WorkaemКарьерная платформа
  • Вакансии
  • Компании
  • Зарплаты
  • Офферы
  • Сервисы
  • Блог
  • Работодателям
Workaem

Карьерная платформа для IT-специалистов: вакансии напрямую с карьерных страниц 300+ компаний, из телеграм-каналов, с международных площадок и от работодателей напрямую. Разбор условий, детектор мёртвых вакансий, AI-инструменты для резюме. Базовые функции бесплатны.

Подпишись, присылаем лучшие вакансии недели
Или читай канал в телеграме
Соискателям
Все вакансииЗа границейУдалёнка в долларахКомпании с РУ основателямиЗарплатыОфферыВозможностиСоветыСоздать резюмеТренировка интервью
По технологиям
Вакансии PythonВакансии JavaScriptВакансии ReactВакансии JavaВакансии GoВакансии Docker
По профессиям
РазработкаДизайнQA / ТестированиеАналитикаProduct / Project ManagerМаркетинг
Работодателям
Разместить вакансиюТарифыБаза кандидатовСвязаться с нами
Кабинет
РегистрацияВойтиЛичный кабинетМои откликиСохранённыеУведомления
Компания
О проектеПредложенияКонтактыБлогКонфиденциальностьУсловия использования
© 2026 Workaem. Все права защищены.КонфиденциальностьУсловияОферта
Made by IT, for IT 💛
Security Engineer - Node.js Proactive Defense (worldwide remote, work anywhere)
ВердиктОписаниеИнструментыКомпания
  1. Главная
  2. /
  3. Вакансии
  4. /
  5. Security Engineer - Node.js Proactive Defense (worldwide remote, work anywhere)

CloudLinux·12 авг.

Security Engineer - Node.js Proactive Defense (worldwide remote, work anywhere)

9 583 – 16 292 $
на 232% выше медианы рынка
≈ 830,6 тыс.–1,4 млн ₽
🌍 УдалённоMiddleПолная занятость🌐 Глобал
9 583 – 16 292 $≈ 830,6 тыс.–1,4 млн ₽
Платят на 265% выше медианы грейда.
Нажмите на сигнал, чтобы увидеть, на чём он основан

Наши требования

An experienced researcher or engineer who can build and iterate on a brand-new product, driving both the research and the development. The hard part of this work is knowing what's malicious, what's vulnerable, and what's just an unusual but legitimate pattern — and being right about it across the long tail of frameworks, libraries, and customer code we'll encounter in production
Familiarity with the Node.js runtime and the JavaScript ecosystem
Strong web application security fundamentals and current knowledge of practical exploitation
A working sense of how detection rules behave at scale — what catches attackers without flagging the long tail of legitimate code
Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do
Comfort directing AI coding agents to high-quality output — most of our engineering does this now
Prior work on runtime-protection products, application firewalls, or instrumentation tooling
Background in malware analysis or incident response
Familiarity with managed-hosting environments
Public security research, vulnerability disclosures, or detection rulesets you've authored

Дополнительно

The product. A brand-new product line, yours to define — what we intercept, what we don't, what the customer-visible surface looks like
The technical approach. Instrumentation strategy, deployment shape, programming language — all open. You'll consult with our architects but the direction is yours
Implementation, end to end. You'll have the full tooling stack we provide — LLM subscriptions, modern dev infrastructure, the works. Use what makes you fast
Methodology. How you build conviction in your detection logic — your call
Cross-layer signal. Our existing stack produces threat intelligence at unmatched scale: tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps
How we'll measure success
The product is held to four numbers: runtime overhead, false positives, false negatives, and customer-escalation volume. They reflect what hosting providers and their customers care about. Hit them well and the product runs inside a meaningful slice of the modern Node.js web
Not a scope-and-handoff role — you drive the work and own the outcome
Not a "platform team will productize this later" role — you ship to real customer fleets and watch the telemetry quickly
Not a spec-and-review role — you are hands-on every day
Why this matters
Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice — "secure your code, audit your dependencies" — does not apply to them
If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops
C
CloudLinux

ГрейдMiddle
ЗанятостьПолная занятость
ФорматУдалённо
ИсточникСкрыто
Опубликовано12 авг.
Все вакансии компании

AI-помощник

под эту вакансию
Войди, чтобы AI оценил твоё соответствие вакансии и написал сопроводительное письмо
Мы против мошенников на площадке: если тебя просят заплатить, продиктовать код или установить непонятное приложение, прекращай общение и сразу пиши нам (чат с основателем или форма обратной связи).