This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Software Engineer (Malware Detection) based in United States.
This is a senior backend and production-infrastructure role focused on building the platform that evaluates the safety of software artifacts before they reach customers. You will own the architecture, scalability, reliability, and operational excellence of a critical malware scanning platform. Working closely with Product Security, you will turn emerging threat research into fast, accurate, and dependable production detections. Your work will support multiple artifact types, including software libraries, containers, AI agent skills, and future product surfaces. You will also shape the APIs and services that enable customers to investigate findings, enforce policies, and manage security decisions at scale. This is an opportunity to provide staff-level technical leadership in a security-focused environment while solving complex challenges across backend systems, infrastructure, and threat detection.
Accountabilities:
- Own the architecture and evolution of a shared malware scanning platform, including scan orchestration, verdict storage, APIs, and the underlying services required by multiple products.
- Build the measurement systems, pipelines, metrics, and dashboards needed to evaluate detection coverage and precision, enabling data-driven decisions about scanner quality.
- Develop efficient feedback loops between engineering and security teams so that detection changes can be evaluated, validated, and deployed rapidly, with systems for reviewing, escalating, and correcting findings at ecosystem scale.
- Scale the scanner platform across multiple artifact types and ecosystems while balancing detection quality, performance, extensibility, throughput, latency, infrastructure costs, and operational complexity.
- Build and operate the analysis infrastructure supporting deterministic static analysis and AI-assisted reasoning over artifact contents, taking emerging threat detections from research prototypes into reliable production systems.
- Partner with security specialists to ensure new detections run accurately and efficiently across new releases and supported ecosystems.
- Develop the APIs and backend services that allow customers to investigate findings, enforce security policies, manage outcomes, and operate the platform at enterprise scale.
- Take production ownership of the scanning system, including alerting, queue health, observability, verdict-before-serve guarantees, reliability, and incident response.
- Provide staff-level technical leadership through architectural decisions, design reviews, code reviews, mentoring, and collaboration across Product, Security, Design, and go-to-market teams.
- Bring multiple years of experience building and operating production backend or infrastructure systems, with a demonstrated track record of staff-level technical ownership and leadership.
- Have strong experience with Go, or deep backend systems expertise combined with the ability to quickly become productive in Go.
- Demonstrate experience owning highly technical platforms or backend infrastructure that supports multiple products, teams, or internal customers.
- Have experience designing and operating high-throughput, event-driven pipelines where performance, latency, scalability, and correctness must be managed simultaneously.
- Possess a strong understanding of software supply chain security, malware detection, vulnerability management, or closely related security domains.
- Be comfortable making engineering design and prioritization decisions in technically complex and ambiguous environments, balancing competing product, security, reliability, and infrastructure requirements.
- Demonstrate experience defining and improving meaningful quality metrics, including the ability to manage false-positive rates and understand the customer impact of both missed detections and incorrect alerts.
- Have hands-on experience deploying and operating production services, with strong judgment around reliability, observability, incident response, and operational tradeoffs.
- Demonstrate experience mentoring engineers and raising engineering standards through thoughtful design and code review practices.
- Bring excellent cross-functional communication skills and the ability to influence Product, Security, Design, and go-to-market stakeholders.
- Experience with malware detection, static analysis, software composition analysis, or vulnerability scanning is a valuable plus.
- Familiarity with package ecosystems such as npm, PyPI, Maven, Go modules, or container registries is advantageous.
- Experience building reusable platform capabilities, cloud infrastructure, software supply chain security solutions, or enterprise security platforms is beneficial.
- Familiarity with AI-assisted security analysis, automated threat detection, sandboxing, dynamic analysis, eBPF, gVisor, seccomp, container isolation, Terraform, or infrastructure-as-code practices is a plus.
- Flexible, remote-first working environment with team meetup opportunities, bi-annual destination summits, and a monthly stipend supporting coworking, phone, and internet expenses.
- Stock options upon hire and promotion, with opportunities to participate in secondary offerings and a 10-year exercise period for options.
- 100% coverage of health, vision, and dental insurance premiums for employees and their dependents.
- Flexible time off designed to support rest, personal needs, and sustainable high performance.
- Paid parental leave of 18 weeks for birthing parents and 12 weeks for non-birthing parents, with flexibility to use the leave throughout a child’s first year.
- A collaborative environment that values customer focus, intentional action, transparency, trust, and strong teamwork.

