Resumo da vaga

Security Engineer- Node.js Proactive Defense (worldwide remote, work anywhere)

Requisitos e responsabilidades

Conteúdo da vaga extraído em seções para revisão mais rápida.

What you'll own

  • The product. A brand-new product line, yours to define — what we intercept, what we don't, what the customer-visible surface looks like.
  • The technical approach. Instrumentation strategy, deployment shape, programming language — all open. You'll consult with our architects but the direction is yours.
  • Implementation, end to end. You'll have the full tooling stack we provide — LLM subscriptions, modern dev infrastructure, the works. Use what makes you fast.
  • Methodology. How you build conviction in your detection logic — your call.
  • Cross-layer signal. Our existing stack produces threat intelligence at unmatched scale: tens of millions of monitored sites, petabyte-scale malware sample storage, real-time domain and URL reputation, IP-level attack feeds. These are available for you to plug into. Use what helps.

RequirementsMust have:

  • Familiarity with the Node.js runtime and the JavaScript ecosystem.
  • Strong web application security fundamentals and current knowledge of practical exploitation.
  • A working sense of how detection rules behave at scale — what catches attackers without flagging the long tail of legitimate code.
  • Ability to start as the PM, architect, lead engineer, and QA for this product. You ask for resources or help when you need them; you don't wait to be told what to do.

Nice to have:

  • Comfort directing AI coding agents to high-quality output — most of our engineering does this now.
  • Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
  • Background in malware analysis or incident response.
  • Familiarity with managed-hosting environments.
  • Public security research, vulnerability disclosures, or detection rulesets you've authored.

What it's not

  • Not a scope-and-handoff role — you drive the work and own the outcome.
  • Not a "platform team will productize this later" role — you ship to real customer fleets and watch the telemetry quickly.
  • Not a spec-and-review role — you are hands-on every day.

Why this matters

  • Most managed-hosting customers are not developers. They cannot patch their apps. They cannot audit their dependencies. They will keep deploying vulnerable code from AI assistants because that's how modern web apps get built now. The textbook advice — "secure your code, audit your dependencies" — does not apply to them.
  • If we don't intercept exploits at runtime, nobody will. The numbers you hit on detection, performance, and false positives will materially affect how much of the modern web stays online when the next exploit class drops.

What's in it for you?

  • A focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • The opportunity to receive a reward for the most innovative idea that the company can patent.
Vagas similares

Mantenha uma lista reserva.

Ver stack
FocoSecurity EngineeringÁrea da vaga
Sinal de senioridadeSeniorNível do candidato
StackJavaScript, LLM, Node.jsSkills principais
Localização1 país aceitoElegibilidade

Stack

Use estas tags para comparar vagas remotas similares.

Elegibilidade de localização

Candidatos devem aplicar apenas quando o país do perfil estiver listado aqui.

Seu perfilPaís não definidoEntre para comparar seu país com esta vaga.

Fluxo de contratação

O WithMira mostra a vaga e depois envia candidatos para a aplicação da empresa.

1Confira fit da vaga, stack e elegibilidade de localização no WithMira.
2Abra a página de aplicação da empresa pelo link rastreado.
3Salve a vaga ou assine oportunidades similares antes de sair.