Back to Jobs

Senior/Principal Security Engineer - Node.js Proactive Defense

TrulyRemote Verified

Hand-curated global remote job with direct application link

Technical Requirements

Node.jsJavaScriptWeb Application SecurityMalware AnalysisRuntime ProtectionApplication FirewallsThreat Intelligence

The mission

We protect web hosting providers and the sites running on their infrastructure through a defense-in-depth stack: web-server-layer WAF, runtime application self-protection for PHP, deep application integrations, a malware scanner with cleanup capability, and network-layer firewalls and IP reputation. Node.js is the fastest-growing segment of the hosting market, and we are building runtime protection inside the Node.js process itself to defend applications without requiring developer cooperation or code modification.

What you'll own

  • The product: Define the product line, scope, and customer-visible surface.
  • The technical approach: Determine instrumentation strategy, deployment, and programming language.
  • Implementation: End-to-end development using our modern tooling stack and LLM integrations.
  • Methodology: Design conviction-building processes for detection logic.
  • Cross-layer signal: Utilize our existing petabyte-scale threat intelligence, malware sample storage, and real-time reputation feeds.

How we'll measure success

The product is held to four key metrics: runtime overhead, false positives, false negatives, and customer-escalation volume.

Requirements

Must have:

  • Familiarity with the Node.js runtime and the JavaScript ecosystem.
  • Strong web application security fundamentals and current knowledge of practical exploitation.
  • A working sense of how detection rules behave at scale to catch attackers without flagging legitimate code.
  • Ability to operate independently as a product manager, architect, lead engineer, and QA.

Nice to have:

  • Comfort directing AI coding agents to high-quality output.
  • Prior work on runtime-protection products, application firewalls, or instrumentation tooling.
  • Background in malware analysis or incident response.
  • Familiarity with managed-hosting environments.
  • Public security research, vulnerability disclosures, or authored detection rulesets.
Senior/Principal Security Engineer - Node.js Proactive Defense
Cloudlinux
Apply