
Security Engineer – Staff Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Poland, +4 more countries.
• Establish the technical strategy for runtime protection within the Node.js environment.
• Develop detection mechanisms to recognize and prevent attacks during application runtime.
• Create and launch the initial version of the product in live production settings.
• Ensure the protection system functions seamlessly without modifications to client code and without disrupting legitimate applications.
• Consistently enhance the product using telemetry, feedback from production, and real-world incidents.
• Meet targeted metrics for runtime overhead, false positives, false negatives, and volume of customer escalations.
• Independently develop a runtime protection layer for Node.js applications.
• Make critical architectural choices and take full accountability for the outcomes.
• Proven experience in Security Engineering or Security Research, with a comprehensive understanding of attack vectors and defense strategies.
• Successfully created and launched a product or solution from inception to production independently.
• Ability to devise a solution for ambiguous challenges and deliver results without constant oversight.
• Experience in architectural design and making significant technical decisions.
• Proficient in English, both written and spoken; all interviews will be conducted in English.
• Node.js security expertise is a plus.
• Background in production and development environments with Linux is advantageous.
• Familiarity with Runtime Protection, WAF, instrumentation, malware analysis, and Incident Response is beneficial.
• Experience in managed hosting or VPS domains is a plus.
• Familiarity with AI coding tools such as Copilot or Cursor is an added advantage.
• Security Engineer or Researcher candidates who do not code regularly should be comfortable using AI-assisted development tools and capable of creating an MVP with their assistance.
• A builder mindset and enthusiasm for developing and maintaining products in production.
• Strong sense of ownership with the ability to define strategies and take charge of results.
• Capability to write code personally or with the help of AI.
• Understanding of Detection Engineering and the operational costs associated with false positives.
• Candidates should not possess only theoretical or research experience without having shipped real products.
• Candidates must have a security element in their background; general Node.js experience is not sufficient.
• Candidates must not reside in countries with complex B2B tax reporting obligations, including the USA, UK, Canada, Germany, France, and others to be specified during screening.
• Candidates must not have a history of frequent job changes every 1–2 years without valid justifications.
• 100% remote work flexibility from anywhere in the world.
• B2B contract with your own sole proprietorship or company.
• Gross budget of up to $12,000 per month before taxes under a B2B agreement.
• Stable and established international product company with over 15 years in the market.
• A pivotal role in developing a new product line from the ground up.
Cisco
Arctiq
Cotiviti
Twilio
Get handpicked remote jobs straight to your inbox weekly.