhance security across package registries, browser extensions (Chrome/VS Code), and proactively monitor GitHub/GitLab for emerging malicious campaigns.
- Track APT (Advanced Persistent Threat) adversaries, characterizing various TTPs (Tactics, Techniques, and Procedures), capabilities, infrastructure, and campaigns.
What You'll Bring
Required:
- 3+ years of work experience and a master’s degree in computer science, engineering, or a related field (or equivalent experience).
- Technical experience across several areas of security operations, including investigations, incident response and management, digital forensics, malware analysis, reverse engineering, threat intelligence, threat hunting, and detection engineering.
- Excellent communication skills and the ability to assess the relevance and impact of threats.
- Experience building tools for automation, data collection, and threat hunting.
- Passion for open source and code.
Preferred:
- Familiarity with TypeScript/JavaScript and/or other programming languages and ecosystems protected by Socket.
- Experience leveraging LLMs or AI-based tools for threat detection.
Benefits
- Market competitive salary bands
- Meaningful equity program
- Comprehensive health benefits for you and your family
- Flexible time-off, holidays, and winter shutdown to rest & recharge
- Paid parental leave
- Remote-first, with quarterly team off-sites
Skills
Malware Analysis, Reverse Engineering, Threat Intelligence, Threat Hunting, Digital Forensics, Incident Response, Detection Engineering, TypeScript, JavaScript, LLMs, Ai-Based Tools, Automation Scripting, GitHub, GitLab
Similar jobs
Security Engineering jobsInvestigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
Develops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.
Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.