Security Engineer - Node.js Proactive Defense
Jobgether · Mexico
Internet Marketplace Platforms · 11-50 employees
About the role
Design and build a new security product line focused on runtime protection for Node.js environments from the ground up. Establish detection methodologies to distinguish malicious activity from legitimate behavior using large-scale threat intelligence.
What they look for
Requirements
Requires strong experience with the Node.js runtime, JavaScript ecosystem, and web application security principles. Candidates should be capable of operating independently to design scalable detection logic and manage product architecture.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer - Node.js Proactive Defense based in Mexico.
We are looking for a highly autonomous Security Engineer to build a new generation of runtime protection for Node.js applications.This role offers the opportunity to create a product from the ground up, combining security research, engineering, and product ownership.You will design and implement solutions that protect modern web applications against evolving threats without requiring customer intervention.Working at the intersection of application security, malware detection, and runtime instrumentation, you will have ownership over both strategy and execution.You will leverage large-scale threat intelligence, modern engineering tools, and AI-assisted workflows to build impactful security capabilities.This is a hands-on role for someone who thrives in ambiguity, enjoys solving complex problems, and wants to make a measurable impact on web security.
\n
Accountabilities:
- Define and build a new security product line focused on runtime protection within Node.js environments.
- Determine the technical strategy, including instrumentation methods, deployment models, programming language choices, and detection approaches.
- Design, develop, test, and iterate on the complete solution from concept through production deployment.
- Establish detection methodologies to distinguish malicious activity, vulnerabilities, and legitimate application behavior across diverse frameworks and libraries.
- Use large-scale security intelligence, including malware data, reputation signals, and threat feeds, to improve protection capabilities.
- Optimize the product against key security and business metrics, including runtime performance, false positives, false negatives, and customer impact.
- Collaborate with security specialists, architects, and engineering teams while maintaining ownership of technical direction and execution.
- Leverage AI-assisted development tools and modern engineering practices to accelerate delivery and improve quality.
- Monitor real-world customer telemetry and continuously improve detection logic and protection mechanisms.
Requirements:
- Strong experience with the Node.js runtime and JavaScript ecosystem.
- Solid understanding of web application security principles and current exploitation techniques.
- Ability to design detection logic that works reliably at scale while minimizing false positives.
- Experience building security tools, application protection solutions, runtime security products, or related engineering systems.
- Strong problem-solving skills and the ability to operate independently in a fast-moving environment.
- Ability to take ownership of product direction, architecture, engineering execution, and quality assurance.
- Comfortable working as a hands-on technical owner rather than only managing specifications or reviews.
- Experience using AI coding assistants and modern development workflows is a plus.
- Background in malware analysis, incident response, managed hosting environments, vulnerability research, or security research is highly valued.
- Experience publishing security research, creating vulnerability disclosures, or developing detection rulesets is a plus.
Benefits:
- Fully remote work environment with flexible working hours and the ability to work from anywhere worldwide.
- Opportunity to work on challenging security projects with direct impact on protecting modern web infrastructure.
- Strong focus on professional growth and continuous development.
- Paid annual vacation, public holidays, and flexible sick leave policy.
- Support for private medical insurance.
- Reimbursement support for co-working spaces and sports or wellness activities.
- Dedicated learning and education budget.
- Opportunity to be recognized and rewarded for innovative ideas and patented solutions.
- Access to modern engineering tools and resources to support high-impact development.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1