Group Lead, Malware Research & Engineering (remote-only, Europe)
CloudLinux Vezi toate joburile
- București
- Permanent
- Full-time
- Cloud Antivirus (CloudAV) Team — Cloud-based malware analysis infrastructure: large-scale Airflow data processing cluster (24+ nodes), PHP emulator sandbox, automated signature generation, file classification pipelines, storage and hardware capacity planning.
- Malware Processing Team — Malware analysis operations: sample triage, signature creation, false negative/false positive remediation, ML-assisted classification, vendor integrations, and remediation tooling.
- Introduce, own and constantly improve key metrics for antivirus products
- Define and prioritize the product roadmap across all three teams
- Drive product initiatives to achieve challenging key metrics
- Collaborate with Product Management on VIP customer requirements and competitive analysis
- Introduce more AI tools & instruments within malware detection lifecycle
- Own the end-to-end malware detection pipeline: from file ingestion through cloud analysis to on-server verdict delivery and cleanup
- Drive architectural decisions for distributed data processing (Airflow DAGs, async Python, ClickHouse, MongoDB, Redis, Kafka)
- Oversee migration and modernization initiatives (e.g., AI malware analysis, AI rules creation)
- Design and implement performance optimizations for cloud processing throughput (10M+ brand new samples added daily)
- Manage infrastructure capacity planning: compute nodes, Ceph storage clusters, database scaling
- Lead 3 teams across multiple time zones
- Hire, mentor, and grow engineers and team leaders for 3 teams
- Coordinate cross-team dependencies with Server Team, Web Protection Team, QA, Infrastructure, and Support
- Ensure signature release quality through automated testing pipelines
- Monitor and improve detection rates, false positive rates, and cleanup success metrics
- Respond to production incidents (certificate expiries, infrastructure failures, processing bottlenecks)
- Manage vendor and partner technical integrations
- Maintain momentum on active initiatives: e.g. Rust migration
- Establish relationships with cross-functional stakeholders (Server Team, Web Protection Team, Product, Support, Infrastructure)
- Identify and address the top 3 detection quality or infrastructure bottlenecks
- Define the department key metrics and start tightening them to excellence
- Past experience leading security products / labs with / researches
- 8+ years of software engineering experience, with 3+ years in a management role leading multiple teams
- Deep expertise in malware analysis and antivirus technologies: static/dynamic analysis, signature-based detection, heuristic engines, file classification
- Strong background in distributed systems and data engineering: experience with workflow orchestration (Airflow, Luigi, or similar), message queues (Kafka, RabbitMQ), and large-scale data processing
- Experience with infrastructure at scale: managing compute clusters, storage systems (Ceph, S3), databases (ClickHouse, MongoDB, PostgreSQL, Redis)
- Strong understanding of CI/CD pipelines: Jenkins, GitLab CI, containerized deployments (Docker)
- Experience with monitoring and observability: Grafana, Sentry, log aggregation
- Experience in the web hosting security domain (cPanel, Plesk, shared hosting environments)
- Background in machine learning applied to malware detection (transformers, LLMs for code analysis)
- Experience with GCP (Secret Manager, Cloud Storage)
- Familiarity with PHP internals and PHP emulation for dynamic analysis
- Track record of building and scaling cloud antivirus / threat intelligence platforms
- Experience managing geographically distributed teams
- Languages: Python (primary), Rust, PHP, SQL
- Orchestration: Apache Airflow, Celery, Redis
- Databases: ClickHouse, MongoDB, PostgreSQL, Redis
- Storage: Ceph, S3-compatible storage
- Infrastructure: Bare metal (Atman DC), Nebula, Docker, GCP
- CI/CD: Jenkins, GitLab
- Monitoring: Grafana, Redash, Sentry
- A focus on professional development.
- Interesting and challenging projects.
- Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide.
- Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
- Compensation for private medical insurance.
- Co-working and gym/sports reimbursement.
- Budget for education.
- The opportunity to receive a reward for the most innovative idea that the company can patent.