Himalayas logo
CloudLinuxCL

Malware Intelligence Analyst (worldwide remote, work anywhere)

CloudLinux provides a commercially supported operating system optimized for shared hosting providers and data centers, enhancing server stability, security, and resource management.

CloudLinux

Employee count: 201-500

Brazil only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Imunify360 Security Suite is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy-to-use solution with the six-layer approach to security delivers comprehensive and complete attack prevention.

Check out our website for more information about our Imunify360 product: https://www.imunify360.com/.

Imunify360 scanners clean millions of infected files and websites every month. Behind this number is a team of malware analysts who reverse-engineer threats, write detection signatures, and build the intelligence layer that protects hundreds of thousands of web servers from small WordPress sites to infrastructure giants.

We're growing the Malware Processing Team and hiring analysts to work across time zones as we move to 24/7 malware coverage. You'll dissect real-world web malware obfuscated PHP backdoors, JavaScript injections, SEO spam, cryptominers and turn your findings into detection rules that ship to production and protect millions of websites.

This is a fully remote position with a fixed schedule tailored to your time zone and preferences.


What You'll Do

  • Analyze and classify web malware: PHP shells, JavaScript injectors, WordPress backdoors, SEO spam, redirectors, cryptominers, and other threats targeting the hosting ecosystem
  • Reverse-engineer obfuscated PHP and JavaScript to understand attacker techniques and extract detection patterns
  • Write and refine PCRE-based detection signatures for our scanning engine precision matters, false positives erode customer trust
  • Maintain processing SLAs as part of a globally distributed team providing round-the-clock malware coverage
  • Research emerging threats new CMS exploitation techniques, supply-chain attacks on plugins/themes, zero-day delivery methods

Requirements

Must have:

  • Strong PCRE regex expertise, you understand anchors, non-capturing groups, performance implications, and can write complex patterns that are both accurate and efficient
  • 3+ years working with PHP and/or JavaScript, reading, understanding, and analyzing code (differentiate legitimate and malicious artifacts, no software engineering skills required)
  • Web malware reverse engineering, JS deobfuscation, PHP deobfuscation, unpacking encoded payloads
  • Understanding of web attack injection, XSS, RCE, file upload exploits, and how they manifest in hosting environments
  • Familiarity with web server and shared hosting architecture, Apache/Nginx/LiteSpeed, Reverse Proxy, PHP handlers, WAF, Namespaces, cgroups, Linux File system permissions.
  • English proficiency at upper-intermediate level or above.

Nice to have:

  • Experience with WordPress internals (themes, plugins, hooks)
  • Hands-on website cleanup or incident response experience
  • Penetration testing or red team background
  • Python scripting for automation and tooling
  • Experience with YARA rules or other signature formats
  • Familiarity with cPanel, Plesk, or DirectAdmin environments

We've intentionally broadened this list. If you bring strong analytical skills and a genuine curiosity about how malware works, but your background is in security research or adjacent fields rather than pure malware analysis, we want to hear from you. Our onboarding process and modern tooling will bridge the gaps.

Work Schedule

We operate a 24/7 malware processing pipeline with a 1-hour SLA. To make that sustainable and fair:

  • You'll work a standard 5-day week (5 on / 2 off) on a fixed schedule aligned with your time zone and preferences — no mandatory rotation.
  • Weekends and public holidays that fall within your schedule are compensated with either bonus payments or an extra vacation days.

Benefits

What's in it for you?

  • 5-day week (5 on / 2 off) on a fixed schedule aligned with your time zone.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves to ensure you maintain a healthy work-life balance.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • The opportunity to receive a reward for the most innovative idea that the company can patent, fostering a culture of creativity and innovation.

By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (https://cloudlinux.com/candidate-privacy-notice), which provides detailed information on how we maintain and handle your data.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Experience

3 years minimum

Location requirements

Hiring timezones

Brazil +/- 0 hours

About CloudLinux

Learn more about CloudLinux and their company culture.

View company profile

CloudLinux is dedicated to enhancing the security, stability, and profitability of Linux for hosting providers and data centers. With a collective experience of over 500 years in Linux, the company is transforming how these entities utilize the technology, extending its benefits to millions of their customers. CloudLinux boasts over 500,000 product installations and serves more than 4,000 customers, including prominent names like Liquid Web, 1&1, and Dell. The company merges profound technical expertise in hosting, kernel development, and open source with exceptional client care. Cloud Linux, Inc. was consolidated into Cloud Linux Software, Inc., which now operates under the TUXCARE trade name (DBA).

The core offering, CloudLinux OS, is specifically engineered for shared hosting environments. It isolates each tenant into a Lightweight Virtualized Environment (LVE), which partitions, allocates, and limits server resources such as CPU, memory, I/O, and the number of processes. This prevents any single user from monopolizing server resources and causing performance degradation or downtime for other users on the same server. This LVE technology is a key differentiator, ensuring a more stable and reliable hosting environment. CloudLinux OS also incorporates features like CageFS, a virtualized file system that encapsulates each user, preventing them from seeing each other's sensitive information or accessing server configuration files. This significantly enhances security in a multi-tenant setup. Furthermore, HardenedPHP ensures the security of the host system by automatically patching older and unsupported PHP versions. The OS is compatible with major control panels like cPanel, Plesk, and DirectAdmin, facilitating easier adoption and management for hosting providers. Beyond the operating system, CloudLinux has expanded its product portfolio with solutions like Imunify360, a comprehensive security suite for Linux web servers, and KernelCare, which provides automated, rebootless kernel patching. The company also initiated AlmaLinux OS, a free, open-source, community-driven enterprise-grade Linux distribution intended as a CentOS alternative, and continues to sponsor the AlmaLinux OS Foundation.

Employee benefits

Learn about the employee benefits and perks provided at CloudLinux.

View benefits

Competitive pay

CloudLinux offers competitive pay.

Paid vacation

Eligible staffers receive paid vacation.

Medical insurance

Eligible staffers receive medical insurance.

English sessions

CloudLinux offers English language sessions.

View CloudLinux's employee benefits
Claim this profileCloudLinux logoCL

CloudLinux

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

13 remote jobs at CloudLinux

Explore the variety of open remote roles at CloudLinux, offering flexible work options across multiple disciplines and skill levels.

View all jobs at CloudLinux

Remote companies like CloudLinux

Find your next opportunity by exploring profiles of companies that are similar to CloudLinux. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan