963,149open jobs
58,194companies
159,364added this week
Browse all
Salary
≈ $34k – $94k per year (Estimated)
Location
Remote (Bulgaria, Brazil, Czech Republic, Romania, Spain, Portugal)
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Aug 10, 2026. Cloudlinux scores A on the Alion truth index.

Overview
Company
Impact
Profile match
CloudLinux is on a mission to continually increase security, stability and availability of Linux servers and devices. Headquartered in Palo Alto, California, CloudLinux Inc. develops a hardened Linux distribution, Linux kernel live security patchi...

CloudLinux is a global remote-first company. We are driven by our principles: do the right thing, employees first, we are remote first, and we deliver high-volume, low-cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we all are successful.

Check out our website for more informationhttps://cloudlinux.com/

Imunify360 Security Suite is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy-to-use solution with the six-layer approach to security delivers comprehensive and complete attack prevention.

The mission

We protect web hosting providers and the sites running on their infrastructure through a defense-in-depth stack: web-server-layer WAF, runtime application self-protection for PHP, deep application integrations (WordPress plugins and similar), a malware scanner with cleanup capability, and network-layer firewalls and IP reputation. The pieces talk to each other, and the threat intelligence they generate at scale powers detection across the stack.

Node.js is the segment of the hosting market growing fastest, and the next layer we want to build for it is runtime protection inside the Node.js process itself. Most Node.js workloads on managed hosting today are AI-generated web apps deployed by non-technical owners who can't, won't, and shouldn't be expected to patch their own code or audit their own dependencies. We're going to defend those apps anyway - at runtime, without their cooperation, without breaking them.

You'll build that runtime protection layer end-to-end.

What you'll own

  • The product. A brand-new product line, yours to define - what we intercept, what we don't, what the customer-visible surface looks like.
  • The technical approach. Instrumentation strategy, deployment shape, programming language - all open. You'll consult with our architects but the direction is yours.
  • Implementation, end to end. You'll have the full tooling stack we provide - LLM subscriptions, modern dev infrastructure, the works. Use what makes you fast.
  • Methodology. How you build conviction in your detection logic - your call.
  • Cross-layer signal. Our existing stack produces threat intelligence at unmatched scale: tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps.

How we'll measure success

The product is held to four numbers: runtime overhead, false positives, false negatives, and customer-escalation volume. They reflect what hosting providers and their customers care about. Hit them well and the product runs inside a meaningful slice of the modern Node.js web.

What we're looking for

An experienced researcher or engineer who can build and iterate on a brand-new product, driving both the research and the development. The hard part of this work is knowing what's malicious, what's vulnerable, and what's just an unusual but legitimate pattern - and being right about it across the long tail of frameworks, libraries, and customer code we'll encounter in production.

Requirements

Must have:

  • Proven experience building and shipping a new product, security solution, major feature, or technical system from scratch.
  • Strong evidence of end-to-end technical ownership, from initial investigation and architecture through implementation, release, and production iteration.
  • Strong web application security knowledge and current knowledge of practical exploitation.
  • A working sense of how detection rules behave at scale - what catches attackers without flagging the long tail of legitimate code.
  • Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do.
  • Comfort directing AI coding agents to high-quality output.

Nice to have:

  • Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
  • Background in malware analysis or incident response.
  • Familiarity with managed-hosting environments.
  • Public security research, vulnerability disclosures, or detection rulesets you've authored.
  • Familiarity with the Node.js runtime and the JavaScript ecosystem.

What it's not

  • Not a scope-and-handoff role - you drive the work and own the outcome.
  • Not a "platform team will productize this later" role - you ship to real customer fleets and watch the telemetry quickly.
  • Not a spec-and-review role - you are hands-on every day.

Why this matters

  • Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice - "secure your code, audit your dependencies" - does not apply to them.
  • If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops.

Benefits

What's in it for you?

  • A focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • The opportunity to receive a reward for the most innovative idea that the company can patent.

By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (https://cloudlinux.com/candidate-privacy-notice), which provides detailed information on how we maintain and handle your data.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
963,149 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Sofia
≈ $27k – $64k per year (Estimated) • Remote (India) • Full-Time • Bengaluru
DevOps
Linux
Windows
Cybersecurity
MITRE ATT&CK
CVSS
Apply
$160k – $180k per year • Remote (likely Sweden)
Python
PowerShell
DevOps
Azure
AWS
Cybersecurity
Qualys Cloud Platform
ISO 27001
Microsoft Defender
Zero Trust
PKI
SIEM
Apply
≈ $117k – $212k per year (Estimated) • Remote (United States) • Full-Time • 6+ years exp • Bachelor's Degree • United States
AI/ML
Copilot
Claude
DevOps
Terraform
Ansible
Azure
CI/CD
AWS
DNS
VPN
Cybersecurity
FortiGate
MITRE ATT&CK
SOC 2
HIPAA
NIST 800-53
Zero Trust
SIEM
Apply
≈ $33k – $74k per year (Estimated) • Remote (Romania) • Full-Time • 5+ years exp • Bucharest
Python
Ruby
PowerShell
Bash
DevOps
Splunk
GCP
Azure
AWS
Linux
Windows
TCP/IP
Cybersecurity
Crowdstrike
Microsoft Sentinel
Microsoft Defender
IBM QRadar
SIEM
Management
Agile
Scrum
Apply
≈ $12k – $32k per year (Estimated) • Remote (India) • Full-Time • 2+ years exp • Delhi
AI/ML
Red Teaming
Edge AI
Cybersecurity
MITRE ATT&CK
Apply
Remote (location not specified)
PHP
PHP
WordPress
AI/ML
LLM
Design
Figma
Apply
Remote (India, Colombia, Mexico, Pakistan, Poland, EST hours) • Full-Time
Python
JavaScript
TypeScript
Node JS
Databases
PostgreSQL
Firestore
AI/ML
LLM
Frontend
Next.js
React.js
Mobile
Firebase
DevOps
Rest API
Helm
Vercel
CI/CD
Git
Docker
Kubernetes
Cybersecurity
HIPAA
Apply
$21k – $27k per year • Remote (EAEU) • Moscow
PHP
PHP
Bitrix
AI/ML
Cursor
AI Agents
DevOps
SLI/SLO/SLA
Management
n8n
Apply
Remote (location not specified, US time zones hours)
AI/ML
AI Agents
LLM
OpenAI
Anthropic
Management
Slack
Apply
Hybrid • 5+ years exp • Hyderabad
JavaScript
Java
Kotlin
TypeScript
Dart
Node JS
Scala
Swift
Objective-C
Scala
Akka
Frontend
GraphQL
React.js
Mobile
Flutter
State Management
Modularization
Maestro
DevOps
Kong
CI/CD
AWS
Design
Figma
Management
Agile
QA
Playwright
Apply
Remote (North America) • Full-Time • New York
DevOps
New Relic
Datadog
Dynatrace
PagerDuty
Docker
Cloudflare
GitHub
GitLab
Linux
Cybersecurity
Snyk
Aqua Security
Veracode
Sonatype Nexus IQ
Mend
Marketing
HubSpot
Apply
≈ $53k – $98k per year (Estimated) • Remote (Bulgaria, Poland, Spain, Armenia, Georgia, European time zones hours) • Full-Time • Warsaw
Python
Go
JavaScript
Node JS
Node JS
Commander.js
Databases
Redis
ElasticSearch
AI/ML
AI Agents
DevOps
Kibana
Debian
Jenkins
Grafana
GitLab
Linux
Management
Jira
Apply
≈ $40k – $110k per year (Estimated) • Remote (Poland, Spain, Portugal) • Lisbon
Python
SQL
Python
Django
Celery
Django REST Framework
Databases
RabbitMQ
DevOps
CI/CD
Linux
Apply
≈ $142k – $269k per year (Estimated) • Remote (EMEA, North America) • Full-Time • Seattle
DevOps
Linux
Apply
≈ $54k – $109k per year (Estimated) • Remote (Bulgaria, Serbia, Spain, Portugal) • Madrid
Python
SQL
DevOps
Terraform
Ansible
OpenTofu
GitLab CI
CI/CD
AWS
Kubernetes
Grafana
FinOps
Linux
Apply
≈ $32k – $74k per year (Estimated) • Hybrid • Sofia
Apply
≈ $29k – $67k per year (Estimated) • Hybrid • Bachelor's Degree • Sofia
Management
Outlook
Microsoft Office
Apply
Hybrid • 2+ years exp • Bachelor's Degree • Sofia
PHP
PHP
WordPress
Apply
≈ $14k – $27k per year (Estimated) • In office • Internship • Sofia
Management
Microsoft Office
Apply
≈ $16k – $35k per year (Estimated) • Hybrid • Sofia
Apply
See all jobs
This is one of many
963,149 more open roles from verified company boards, updated every day.