Мэтч & Сопровод
Покажет вашу совместимость и напишет письмо
Описание вакансии
TL;DR
Engineering Manager (Cybersecurity): Leading the Language Security Research function to deliver security patches for end-of-life and non-EOL open-source language runtimes and frameworks with an accent on engineering leadership, CVE analysis, and cross-functional delivery. Focus on managing multiple specialized teams, automating vulnerability discovery via AI, and ensuring SLA compliance for high-stakes security releases.
Location: Remote (Worldwide). Must have already relocated from Russia and Belarus.
Company
TuxCare provides security solutions for Linux and open-source software, focusing on automated live vulnerability patching for enterprise organizations.
What you will do
- Lead and develop four engineering teams (~18 engineers) specializing in Java, JavaScript, Go, Python, and PHP.
- Define and enforce technical standards for CVE analysis, vulnerability assessment, and patch backporting processes.
- Drive consistency in CI/CD pipelines, tooling, and security release workflows across all language ecosystems.
- Evaluate and implement AI-assisted automation for vulnerability discovery and backporting.
- Own SLA compliance and coordinate delivery between language teams and OS, Docker, and platform teams.
- Manage hiring plans, performance reviews, and career development for all reports.
Requirements
- 6+ years of hands-on software development experience across multiple language ecosystems.
- 3+ years of engineering leadership experience (Team Lead or EM) in a product company.
- Strong proficiency in Java is required; knowledge of JS, Go, Python, or PHP is a plus.
- Hands-on experience with CVE triage, patch backporting, or vulnerability analysis.
- Experience with CI/CD systems (GitLab CI, Jenkins) and dependency management tools (Maven, npm, pip, Go modules).
- English: Upper-intermediate (B2) or higher required.
- Location: Must be based outside of Russia and Belarus.
Nice to have
- Understanding of the security vulnerability lifecycle (CVE, CVSS, CWE, CSAF/VEX).
- Background in open-source security, supply chain security, or ELS-type products.
- Experience integrating AI tooling into research or patching workflows.
- Knowledge of Docker, Kubernetes, or cloud-native ecosystems.
Culture & Benefits
- Fully remote work with flexible hours, allowing you to work from any location worldwide.
- 24 days of paid vacation per year, 10 national holidays, and unlimited sick leave.
- Compensation for private medical insurance.
- Reimbursement for co-working and gym/sports memberships.
- Focus on professional development with mentorship and knowledge-exchange programs.
- Rewards for innovative ideas that the company can patent.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →