Remote Jobs RockRemote Jobs Rock

Security Engineer / Staff Engineer

🕒 27 days ago
📍 🇵🇱 Poland +5 - Remote?🎺 Lead📏 Cybersecurity Engineer📢 🇬🇧 English Required💼 Full-Time
Security EngineeringSecurity ResearchNode.jsArchitecture Design

📜 Description

  • Define the technical approach for building runtime protection inside the Node.js process.
  • Design the detection logic to identify and block attacks during application execution.
  • Build and launch the first version of the product in real production environments.
  • Ensure the protection works without requiring changes to client code and without breaking legitimate applications.
  • Continuously improve the product based on telemetry, production feedback, and real-world incidents.

🛠️ Requirements

  • Builder: You genuinely enjoy creating something new and seeing it run in production.
  • High ownership: You don't wait for tasks to be assigned — you define the approach and own the results.
  • Practioner: You write code (yourself or with AI), not just review and coordinate.
  • You understand Detection Engineering — how detection rules behave at scale across thousands of servers and the true cost of false positives.

✨ Benefits

  • Format: 100% remote work anywhere in the world.
  • Legal setup: B2B only (contract with your sole proprietorship or company).
  • Budget: Up to $12,000 gross/month (before taxes, under a B2B agreement).
  • Company: A stable, established international product company with 15+ years in the market.
  • Role: A key position in building a new product line from the ground up.
Full job description

Imunify360 is a leading developer of Linux infrastructure and security solutions. Our flagship product, Imunify360, is a comprehensive security suite that protects thousands of shared hosting environments, VPS, and dedicated servers worldwide. Our clients include industry giants such as Dell, GoDaddy, IBM, and Zoom, with over 4,500 customers globally. The company has more than 250 employees.

We are looking for an engineer-architect to build a new product from scratch. This is not a position within an existing team—you will single-handedly create a runtime protection layer for Node.js applications. The hosting market is rapidly adopting Node.js, and modern applications are increasingly generated by users with AI tools and little technical security expertise. Your mission is to make protection automatic, transparent to client code, and effective in real time.

This is a role with the highest level of ownership (Senior / Staff / Architect level), where you will make key architectural decisions and take full responsibility for the outcome.

Responsibilities

  • Define the technical approach for building runtime protection inside the Node.js process.
  • Design the detection logic to identify and block attacks during application execution.
  • Build and launch the first version of the product in real production environments.
  • Ensure the protection works without requiring changes to client code and without breaking legitimate applications.
  • Continuously improve the product based on telemetry, production feedback, and real-world incidents.
  • Achieve target values across four key metrics:
    • Runtime overhead
    • False positives
    • False negatives
    • Customer escalation volume

Requirements

The top priority is Security, not just Node.js. Security experience outweighs general backend tenure.

Must-have:

  • Experience in Security Engineering or Security Research (deep understanding of attack vectors and defense methods).
  • Have independently built and shipped a product/solution from scratch (end-to-end ownership: from idea to production).
  • Ability to take an ambiguous problem, define a solution, and deliver a working result without constant supervision.
  • Experience designing architecture and making key technical decisions (Staff/Architect level is a strong plus).
  • English language: Intermediate or higher (written and spoken — all interviews are conducted in English).

Nice-to-have:

  • Security experience specifically in the context of Node.js (vulnerability analysis, securing, researching Node.js applications).
  • Experience with Linux in production and development environments.
  • Knowledge of Runtime Protection, WAF, instrumentation, malware analysis, and Incident Response.
  • Experience in managed hosting / VPS domains.
  • Experience with AI coding agents (Copilot, Cursor, etc.).

Important: If you are a Security Engineer / Researcher who doesn't code on a daily basis, you must be comfortable using AI-assisted development tools and be capable of building an MVP with their help.

Who you are (mindset):

  • Builder: You genuinely enjoy creating something new and seeing it run in production.
  • High ownership: You don't wait for tasks to be assigned — you define the approach and own the results.
  • Practioner: You write code (yourself or with AI), not just review and coordinate.
  • You understand Detection Engineering — how detection rules behave at scale across thousands of servers and the true cost of false positives.

We do NOT consider candidates who:

  • Have only theoretical or research experience without shipping real products.
  • Have general Node.js development experience but lack a security component.
  • Reside in countries with complex B2B tax reporting requirements (USA, UK, Canada, Germany, France, and others — to be clarified during screening).
  • Have frequent job changes (every 1–2 years) without valid reasons.

Benefits

  • Format: 100% remote work anywhere in the world.
  • Legal setup: B2B only (contract with your sole proprietorship or company).
  • Budget: Up to $12,000 gross/month (before taxes, under a B2B agreement).
  • Company: A stable, established international product company with 15+ years in the market.
  • Role: A key position in building a new product line from the ground up.
Phantom

Staff Product Security Engineer (Security)

🕒 8 days ago
Phantom👥 51 - 200 employees🏢 Computer Software

As a Staff Product Security Engineer, you will lead security initiatives, partner with engineering teams, and enhance security practices across Phantom's products using AI-driven solutions.

Product SecurityApplication SecuritySecurity EngineeringSoftware Engineering
Upguard

Staff Product Security Engineer

🕒 20 days ago
Upguard👥 201 - 500 employees🏢 Information Technology And Services

As UpGuard's first dedicated product security hire, you'll define security standards and practices, manage vulnerabilities, and lead security initiatives across our cloud-native infrastructure.

Security EngineeringSoftware EngineeringSecurity OperationsCloud Security
Reddit

Staff Product Security Engineer

📅 Apr 29
Reddit👥 1001 - 5000 employees🏢 Online Community/social Media

As a Staff Product Security Engineer, you'll lead the design and implementation of secure frameworks and controls to enhance security in AI-assisted development and engineering workflows.

Software EngineeringProduct SecurityApplication SecurityGo

Trusted by Remote Workers