Socket (socket.dev) Logo

Socket (socket.dev)

Research Intern

Reposted 10 Days Ago
Remote
Hiring Remotely in United States
Internship
Remote
Hiring Remotely in United States
Internship
As a Research Intern, you will collaborate on software supply chain security, conducting research, designing algorithms, and developing detection prototypes.
The summary above was generated by AI

About Us

Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers — from Anthropic to xAI, and Figma to Vercel — love Socket (just check out their tweets to see for yourself!)


Founded by Feross Aboukhadijeh, a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $65M in funding from top angels, operators, and security leaders.

About the Role

You will collaborate with world-class software engineers to build the next generation of defenses against software supply chain attacks. This internship offers a unique opportunity to translate cutting-edge research ideas into real-world systems that safeguard millions of developers worldwide. You will contribute to the design and implementation of large-scale data collection and analysis pipelines, conduct in-depth investigations of malicious activity in open source ecosystems, and prototype novel techniques for detecting fraud and abuse on platforms such as GitHub.

As one of our research interns, you will not only push the boundaries of software supply chain security but also help shape the culture and direction of a fast-growing security company. This role is ideal for PhD students eager to bridge academia and industry and bring innovative research into production environments while gaining hands-on development experience in a high-impact, mission-driven setting.


What You'll Do

  • Conduct applied research on emerging threats in the software supply chain (e.g., typosquatting, dependency confusion, malicious maintainers) and translate findings into detection prototypes.

  • Design and evaluate novel algorithms for identifying malicious or inauthentic activity across ecosystems such as npm, PyPI, and GitHub.

  • Leverage data science and machine learning techniques to model suspicious publishing behaviors, coordinated activity, and fraud campaigns.

  • Develop automated research tools to collect, transform, and analyze large-scale datasets from third-party APIs (e.g., npm, GitHub, PyPI).

  • Prototype and validate detection systems that can be integrated into Socket’s threat intelligence platform, bridging research insights with production impact.

  • Collaborate with engineers and designers to experiment with new ways of surfacing research findings in user-facing interfaces and developer workflows.

  • Publish research outputs internally (dashboards, reports, proofs-of-concept) to influence product strategy and share with the broader community when appropriate.

  • Contribute to the early team culture, bringing a research-driven perspective to technical discussions, prioritization, and the company’s long-term vision.


What You'll Bring

  • You are enrolled in a postgraduate or PhD program in computer science (or related field) and eager to apply your research expertise to real-world problems in software supply chain security.

  • Strong background in one or more of the following: program analysis, data mining, applied machine learning, large-scale systems, or security research.

  • Proficiency with languages commonly used for prototyping and research (e.g., JavaScript/TypeScript, Python, or similar).

  • Familiarity with software and systems security concepts, such as threat modeling, malware analysis, or adversarial behavior in open ecosystems.

  • Experience conducting research involving data analysis, statistical methods, or experimental evaluation.

  • Strong analytical and creative problem-solving skills; able to explore novel approaches and rigorously evaluate their effectiveness.

  • Self-motivated and comfortable driving independent research while collaborating with an interdisciplinary team.

  • Strong written and verbal communication skills for presenting research findings and collaborating across engineering and design.

  • Bonus points for prior work in one or more of the following:

    • Static/dynamic analysis of software or binaries

    • Open source security research or published academic work

    • Experience with Socket-supported ecosystems

    • Building scalable data pipelines or visualization dashboards

Our Interview Process:

  1. Informational with the Hiring Manager

  2. Take-home problem

    1. Internal review of your take-home

    2. Live review with you & one of our engineers

  3. Virtual f2f with a few members of the team

  4. Debrief

  5. Final Interview with Feross, Founder & CEO

  6. References

  7. Decision/Offer

We know how important clarity is when looking for a new role, so we've put together a read-me about the Interview Process at Socket.

Benefits: Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work. We offer:

  • Market competitive salary bands

  • Meaningful equity program

  • Comprehensive health benefits for you and your family

  • Flexible time-off, holidays, and winter shutdown to rest & recharge

  • Paid parental leave

  • Remote-first, with quarterly team off-sites

At Socket, we

  1. Pursue Excellence: We set ourselves apart by consistently delivering work of exceptional quality and distinction.

  2. Move with urgency and focus: We prioritize swift, decisive action.

  3. Think rigorously: We care about being right and it often takes reasoning from first principles to get there. We value alternative perspectives and have constructive discussions.

  4. Trust and amplify: We overtrust, always assume good intent, and give specific feedback to help each other improve.

  5. Feel a strong sense of ownership: We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.

  6. Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.

Top Skills

JavaScript
Python
Typescript
HQ

Socket (socket.dev) San Francisco, California, USA Office

San Francisco, CA, United States

Similar Jobs

2 Days Ago
Easy Apply
In-Office or Remote
Easy Apply
25-25 Annually
Internship
25-25 Annually
Internship
Edtech • Healthtech
The intern will assist with literature reviews, support research dissemination, develop project deliverables, and collaborate with team members.
Top Skills: Microsoft Office Suite
2 Days Ago
Easy Apply
In-Office or Remote
Easy Apply
22-22 Annually
Internship
22-22 Annually
Internship
Edtech • Healthtech
Assist in research projects related to state education finance, data collection and analysis, and report development.
Top Skills: Microsoft Office SuiteRSpssStata
3 Days Ago
In-Office or Remote
30-35 Hourly
Internship
30-35 Hourly
Internship
Information Technology • Logistics • Financial Services
As a UX Research & Data Insights Intern at Pitney Bowes, you will conduct user research, utilize qualitative and quantitative methods, and synthesize findings into actionable insights for product development.
Top Skills: Data AnalysisUx Research

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account