← Todas as vagas

Security Engineer – Staff Engineer

Sobre a vaga

• Define the technical approach for runtime protection inside the Node.js process
• Design detection logic to identify and block attacks during application execution
• Build and launch the first product version in real production environments
• Ensure protection works without changes to client code and without breaking legitimate applications
• Continuously improve the product using telemetry, production feedback, and real-world incidents
• Achieve target values for runtime overhead, false positives, false negatives, and customer escalation volume
• Single-handedly create a runtime protection layer for Node.js applications
• Make key architectural decisions and take full responsibility for the outcome

• Experience in Security Engineering or Security Research, with deep understanding of attack vectors and defense methods
• Independently built and shipped a product or solution from scratch, end-to-end from idea to production
• Ability to define a solution for an ambiguous problem and deliver without constant supervision
• Experience designing architecture and making key technical decisions
• Intermediate or higher English, written and spoken; all interviews are conducted in English
• Node.js security experience is nice to have
• Production and development experience with Linux is nice to have
• Knowledge of Runtime Protection, WAF, instrumentation, malware analysis, and Incident Response is nice to have
• Experience in managed hosting or VPS domains is nice to have
• Experience with AI coding agents such as Copilot or Cursor is nice to have
• Security Engineer or Researcher candidates who do not code daily must be comfortable using AI-assisted development tools and capable of building an MVP with their help
• Builder mindset and enjoyment of creating and running products in production
• High ownership and ability to define the approach and own results
• Ability to write code personally or with AI
• Understanding of Detection Engineering and the operational cost of false positives
• Candidates must not have only theoretical or research experience without shipping real products
• Candidates must have a security component to their experience; general Node.js experience alone is insufficient
• Candidates must not reside in countries with complex B2B tax reporting requirements, including USA, UK, Canada, Germany, France, and others to be clarified during screening
• Candidates must not have frequent job changes every 1–2 years without valid reasons

• 100% remote work anywhere in the world
• B2B contract with your sole proprietorship or company
• Budget up to $12,000 gross/month before taxes under a B2B agreement
• Stable, established international product company with 15+ years in the market
• Key position building a new product line from the ground up