Join our mission to secure the universe of code.

Our story

Aaron and Louis were working together on a government contract for an organization that used lots of open source software. They looked for a solution that could identify malware lurking in open source dependencies. They found inadequate legacy products that merely focused on vulnerabilities. To address this major gap, they teamed up with Pete to build Phylum and define the future of software supply chain security.

Our culture

Our rapidly growing team is connected by a commitment to integrity and transparency. We value working with good people and creating solutions that solve massively complex problems. Our entire team is 100% remote which allows us to work with the very best talent across the country. We balance our mission-driven goals with fun, flexibility, and a work environment that encourages creativity and innovation.

We want you to be your best self, which is why we provide

Competitive Salary

Meaningful Stock Options

Fully Paid Health Benefits

Generous, Flexible PTO

Work From Anywhere (100% remote team)

401k with 3% guaranteed company contribution

Open positions

Join our all-remote team!

Security Researcher

Remote Full-time

Phylum is defining the future of software supply chain security. Our technology applies machine leaning, deep analytics, and static code analysis to defend systems from far more than known software vulnerabilities. We’re on a mission to help companies defend their systems and stay ahead of today’s cybersecurity threats and emerging attack vectors.  

As a venture-backed start-up, we’re off to the races. Now is an exciting time to join our 100% remote team and have a huge impact.   

We’re looking for a Security Researcher to join our team!  

What You’ll Be Doing 

  • Research emerging threats and new ways to identify malicious indicators and vulnerable code in open-source software 
  • Utilize data-driven methods including statistical analysis and other advanced techniques  
  • Adapt research results into new heuristics and analytics for our flagship product 
  • Refine the product tooling to fine-tune performance and impact 
  • Write about your product insights and findings 

About You 

  • Highly skilled at malware analysis, vulnerability research, and identifying security threats 
  • Experience with reverse engineering and static code analysis 
  • Advanced programming skills in Python 
  • Must have 3+ years of relevant industry experience 
  • Experience with machine learning and data science 
  • Past work experience in an early-stage, fast-growing start-up is a plus 
  • Familiarity with Spark and Scala is a plus 

The Tech Stack   

Our engineering team embraces modern software engineering practices. All of our code runs in a continuous integration environment with good testing. We primarily deploy on Linux environments and lean heavily on Docker. Much of our code is written in Python, Rust, and Scala.   

Phylum’s ingestion platform is built around Kafka. We store our datasets with Hadoop, leveraging Hive, HBase, and Elasticsearch, and we lean on Spark for analytics. All of our infrastructure sits on Kubernetes.   

Phylum’s front-end stack uses modern Javascript, React, Redux, d3.js, and all the usual front-end tooling like webpack and babel.   

We interact with projects that make extensive use of Scala, C, and C++. 


  • Competitive salary commensurate with experience ($120,000 - $150,000) 
  • Meaningful stock options 
  • Exceptional medical, dental, and vision (with premiums paid 100% by Phylum) 
  • 401k with 3% company contribution whether you participate or not 
  • Unlimited paid time off 
  • Work from anywhere in the U.S. 

Phylum is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or other characteristic protected by applicable law. 

Interested? Please send cover letter and CV to