Security Engineer - Node.js Proactive Defense (remote work)
Quick Summary
tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps.
Proven experience building and shipping a new product, security solution, major feature, or technical system from scratch. Strong evidence of end-to-end technical ownership,
Responsibilities
~1 min readRequirements
~1 min read- Proven experience building and shipping a new product, security solution, major feature, or technical system from scratch.
- Strong evidence of end-to-end technical ownership, from initial investigation and architecture through implementation, release, and production iteration.
- Strong web application security knowledge and current knowledge of practical exploitation.
- A working sense of how detection rules behave at scale — what catches attackers without flagging the long tail of legitimate code.
- Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do.
- Comfort directing AI coding agents to high-quality output.
Nice to Have
~1 min read- Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
- Background in malware analysis or incident response.
- Familiarity with managed-hosting environments.
- Public security research, vulnerability disclosures, or detection rulesets you've authored.
- Familiarity with the Node.js runtime and the JavaScript ecosystem.
- Not a scope-and-handoff role — you drive the work and own the outcome.
- Not a "platform team will productize this later" role — you ship to real customer fleets and watch the telemetry quickly.
- Not a spec-and-review role — you are hands-on every day.
- Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice — "secure your code, audit your dependencies" — does not apply to them.
- If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops.
What We Offer
~1 min read- A focus on professional development.
- Interesting and challenging projects.
- Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
- Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
- Compensation for private medical insurance.
- Co-working and gym/sports reimbursement.
- Budget for education.
- The opportunity to receive a reward for the most innovative idea that the company can patent.
By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (https://cloudlinux.com/candidate-privacy-notice), which provides detailed information on how we maintain and handle your data.
Location & Eligibility
Listing Details
- Posted
- August 10, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 25%
- Scored at
- September 29, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.