
Security Engineer / Staff Engineer
At a Glance
- Category
- 💻 Technology
- Level
- Senior
- Type
- Full-time
Are You in the 25%?
- Check if Alex Staff Agency will actually see your resume
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
Imunify360 is a leading developer of Linux infrastructure and security solutions. Our flagship product, Imunify360, is a comprehensive security suite that protects thousands of shared hosting environments, VPS, and dedicated servers worldwide. Our clients include industry giants such as Dell, GoDaddy, IBM, and Zoom, with over 4,500 customers globally. The company has more than 250 employees.
We are looking for an engineer-architect to build a new product from scratch. This is not a position within an existing team—you will single-handedly create a runtime protection layer for Node.js applications. The hosting market is rapidly adopting Node.js, and modern applications are increasingly generated by users with AI tools and little technical security expertise. Your mission is to make protection automatic, transparent to client code, and effective in real time.
This is a role with the highest level of ownership (Senior / Staff / Architect level), where you will make key architectural decisions and take full responsibility for the outcome.
Responsibilities
• Define the technical approach for building runtime protection inside the Node.js process.
• Design the detection logic to identify and block attacks during application execution.
• Build and launch the first version of the product in real production environments.
• Ensure the protection works without requiring changes to client code and without breaking legitimate applications.
• Continuously improve the product based on telemetry, production feedback, and real-world incidents.
• Achieve target values across four key metrics:
• Runtime overhead
• False positives
• False negatives
• Customer escalation volume
The top priority is Security, not just Node.js. Security experience outweighs general backend tenure.
Must-have:
- Experience in Security Engineering or Security Research (deep understanding of attack vectors and defense methods).
- Have independently built and shipped a product/solution from scratch (end-to-end ownership: from idea to production).
- Ability to take an ambiguous problem, define a solution, and deliver a working result without constant supervision.
- Experience designing architecture and making key technical decisions (Staff/Architect level is a strong plus).
- English language: Intermediate or higher (written and spoken — all interviews are conducted in English).Nice-to-have:
- Security experience specifically in the context of Node.js (vulnerability analysis, securing, researching Node.js applications).
- Experience with Linux in production and development environments.
- Knowledge of Runtime Protection, WAF, instrumentation, malware analysis, and Incident Response.
- Experience in managed hosting / VPS domains.
- Experience with AI coding agents (Copilot, Cursor, etc.).Important: If you are a Security Engineer / Researcher who doesn't code on a daily basis, you must be comfortable using AI-assisted development tools and be capable of building an MVP with their help.
Who you are (mindset):
- Builder: You genuinely enjoy creating something new and seeing it run in production.
- High ownership: You don't wait for tasks to be assigned — you define the approach and own the results.
- Practioner: You write code (yourself or with AI), not just review and coordinate.
- You understand Detection Engineering — how detection rules behave at scale across thousands of servers and the true cost of false positives.We do NOT consider candidates who:
- Have only theoretical or research experience without shipping real products.
- Have general Node.js development experience but lack a security component.
- Reside in countries with complex B2B tax reporting requirements (USA, UK, Canada, Germany, France, and others — to be clarified during screening).
- Have frequent job changes (every 1–2 years) without valid reasons.
- Format: 100% remote work anywhere in the world.
- Legal setup: B2B only (contract with your sole proprietorship or company).
- Budget: Up to $12,000 gross/month (before taxes, under a B2B agreement).
- Company: A stable, established international product company with 15+ years in the market.
- Role: A key position in building a new product line from the ground up.
Requirements
- •Experience in Security Engineering or Security Research
- •Deep understanding of attack vectors and defense methods
- •Proven track record of building and shipping a product from scratch
- •Ability to work independently and handle ambiguous problems
- •Experience designing architecture and making key technical decisions
- •Intermediate or higher English language proficiency
Nice to Have
- •Security experience specifically in the context of Node.js
- •Experience with Linux in production and development environments
- •Knowledge of Runtime Protection, WAF, instrumentation, malware analysis, and Incident Response
- •Experience in managed hosting / VPS domains
- •Experience with AI coding agents (Copilot, Cursor, etc.)
Responsibilities
- •Define the technical approach for building runtime protection inside the Node.js process
- •Design detection logic to identify and block attacks during execution
- •Build and launch the first version of the product in production environments
- •Ensure protection works without requiring changes to client code
- •Improve product based on telemetry, production feedback, and real-world incidents
- •Achieve target values for runtime overhead, false positives, false negatives, and escalation volume
- Check if Alex Staff Agency will actually see your resume
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
Alex Staff Agency provides recruitment and staffing solutions. They connect businesses with qualified candidates across various industries.