CloudLinux
Posted 3w ago

Security Engineer - Node.js Proactive Defense (worldwide remote, work anywhere)

CloudLinux
Madrid or Europe
RemoteFull Time
Responsibilities
  • building product
  • designing instrumentation
  • driving research
Requirements
  • Deep Node.js and JavaScript knowledge
  • Strong web application security and exploitation skills
  • Experience designing detection rules at scale, and ability to own PM/architecture/implementation for a runtime-protection product
Technical tools mentioned
Node.jsJavaScript

Job description

CloudLinux is a global remote-first company. We are driven by our principles: do the right thing, employees first, we are remote first, and we deliver high-volume, low-cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we all are successful. 

Check out our website for more information https://cloudlinux.com/

Imunify360 Security Suite is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy-to-use solution with the six-layer approach to security delivers comprehensive and complete attack prevention.

The mission

We protect web hosting providers and the sites running on their infrastructure through a defense-in-depth stack: web-server-layer WAF, runtime application self-protection for PHP, deep application integrations (WordPress plugins and similar), a malware scanner with cleanup capability, and network-layer firewalls and IP reputation. The pieces talk to each other, and the threat intelligence they generate at scale powers detection across the stack.

Node.js is the segment of the hosting market growing fastest, and the next layer we want to build for it is runtime protection inside the Node.js process itself. Most Node.js workloads on managed hosting today are AI-generated web apps deployed by non-technical owners who can't, won't, and shouldn't be expected to patch their own code or audit their own dependencies. We're going to defend those apps anyway — at runtime, without their cooperation, without breaking them.

You'll build that runtime protection layer end-to-end.

What you'll own

  • The product. A brand-new product line, yours to define — what we intercept, what we don't, what the customer-visible surface looks like.
  • The technical approach. Instrumentation strategy, deployment shape, programming language — all open. You'll consult with our architects but the direction is yours.
  • Implementation, end to end. You'll have the full tooling stack we provide — LLM subscriptions, modern dev infrastructure, the works. Use what makes you fast.
  • Methodology. How you build conviction in your detection logic — your call.
  • Cross-layer signal. Our existing stack produces threat intelligence at unmatched scale: tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps.

How we'll measure success

The product is held to four numbers: runtime overhead, false positives, false negatives, and customer-escalation volume. They reflect what hosting providers and their customers care about. Hit them well and the product runs inside a meaningful slice of the modern Node.js web.

What we're looking for

An experienced researcher or engineer who can build and iterate on a brand-new product, driving both the research and the development. The hard part of this work is knowing what's malicious, what's vulnerable, and what's just an unusual but legitimate pattern — and being right about it across the long tail of frameworks, libraries, and customer code we'll encounter in production.

Requirements

Must have:

  • Familiarity with the Node.js runtime and the JavaScript ecosystem.
  • Strong web application security fundamentals and current knowledge of practical exploitation.
  • A working sense of how detection rules behave at scale — what catches attackers without flagging the long tail of legitimate code.
  • Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do.

Nice to have:

  • Comfort directing AI coding agents to high-quality output — most of our engineering does this now.
  • Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
  • Background in malware analysis or incident response.
  • Familiarity with managed-hosting environments.
  • Public security research, vulnerability disclosures, or detection rulesets you've authored.

What it's not

  • Not a scope-and-handoff role — you drive the work and own the outcome.
  • Not a "platform team will productize this later" role — you ship to real customer fleets and watch the telemetry quickly.
  • Not a spec-and-review role — you are hands-on every day.

Why this matters

  • Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice — "secure your code, audit your dependencies" — does not apply to them.
  • If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops.

Benefits

What's in it for you?

  • A focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • The opportunity to receive a reward for the most innovative idea that the company can patent.

By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (https://cloudlinux.com/candidate-privacy-notice), which provides detailed information on how we maintain and handle your data.

About CloudLinux

Provides security, stability, and live patching for Linux servers.

Year founded
2009
Employees
250
Organization type
Private
Latest investment
Private Equity (2018) — led by Equivia Partners
Headquarters
US

Similar jobs

Security Engineer roles near Madrid, Community of Madrid
1d
Save
Mark Applied
Hide
Security Engineer L3
Las Rozas, Community of Madrid, Spain
OnsiteFull Time
DXC Technology
DXC TechnologyNYSE: DXC: Global provider of IT services and business technology solutions.
5+ YOERequires 5+ years in network security engineering, 3+ years with Guardicore/Akamai and Tufin, zero-trust and firewall expertise, scripting, automation, team leadership, and English and Spanish proficiency.
Guardicore, Akamai, Tufin, SecureTrack, SecureChange, SecureApp, Palo Alto, Fortinet, Check Point, Python, REST APIs, Ansible, SIEM, SOAR, AWS, Microsoft Azure, Google Cloud Platform
3d
Save
Mark Applied
Hide
Senior Security Engineer
Madrid, Community of Madrid, Spain
€75k-€83k/yr OnsiteFull Time
Auctane
Auctane: Provides software for e-commerce shipping and global mailing services.
7+ YOE3+ MgmtBachelor's degree in a technical field, 7+ years in cybersecurity, program leadership experience, advanced enterprise or cloud security expertise, stakeholder communication, and experience leading engineers and analysts.
AWS, GCP, SaaS, Gemini, Claude, CNAPP, DSPM, DAST, SAST, SCA, ASM, SIEM, Google Workspace, Python, PowerShell, Bash, GuardDuty, Security Hub, GCP Security Command Center, Wiz, Crowdstrike, Azure, Cigna, Cobee, LinkedIn Learning, Wellhub, Curalinc, Rocketlawyer, Slack, Packlink Pro
1w
Save
Mark Applied
Hide
Security Engineer
Berlin or Paris or Amsterdam or Madrid
RemoteFull Time
Qdrant
Qdrant: Open-source vector search engine for AI retrieval and infrastructure.
3+ YOE3+ years security engineering or vulnerability management experience; hands-on with Rust/Go/Python, cloud and container security, bug bounty triage, and CI/CD security; strong written communication.
Rust, Go, Python, AWS, Kubernetes, GitHub, CI/CD
2w
Save
Mark Applied
Hide
Space Security Engineer - Relocation to Spain
Rivas-Vaciamadrid, Madrid, Spain
OnsiteFull Time
Grupo Oesía
Grupo Oesía: Digital and industrial engineering for defense and aerospace industries.
8+ YOE8+ years in security/defence/aerospace, cybersecurity risk management, threat analysis, secure architecture, systems modelling (MBSE a plus), experience in international projects, advanced English (C1).
3w
Save
Mark Applied
Hide
Experto Ciberseguridad & Networking
Madrid, Community of Madrid, Spain
HybridFull Time
Atalanta
Atalanta: Provider of cybersecurity and digital strategy consulting services.
Experience implementing, configuring, administering and supporting perimeter security and network solutions (Cloudflare, Zscaler, Fortinet, Palo Alto); BGP, SDWAN, IPv6; Crowdstrike and Azure EntraID administration; strong communication and proactivity.
Cloudflare, Zscaler, Fortinet, Palo Alto, Crowdstrike, Azure EntraID, BGP, SDWAN, IPv6
4w
Save
Mark Applied
Hide
Senior Security Engineer - Applications Identity and Access Management (Hybrid set up)
Madrid, Community of Madrid, Spain
€60k-€100k/yr HybridFull Time
Swiss Re
Swiss ReSIX Swiss Exchange: SREN: Provides global reinsurance and insurance-based risk management solutions.
Background in software engineering or DevSecOps, deep knowledge of authentication protocols, experience designing secure multi-cloud integrations, coding ability, and strong communication of technical risk.
1mo
Save
Mark Applied
Hide
Tech_- Ingeniero/a experto en Tecnologías de Seguridad
Madrid, Community of Madrid, Spain
HybridFull Time
Telefónica
TelefónicaBolsas y Mercados Españoles: TEF: Global provider of telecommunications and digital infrastructure services.
3+ YOE3+ years cybersecurity experience, degree in Computer Science/Telecommunications or equivalent, strong knowledge of SSE, ZTNA, and WAF technologies, fluent Spanish and English.
SSE (Security Service Edge), Netskope, Zscaler, F5, Linux
1mo
Save
Mark Applied
Hide
Senior Security Engineer
Madrid, Community of Madrid, Spain
OnsiteFull Time
Roche
RocheSIX Swiss Exchange: ROG: Develops and manufactures pharmaceutical medicines and diagnostic solutions.
5+ YOEMinimum 5 years IT security experience; experience with OT/manufacturing systems, incident response, security architecture, stakeholder management, and automation using secure AI tools. Bachelor's in computing/engineering is an asset.
Java, Net, C++, Python, bash, power shell, ServiceNow