Vulnerability Research Software Engineer
Core
Build and scale patching infrastructure to deliver secure, vetted packages to developers worldwide, focusing on supply chain security and creating patches for critical vulnerabilities.
Role type
Senior IC software engineer (supply chain security & patching)
Builds
Automated patching infrastructure, CLI tooling, APIs, and integrations for certified packages
Domain
Software supply chain security, open source ecosystem, package management
Deliverable
production ML models | product features | infrastructure
Required skills
Rust, Unix/Linux environments, Node.js, JavaScript, TypeScript, package managers (npm/yarn/pnpm), API development, data processing pipelines, automated testing, CI/CD
Preferred skills
Security tooling, vulnerability scanning, patch management, software supply chain security, Python/Go ecosystems, open source contributions, DevSecOps, high-throughput data processing
Technologies
Rust, Node.js, JavaScript, TypeScript, npm, yarn, pnpm, React, CI/CD
Responsibilities
Build and maintain CLI tooling for customer environments; Implement package-manager integrations and handle ecosystem-specific edge cases; Translate dependency and vulnerability workflows into developer-facing interfaces; Debug implementation issues across Unix-based environments; Scale patch production to dozens or hundreds of patches per week; Build APIs and integrations to deliver certified packages; Create tooling for patch quality assurance and testing; Work with security researchers to understand and patch critical vulnerabilities
Seniority
Senior, hands-on IC