CloudLinux Security Engineer
Cloudlinux
The mission
We protect web hosting providers and the sites running on their infrastructure through a defense-in-depth stack: web-server-layer WAF, runtime application self-protection for PHP, deep application integrations (WordPress plugins and similar), a malware scanner with cleanup capability, and network-layer firewalls and IP reputation. The pieces talk to each other, and the threat intelligence they generate at scale powers detection across the stack.
Node.js is the segment of the hosting market growing fastest, and the next layer we want to build for it is runtime protection inside the Node.js process itself. Most Node.js workloads on managed hosting today are AI-generated web apps deployed by non-technical owners who can't, won't, and shouldn't be expected to patch their own code or audit their own dependencies. We're going to defend those apps anyway — at runtime, without their cooperation, without breaking them.
You'll build that runtime protection layer end-to-end.
What you'll own
- The product. A brand-new product line, yours to define — what we intercept, what we don't, what the customer-visible surface looks like.
- The technical approach. Instrumentation strategy, deployment shape, programming language — all open. You'll consult with our architects but the direction is yours.
- Implementation, end to end. You'll have the full tooling stack we provide — LLM subscriptions, modern dev infrastructure, the works. Use what makes you fast.
- Methodology. How you build conviction in your detection logic — your call.
- Cross-layer signal. Our existing stack produces threat intelligence at unmatched scale: tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps.
How we'll measure success
The product is held to four numbers: runtime overhead, false positives, false negatives, and customer-escalation volume. They reflect what hosting providers and their customers care about. Hit them well and the product runs inside a meaningful slice of the modern Node.js web.
What we're looking for
An experienced researcher or engineer who can build and iterate on a brand-new product, driving both the research and the development. The hard part of this work is knowing what's malicious, what's vulnerable, and what's just an unusual but legitimate pattern — and being right about it across the long tail of frameworks, libraries, and customer code we'll encounter in production.
Requirements
Must have:
- Familiarity with the Node.js runtime and the JavaScript ecosystem.
- Strong web application security fundamentals and current knowledge of practical exploitation.
- A working sense of how detection rules behave at scale — what catches attackers without flagging the long tail of legitimate code.
- Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do.
Nice to have:
- Comfort directing AI coding agents to high-quality output — most of our engineering does this now.
- Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
- Background in malware analysis or incident response.
- Familiarity with managed-hosting environments.
- Public security research, vulnerability disclosures, or detection rulesets you've authored.
What it's not
- Not a scope-and-handoff role — you drive the work and own the outcome.
- Not a "platform team will productize this later" role — you ship to real customer fleets and watch the telemetry quickly.
- Not a spec-and-review role — you are hands-on every day.
Why this matters
- Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice — "secure your code, audit your dependencies" — does not apply to them.
- If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops.
Benefits
What's in it for you?
- A focus on professional development.
- Interesting and challenging projects.
- Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
- Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
- Compensation for private medical insurance.
- Co-working and gym/sports reimbursement.
- Budget for education.
- The opportunity to receive a reward for the most innovative idea that the company can patent.
- ...web. What we're looking for An experienced researcher or engineer who can build and iterate on a brand-new product, driving both... ...and the JavaScript ecosystem. Strong web application security fundamentals and current knowledge of practical exploitation....SuggestedFull timeRemote workWorldwideFlexible hours
- ...CloudLinux is a global remote-first company driven by principles: do the right thing, employees... ..., low-cost Linux infrastructure and security products to help companies increase the... ...approach. We are looking for an experienced engineer to own the automated pipelines that turn...SuggestedFull timeRemote workWorldwideFlexible hoursNight shift
- ...together multiple teams working on the construction of our gigafactory and the different stages of battery cell production. From engineering and design to process optimization and production excellence, Operations is where the future of energy takes shape. As our Facility...SuggestedPermanent employmentFull timeContract workFlexible hoursRotating shift
- ...profiling database behind Grafana Cloud Profiles. Pyroscope gives engineers code-level visibility into how their applications use CPU and... ...as part of your daily workflow (your choice of tools, within security guidelines), backed by a company-funded usage budget so you...SuggestedFull timeRemote workShift work
- ...Internship - Regulatory Engineer Spain • United States Research & Engineering Remote Full-time About Alinia We are an early-stage AI startup on a mission to enable the safe and compliant deployment of AI Agents in regulated industries, worldwide, through...SuggestedFull timeInternshipRemote workWorldwide
- Responsibilities: Own the end-to-end attribution and signals system, becoming the company’s expert driving technical decisions and best practices across the organization Implement and improve attribution models ( Appsflyer , GA4 , custom server-side) ensuring it remains...Full time
- ...financial transactions every month across multiple providers, regions, and products. We are looking for an experienced OpenSearch Engineer to own and scale our AWS OpenSearch infrastructure and the pipelines that synchronize data from PostgreSQL . You will be responsible...Full time
- Job Description We're seeking an experienced Go Engineer to join our team and contribute significantly to our payment gateway product.... ...the project: Payment gateway solutions - fintech product that securely connects merchants and financial institutions to process online...Full time
- The Opportunity We build Pyroscope , the open-source continuous profiling database behind Grafana Cloud Profiles. Pyroscope gives engineers code-level visibility into how their applications use CPU and memory, down to the specific line of code, and connects that signal...Full timeShift work
- ...Management and In-Flight Entertainment solutions. Working with engineering teams in Madrid and Basel, you will help create reliable and... ...Stability: Backed by General Dynamics, offering long-term security and investment in your growth. Our hiring process At Jet...Full timeLocal areaRemote workWorldwideFlexible hours2 days per week
- ...Qdrant is an open-source vector search engine powering the next generation of AI applications, from semantic search and retrieval-augmented generation (RAG) to AI agents and real-time recommendations. Trusted by global leaders like Canva, HubSpot, Tripadvisor, Bosch...Full timeRemote workFlexible hours
- ...recently 2025) LinkedIn as one of the Top 20 Startups in the UK (2025) About this role in the team: We are looking for a QA Engineer who views AI as their primary leverage. At BVNK, we aren't just looking for someone to maintain scripts; we want an engineer who views...Full timeWorldwideFlexible hoursShift work
- What you will own Design and evolve core platform services and internal APIs consumed by multiple teams. Drive architectural initiatives such as gRPC migration, eventing/pub-sub foundations, and platform refactors. Own and improve control-plane and cluster-api components...Full time
- ...through monitoring, logging, and alerting. Automate workflows and integrations across systems and tools. Collaborate with engineering, operations, and data teams to understand and support their infrastructure needs. Contribute to incident response, root cause...Full time
$15 per hour
Summary The Wikimedia Foundation is seeking a Senior Software Engineer to join the team supporting the Wikidata Platform — the structured data backbone of Wikimedia projects and a key part of the global open knowledge ecosystem. You’ll help scale and sustain the Wikidata...Full time- About the team The MongoDB Tools Team builds Percona's open source operational tooling for MongoDB . Two projects sit at the center of what we do. Percona ClusterSync for MongoDB (PCSM) clones and continuously replicates data between clusters. Percona Backup for MongoDB...Full time
- Role Overview We are looking for a Senior QA Engineer to ensure the quality, reliability, and accuracy of trading and related products for a centralized crypto exchange. This role requires strong technical knowledge and an understanding of complex financial systems. You...Full time
- ...provisioning, grants, backups, restores, health checks, and ownership metadata. Help build DBaaS-style self-service capabilities so engineering teams can request databases, access, credentials, and operational checks with less manual DBA intervention. Improve observability...Full time
- ...tangible impact at global scale. We're looking for a Data Platform Engineer to join our Data Engineering team and help build a modern data... ...a critical role in enabling reliable, high-performance, and secure data systems. You'll work closely with data engineers,...Full timeLocal areaRemote work
- Your Responsibilities: Own production PostgreSQL reliability: HA design, Patroni, PgBouncer, replication, failover, upgrades, vacuum/bloat control, query tuning, locks, indexes, capacity, backups, PITR, and restore validation. Improve disaster recovery and operational evidence...Full time
- ...architectures globally. Position Overview We are seeking a highly analytical, connection-obsessed, and systems-minded AI Systems Engineer to join our decentralized core Operations matrix under a high-agency full-time remote engagement framework open to builders across...Full timeLocal areaRemote workWork from homeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CloudLinux Security Engineer. Be the first to apply!














