Remote job
Staff Software Engineer (Malware Detection)
Job details
About this role
Role overview A Staff Software Engineer is needed to lead the engineering of a shared malware scanning platform that evaluates every open source artifact before it reaches customers. Sitting in the critical path for libraries, containers, AI agent skills, and future product lines, the platform must deliver fast, accurate verdicts at enterprise scale. This is a backend and production-infrastructure role inside the security domain: the hire builds and operates the machinery that turns threat research into dependable detections, rather than performing the threat research itself.
Responsibilities - Build the measurement layer behind detection coverage and precision, including the pipelines, metrics, and dashboards used to steer the product. - Engineer a tight feedback loop with the threat research team so detection changes can be evaluated, tuned, and shipped in hours. - Own architecture for scan orchestration, verdict storage, and the APIs that every consuming product depends on, scaling the platform to new artifact types. - Build and scale the analysis engine, combining deterministic static analysis with AI-assisted reasoning over artifact contents. - Develop the APIs, services, and policy back-end that power how customers investigate, enforce, and appeal scanner findings at enterprise scale. - Operate the scanner as a critical-path production system: alerting, queue health, verdict-before-serve guarantees, and incident response.
Requirements - Multiple years building and operating production backend or infrastructure systems, with a clear record of staff-level technical leadership. - Strong Go experience, or deep backend systems experience with the ability to ramp quickly on Go. - Track record owning a highly technical platform or backend infrastructure that serves multiple products or internal customers. - Hands-on experience with high-throughput, event-driven pipelines where throughput, latency, and correctness must all be met simultaneously. - Solid grounding in software supply chain security, malware detection, vulnerability management, or adjacent security domains. - Comfort owning a metric such as false-positive rate, instrumenting it honestly, and driving it down despite ambiguous tradeoffs.
Nice to have - Experience with malware detection, static analysis, software composition analysis, or vulnerability scanning products. - Familiarity with ecosystems such as npm, PyPI, Maven, Go modules, or container registries, and with AI-assisted or regression-tested threat detection. - Background with sandboxing and dynamic analysis tools such as eBPF, gVisor, seccomp, or container isolation. - Comfort working across application and infrastructure layers, including cloud infrastructure and infrastructure-as-code tools like Terraform.
Benefits and work setup - Remote-first culture with team meetups, bi-annual destination summits, and a monthly stipend for coworking, phone, and internet costs. - Stock options granted on hire and promotion, with participation in secondary offerings and up to 10 years to exercise. - 100% employer-paid health, vision, and dental premiums for employees and dependents. - Flexible time off, 18 weeks paid leave for birthing parents, and 12 weeks for non-birthing parents.