Snyk is a Cloud & Application Security company founded in 2015 and based in Boston, United States. It has raised $1.3B in total funding, most recently a Series G in 2022 at a $7.4B valuation.
| Date | Stage | Amount | Valuation | Lead investors |
|---|---|---|---|---|
| Dec 13, 2022 | Series G | $196.5M | $7.4B | Qatar Investment Authority |
| Sep 9, 2021 | Series F | $530M | $8.5B |
| Sands Capital, Tiger Global Management |

An analysis piece on how open source software must evolve past its freewheeling origins toward security-hardened supply chain practices as enterprise adoption grows.

Researchers uncover NullReceiver technique hiding C2 IPs in Ethereum empty transfers via trojanized npm packages.

A credential-stealing npm worm spread from keyv@6.0.0 into 353-868 packages, planting Claude Code and VS Code hooks.

Snyk launches a Studio integration with Snowflake Cortex Code to scan AI-generated code, dependencies, and containers for vulnerabilities during development.

Snyk argues security teams must continuously test AI-generated code and govern agents to keep pace with attacker speed.

Researchers disclose CVE-2026-59726, a CVSS 10.0 unauthenticated RCE flaw in Ruflo MCP affecting Anthropic Claude Code and OpenAI Codex.
Snyk Code is an AI-powered SAST (static application security testing) engine that scans proprietary source code in real time to find security vulnerabilities as developers write. Powered by the DeepCode AI engine, it analyzes code patterns across many languages, provides fix suggestions, and integrates directly into the IDE, source control, and CI/CD pipelines so developers can catch and remediate issues without leaving their workflow.
Snyk Open Source is a software composition analysis (SCA) tool that automatically discovers and fixes vulnerabilities in open-source dependencies. It continuously monitors dependency trees for known CVEs and license risks, opens automated fix pull requests, and prioritizes issues by exploitability. It supports major ecosystems including npm, Maven, pip, Go modules, and NuGet, helping teams manage the open-source supply chain that makes up most of a modern application.
Snyk Container scans container images for OS- and application-level vulnerabilities across the container lifecycle, integrating into Dockerfiles, registries, and CI/CD and recommending minimal base-image alternatives to shrink attack surface. Snyk IaC secures cloud infrastructure configurations, scanning Terraform, CloudFormation, Kubernetes, Helm, and ARM templates for misconfigurations in the IDE, CLI, and pipelines, and detecting drift in deployed cloud environments so issues are caught before they reach production.
We don't have a live feed for this company's ATS. Their careers page has every open role.
View all careers ↗