Security Engineer - Node.js Proactive Defense (worldwide remote, work anywhere)

CloudLinux Inc.

Warszawa

Hybrid

PLN 240,000 - 420,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Fully remote with flexible hours
Paid vacation and holidays
Private medical insurance
Education budget

Job summary

CloudLinux is building a brand-new runtime-protection product for Node.js in a fully remote setting. You will own the product scope, technical approach, and end-to-end delivery, coordinating with architects and engineers to ship to real customer fleets.

The role requires strong web security expertise, experience with end-to-end ownership, and the ability to guide AI-assisted coding to high-quality results. Flexible hours, international remote work, and a competitive package are offered.

Qualifications

  • Proven experience building and shipping a new product, security solution, major feature, or technical system from scratch.
  • End-to-end technical ownership from investigation and architecture through implementation, release, and production iteration.
  • Strong web application security knowledge and practical exploitation awareness.
  • Knowledge of how detection rules behave at scale and how to balance false positives.
  • Ability to start as PM, architect, lead engineer, and QA for this product.
  • Comfort directing AI coding agents to high-quality output.

Responsibilities

  • Define the brand-new product line and customer-facing surface.
  • Shape the technical approach, deployment shape, and programming language choices.
  • Lead end-to-end implementation with available tooling and resources.
  • Develop detection logic and validity measures for runtime protection.
  • Collaborate with architects while owning delivery and outcomes.

Skills

Product ownership
Security knowledge
Web app security
Node.js familiarity
AI coding guidance

Job description

CloudLinux is a global remote-first company. We are driven by our principles: do the right thing, employees first, we are remote first, and we deliver high-volume, low-cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we all are successful.

Check out our website for more information https://cloudlinux.com/

Imunify360 Security Suite is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy-to-use solution with the six-layer approach to security delivers comprehensive and complete attack prevention.

The mission

We protect web hosting providers and the sites running on their infrastructure through a defense-in-depth stack: web-server-layer WAF, runtime application self-protection for PHP, deep application integrations (WordPress plugins and similar), a malware scanner with cleanup capability, and network-layer firewalls and IP reputation. The pieces talk to each other, and the threat intelligence they generate at scale powers detection across the stack.

Node.js is the segment of the hosting market growing fastest, and the next layer we want to build for it is runtime protection inside the Node.js process itself. Most Node.js workloads on managed hosting today are AI-generated web apps deployed by non-technical owners who can't, won't, and shouldn't be expected to patch their own code or audit their own dependencies. We're going to defend those apps anyway — at runtime, without their cooperation, without breaking them.

You’ll build that runtime protection layer end-to-end.

What you’ll own
  • The product. A brand-new product line, yours to define — what we intercept, what we don't, what the customer-visible surface looks like.
  • The technical approach. Instrumentation strategy, deployment shape, programming language — all open. You’ll consult with our architects but the direction is yours.
  • Implementation, end to end. You’ll have the full tooling stack we provide — LLM subscriptions, modern dev infrastructure, the works. Use what makes you fast.
  • Methodology. How you build conviction in your detection logic — your call.
  • Cross-layer signal. Our existing stack produces threat intelligence at unmatched scale: tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps.
How we’ll measure success

The product is held to four numbers: runtime overhead, false positives, false negatives, and customer-escalation volume. They reflect what hosting providers and their customers care about. Hit them well and the product runs inside a meaningful slice of the modern Node.js web.

What we’re looking for

An experienced researcher or engineer who can build and iterate on a brand-new product, driving both the research and the development. The hard part of this work is knowing what's malicious, what's vulnerable, and what's just an unusual but legitimate pattern — and being right about it across the long tail of frameworks, libraries, and customer code we'll encounter in production.

Must have:

  • Proven experience building and shipping a new product, security solution, major feature, or technical system from scratch.
  • Strong evidence of end-to-end technical ownership, from initial investigation and architecture through implementation, release, and production iteration.
  • Strong web application security knowledge and current knowledge of practical exploitation.
  • A working sense of how detection rules behave at scale — what catches attackers without flagging the long tail of legitimate code.
  • Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do.
  • Comfort directing AI coding agents to high-quality output.

Nice to have:

  • Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
  • Background in malware analysis or incident response.
  • Familiarity with managed-hosting environments.
  • Public security research, vulnerability disclosures, or detection rulesets you've authored.
  • Familiarity with the Node.js runtime and the JavaScript ecosystem.
What it's not
  • Not a scope-and-handoff role — you drive the work and own the outcome.
  • Not a "platform team will productize this later" role — you ship to real customer fleets and watch the telemetry quickly.
  • Not a spec-and-review role — you are hands-on every day.
Why this matters
  • Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice — “secure your code, audit your dependencies” — does not apply to them.
  • If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops.

What's in it for you?

  • A focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • The opportunity to receive a reward for the most innovative idea that the company can patent.

By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy https://cloudlinux.com/candidate-privacy-notice, which provides detailed information on how we maintain and handle your data.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Node.js Proactive Security Engineer
Remote Node.js Proactive Security Engineer

CloudLinux • Warszawa

On-site
PLN 180,000 - 280,000
Fully remote work with flexible hours
Paid vacation and holidays
Education budget
+1
Remote Node.js Security Engineer — Runtime Protection
Remote Node.js Security Engineer — Runtime Protection

CloudLinux Inc. • Warszawa

Hybrid
PLN 240,000 - 420,000
Fully remote with flexible hours
Paid vacation and holidays
Private medical insurance
+1
DevOps Engineer (worldwide remote, work anywhere)
DevOps Engineer (worldwide remote, work anywhere)

CloudLinux Inc. • Warszawa

Hybrid
PLN 446,000 - 669,000
Fully remote work
Flexible working hours
Paid vacation
+5
Application Security Engineer
Application Security Engineer

LionHires Recruitment • Poland

On-site
PLN 180,000 - 240,000
Senior Database Reliability Engineer (DBRE) & Architect (worldwide remote)
Senior Database Reliability Engineer (DBRE) & Architect (worldwide remote)

CloudLinux Inc. • Województwo mazowieckie

Remote
PLN 60,000 - 90,000
24 days paid vacation
Private medical insurance compensation
Co-working and gym reimbursement
+1
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000
Engineering Manager | NordLayer
Engineering Manager | NordLayer

Nord Security • Warszawa

On-site
USD 120,000 - 160,000
Premium healthcare
Work from anywhere
Mentorship programs
+2
Security Engineer
Security Engineer

Flox • Poland

Hybrid
PLN 167,400 - 223,200
Flexible hybrid environment
Meaningful equity
Director of Engineering
Director of Engineering

Internetwork Expert • Warszawa

Hybrid
PLN 682,000 - 1,062,000
Fully remote position
Global team
Flexible working hours
Application Security Engineer | Senior
Application Security Engineer | Senior

Nord Security • Poland

On-site
Private health insurance
Flexible work arrangements
Physical well-being programs
+3