Author
This is some text inside of a div block.
Last Updated
This is some text inside of a div block.
Editorial Transparency
This is some text inside of a div block.

Head of Malware Research & Engineering (remote-only, Europe)

CloudLinux is a global remote-first company. We are driven by our principles: do the right thing, employees first, we are remote first, and we deliver high-volume, low-cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we all are successful.

Imunify360 Security Suite is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy-to-use solution with the six-layer approach to security delivers comprehensive and complete attack prevention.

We are seeking an experienced Engineering Leader to head the Cloud Antivirus Department at Imunify360, overseeing three specialized teams that form the core of Imunify's malware detection, analysis, and cloud scanning infrastructure. This role combines deep technical expertise in malware analysis and distributed systems with strong people management and strategic product vision.

The department is responsible for protecting millions of websites on shared hostings through the Imunify360/ImunifyAV product line, processing tens of millions of files through a cloud-based antivirus pipeline, and maintaining the malware signature lifecycle from creation to deployment.

Teams Under Management

  1. Malware Team — On-server malware scanning and detection stack: signature-based and heuristic scanners, real-time file monitoring, malware cleaner, signature server, release engineering and rollout.
  2. Cloud Antivirus (CloudAV) Team — Cloud-based malware analysis infrastructure: large-scale Airflow data processing cluster (24+ nodes), PHP emulator sandbox, automated signature generation, file classification pipelines, storage and hardware capacity planning.
  3. Malware Processing Team — Malware analysis operations: sample triage, signature creation, false negative/false positive remediation, ML-assisted classification, vendor integrations, and remediation tooling.

Key Responsibilities

Product & Strateg y

  • Introduce, own and constantly improve key metrics for antivirus products
  • Define and prioritize the product roadmap across all three teams
  • Drive product initiatives to achieve challenging key metrics
  • Collaborate with Product Management on VIP customer requirements and competitive analysis
  • Introduce more AI tools & instruments within malware detection lifecycle

Technical Leadership & Architecture

  • Own the end-to-end malware detection pipeline: from file ingestion through cloud analysis to on-server verdict delivery and cleanup

  • Drive architectural decisions for distributed data processing (Airflow DAGs, async Python, ClickHouse, MongoDB, Redis, Kafka)
  • Oversee migration and modernization initiatives (e.g., AI malware analysis, AI rules creation)
  • Design and implement performance optimizations for cloud processing throughput (10M+ brand new samples added daily)
  • Manage infrastructure capacity planning: compute nodes, Ceph storage clusters, database scaling

People Management

  • Lead 3 teams across multiple time zones
  • Hire, mentor, and grow engineers and team leaders for 3 teams
  • Coordinate cross-team dependencies with Server Team, Web Protection Team, QA, Infrastructure, and Support

Operational Excellence

  • Ensure signature release quality through automated testing pipelines
  • Monitor and improve detection rates, false positive rates, and cleanup success metrics
  • Respond to production incidents (certificate expiries, infrastructure failures, processing bottlenecks)
  • Manage vendor and partner technical integrations

Goals for the First 6 Months

  1. Understand the full pipeline end-to-end: from file ingestion from clients' servers, pipelines processing in the cloud, verdict delivery, and on-server scanning/cleanup
  2. Maintain momentum on active initiatives: e.g. Rust migration
  3. Establish relationships with cross-functional stakeholders (Server Team, Web Protection Team, Product, Support, Infrastructure)
  4. Identify and address the top 3 detection quality or infrastructure bottlenecks
  5. Define the department key metrics and start tightening them to excellence

About CloudLinux

CloudLinux is on a mission to make Linux secure, stable, and profitable, with over 500,000 product installations and 4,000 customers, including Liquid Web, 1&1, and Dell.
Apply Now