Himalayas logo
CloudLinuxCL

Lead Application Security Engineer / DevSecOps Engineer (worldwide remote)

CloudLinux provides a commercially supported operating system optimized for shared hosting providers and data centers, enhancing server stability, security, and resource management.

CloudLinux

Employee count: 201-500

Georgia only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

CloudLinux is a global remote-first company. We are driven by our principles: do the right thing, employees first, we are remote first, and we deliver high-volume, low-cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we are all successful. We are truly a great place to work.

Check out our website for more information https://cloudlinux.com/

We are looking for a skilled Lead Application Security Engineer / DevSecOps Engineer who will play a key role in improving the security of our software products and driving best practices across the development lifecycle.

As a Lead Application Security Engineer / DevSecOps Engineer, you will:

  • Perform a security review of the company's external services.
  • Design and implement recommendations for security hardening.
  • Participate in all steps of SDLC as a security engineer.
  • Design and review new features to implement the Security by Design principle.
  • Call attention to risks and drive actions to address those risks to protect users.

Requirements

To be successful in this role, you should have:

  • Good technical knowledge and deep understanding of security, including but not limited to: web applications security (both backend and frontend), penetration testing, and modern security mechanisms.
  • Experience in assessing the security of Web applications (at least 3 years) and Binary applications.
  • Deep understanding of modern web technologies (OAuth, JWT, CORS, CSP, SOP, SameSite, etc.) and architectures.
  • Relevant education or a good understanding of information security and information technologies basics.
  • Experience coding/scripting in one or more general-purpose languages.
  • Deep understanding of Linux architecture and security stack.
  • Experience in binary vulnerabilities and exploitation.
  • At least an upper-intermediate level of English proficiency.

It would be a plus if you also have:

  • Experience in exploiting vulnerabilities found in the code.
  • Experience with code audits, code audit automation.
  • Experience in architecting, developing, or maintaining secure cloud solutions.
  • Experience in review of Docker/Kubernetes architectures.
  • Successful CTF or Bug Bounty participation will be a major plus.
  • Relevant certificates (OSCP, AWAE, CREST, GPEN) will be a major plus.

Benefits

What's in it for you?

  • A focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours, which allows you to schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • The opportunity to receive a reward for the most innovative idea that the company can patent.

By applying for this position, you agree with CloudLinux Privacy Policy (https://cloudlinux.com/legal/privacy-policies-hub/ ) and give us your consent to maintain and process your personal data with this respect. Please read our Privacy Policy for more information.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Location requirements

Hiring timezones

Georgia +/- 0 hours

About CloudLinux

Learn more about CloudLinux and their company culture.

View company profile

CloudLinux is dedicated to enhancing the security, stability, and profitability of Linux for hosting providers and data centers. With a collective experience of over 500 years in Linux, the company is transforming how these entities utilize the technology, extending its benefits to millions of their customers. CloudLinux boasts over 500,000 product installations and serves more than 4,000 customers, including prominent names like Liquid Web, 1&1, and Dell. The company merges profound technical expertise in hosting, kernel development, and open source with exceptional client care. Cloud Linux, Inc. was consolidated into Cloud Linux Software, Inc., which now operates under the TUXCARE trade name (DBA).

The core offering, CloudLinux OS, is specifically engineered for shared hosting environments. It isolates each tenant into a Lightweight Virtualized Environment (LVE), which partitions, allocates, and limits server resources such as CPU, memory, I/O, and the number of processes. This prevents any single user from monopolizing server resources and causing performance degradation or downtime for other users on the same server. This LVE technology is a key differentiator, ensuring a more stable and reliable hosting environment. CloudLinux OS also incorporates features like CageFS, a virtualized file system that encapsulates each user, preventing them from seeing each other's sensitive information or accessing server configuration files. This significantly enhances security in a multi-tenant setup. Furthermore, HardenedPHP ensures the security of the host system by automatically patching older and unsupported PHP versions. The OS is compatible with major control panels like cPanel, Plesk, and DirectAdmin, facilitating easier adoption and management for hosting providers. Beyond the operating system, CloudLinux has expanded its product portfolio with solutions like Imunify360, a comprehensive security suite for Linux web servers, and KernelCare, which provides automated, rebootless kernel patching. The company also initiated AlmaLinux OS, a free, open-source, community-driven enterprise-grade Linux distribution intended as a CentOS alternative, and continues to sponsor the AlmaLinux OS Foundation.

Employee benefits

Learn about the employee benefits and perks provided at CloudLinux.

View benefits

Competitive pay

CloudLinux offers competitive pay.

Paid vacation

Eligible staffers receive paid vacation.

Medical insurance

Eligible staffers receive medical insurance.

English sessions

CloudLinux offers English language sessions.

View CloudLinux's employee benefits
Claim this profileCloudLinux logoCL

CloudLinux

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

13 remote jobs at CloudLinux

Explore the variety of open remote roles at CloudLinux, offering flexible work options across multiple disciplines and skill levels.

View all jobs at CloudLinux

Remote companies like CloudLinux

Find your next opportunity by exploring profiles of companies that are similar to CloudLinux. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan