обновлено 4 дня назад
Security Researcher Engineer (Node.js)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Researcher Engineer (Node.js): Building a runtime protection layer inside the Node.js process for managed hosting environments with an accent on web application security, detection logic, and runtime instrumentation. Focus on designing and implementing a new product that intercepts exploits at runtime without breaking applications, leveraging large-scale threat intelligence.
Location: Fully remote; work from any location worldwide. Listed locations include Sofia, Madrid, Bucharest, Lisbon, Prague, and Brasília.
Company
is a remote-first company developing Linux infrastructure and security products for hosting providers, including the Imunify360 security suite.
What you will do
- Define and build a new runtime protection product for Node.js applications from the ground up.
- Own the product scope, interception model, customer-facing functionality, instrumentation strategy, deployment shape, and programming language.
- Lead research and end-to-end implementation, from initial investigation and architecture through release and production iteration.
- Use threat intelligence from monitored sites, malware samples, domain and URL reputation, and IP attack feeds to improve detection.
- Direct AI coding agents and use modern development infrastructure to accelerate delivery.
- Optimize runtime overhead, false positives, false negatives, and customer-escalation volume.
Requirements
- Experience building and shipping a new product, security solution, major feature, or technical system from scratch.
- End-to-end technical ownership covering investigation, architecture, implementation, release, and production iteration.
- Strong web application security knowledge and current practical exploitation expertise.
- Understanding of detection rules at scale and the ability to distinguish malicious behavior from unusual legitimate code.
- Ability to operate as product manager, architect, lead engineer, and QA for the product.
- Comfort directing AI coding agents toward high-quality output.
Nice to have
- Experience with runtime protection products, application firewalls, or instrumentation tooling.
- Malware analysis or incident response background.
- Familiarity with managed-hosting environments, Node.js, or the JavaScript ecosystem.
- Public security research, vulnerability disclosures, or authored detection rulesets.
Culture & Benefits
- Remote-first environment with flexible working hours and worldwide location flexibility.
- Professional development opportunities, education budget, and challenging technical projects.
- 24 paid vacation days, 10 national holidays, and unlimited sick leave.
- Private medical insurance, co-working reimbursement, and gym or sports reimbursement.
- Opportunity to receive a reward for an innovative idea that the company can patent.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →