Skip to content

Open nowPosted 31 days ago

Security Engineer / Staff Engineer

Workable (global search)109,826 open roles

Where
United Arab Emirates
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer / Staff EngineerWorkable (global search) · United Arab Emirates
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 31 days ago

Workable (global search) median: 2 days open

The posting

Imunify360 is a leading developer of Linux infrastructure and security solutions. Our flagship product, Imunify360, is a comprehensive security suite that protects thousands of shared hosting environments, VPS, and dedicated servers worldwide. Our clients include industry giants such as Dell, GoDaddy, IBM, and Zoom, with over 4,500 customers globally. The company has more than 250 employees.

We are looking for an engineer-architect to build a new product from scratch. This is not a position within an existing team—you will single-handedly create a runtime protection layer for Node.js applications. The hosting market is rapidly adopting Node.js, and modern applications are increasingly generated by users with AI tools and little technical security expertise. Your mission is to make protection automatic, transparent to client code, and effective in real time.

This is a role with the highest level of ownership (Senior / Staff / Architect level), where you will make key architectural decisions and take full responsibility for the outcome.

Responsibilities

  • Define the technical approach for building runtime protection inside the Node.js process.
  • Design the detection logic to identify and block attacks during application execution.
  • Build and launch the first version of the product in real production environments.
  • Ensure the protection works without requiring changes to client code and without breaking legitimate applications.
  • Continuously improve the product based on telemetry, production feedback, and real-world incidents.
  • Achieve target values across four key metrics:
  • Runtime overhead
  • False positives
  • False negatives
  • Customer escalation volume

Requirements

The top priority is Security, not just Node.js. Security experience outweighs general backend tenure.

Must-have:

  • Experience in Security Engineering or Security Research (deep understanding of attack vectors and defense methods).
  • Have independently built and shipped a product/solution from scratch (end-to-end ownership: from idea to production).
  • Ability to take an ambiguous problem, define a solution, and deliver a working result without constant supervision.
  • Experience designing architecture and making key technical decisions (Staff/Architect level is a strong plus).
  • English language: Intermediate or higher (written and spoken — all interviews are conducted in English).

Nice-to-have:

  • Security experience specifically in the context of Node.js (vulnerability analysis, securing, researching Node.js applications).
  • Experience with Linux in production and development environments.
  • Knowledge of Runtime Protection, WAF, instrumentation, malware analysis, and Incident Response.
  • Experience in managed hosting / VPS domains.
  • Experience with AI coding agents (Copilot, Cursor, etc.).

Important: If you are a Security Engineer / Researcher who doesn't code on a daily basis, you must be comfortable using AI-assisted development tools and be capable of building an MVP with their help.

Who you are (mindset):

  • Builder: You genuinely enjoy creating something new and seeing it run in production.
  • High ownership: You don't wait for tasks to be assigned — you define the approach and own the results.
  • Practioner: You write code (yourself or with AI), not just review and coordinate.
  • You understand Detection Engineering — how detection rules behave at scale across thousands of servers and the true cost of false positives.

We do NOT consider candidates who:

  • Have only theoretical or research experience without shipping real products.
  • Have general Node.js development experience but lack a security component.
  • Reside in countries with complex B2B tax reporting requirements (USA, UK, Canada, Germany, France, and others — to be clarified during screening).
  • Have frequent job changes (every 1–2 years) without valid reasons.

Benefits

  • Format: 100% remote work anywhere in the world.
  • Legal setup: B2B only (contract with your sole proprietorship or company).
  • Budget: Up to $12,000 gross/month (before taxes, under a B2B agreement).
  • Company: A stable, established international product company with 15+ years in the market.
  • Role: A key position in building a new product line from the ground up.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.