cloud linux software, inc

Engineering Team Lead - Email Security (Imunify Email & Email Gateway)

The company is hiring remote specialists who have already relocated from Russia/Belarus.

cloud linux software, inc · На сервисе с: 17.08.26 12:28

Зарплата не указанаВесь мирУдалёнка

The company is hiring remote specialists who have already relocated from Russia/Belarus.

Description

CloudLinux is the maker of Imunify360 — a suite of security products protecting millions of websites across the web hosting industry. Our email security line covers both sides of the email problem for hosting providers: an inbound anti-spam engine integrated with hosting control panels, and an outbound SMTP gateway that protects sender reputation and keeps legitimate mail out of the spam folder.

We are looking for an Engineering Team Lead to run the team that builds and operates this product line. You will lead a small, senior, fully remote squad (currently 7–8 people: Go and Python engineers, a deliverability engineer, an anti-spam engineer, and data analysis/annotation) and be accountable for what the team ships, how reliably it runs, and how the people on it grow.

This is a hands-on lead role, not a pure people-management role. Expect roughly 60% leadership (delivery, technical direction, coaching, incident command) and 40% hands-on engineering (design reviews, code review, spikes, production debugging). You are not expected to be the top individual contributor on the team — you are expected to be able to read every part of the system and hold a credible technical opinion about it.

You don't need to arrive as an email expert. If you have led engineers in an adjacent technical domain — infrastructure, networking, security, messaging, anti-abuse — and have a track record of getting deep into complex technical territory fast, we will teach you the email side.

The system you would inherit

  • Inbound filtering: an Rspamd-based engine with a trained rule/ML model, released on a regular retraining cycle and measured on spam catch rate and false-positive rate.
  • Outbound gateway: a Halon-based SMTP relay with per-domain warm-up ladders, rate limiting, quarantine, feedback-loop (ARF) processing, and a customer portal — Go services on bare metal.
  • Panel integrations: cPanel/WHM, Plesk, DirectAdmin, plus Debian/Postfix deployments for large hosting partners.
  • Data plane: Elasticsearch, Redis, Grafana dashboards and alerting, corpus and annotation pipelines feeding model training.
  • Delivery: GitLab, Jenkins, Jira, a weekly release cadence, blameless post-mortems within 24 hours.

What you will own

Delivery:

  • Turn the product backlog into a credible, sequenced engineering plan — estimates, dependencies, and a release train the team actually hits.
  • Run the team's weekly cadence: planning, release readiness, status reporting with real numbers rather than adjectives.
  • Own engineering quality gates for model releases: no detection model ships without a measured catch rate and false-positive deltas against the previous model, and a rollback path.
  • Keep technical debt visible and funded — negotiate it into the roadmap rather than absorbing it silently.
  • Report delivery status and risk to engineering leadership weekly; every item carries an owner and a due date.

Technical direction:

  • Own the architecture of the email stack together with the architecture group: review designs, write and approve ADRs, and make build-vs-buy calls with explicit trade-offs.
  • Review code and designs on the critical path — mail flow, rate limiting, quarantine, authentication — and set the bar for tests, observability, and safe rollout.
  • Own production health: SLOs, alerting, capacity, and the deliverability posture of our sending infrastructure (IP reputation, SPF/DKIM/DMARC, rDNS, RBL listings).
  • Act as incident commander for product-impacting events: coordinate remediation across teams, keep partners informed, and author the post-mortem within 24 hours with named owners and dates.

People:

  • Lead a distributed team across the globe: 1:1s, goal setting, performance reviews, and career development.
  • Hire: define the profile, run technical interviews, onboard, and mentor engineers.
  • Set the working agreements that make async work — written decisions, public-by-default communication, durable artifacts over meetings.

AI-augmented engineering:

We evaluate engineers here partly on how effectively they work with coding agents. As the lead you are expected to model and coach this: prompt specificity, review quality on agent-generated code, tool-boundary awareness, context provision, iteration effectiveness, error recovery, and end-to-end task completion. The team has already scaffolded its repositories for agent-assisted development; extending that to the model and rule pipelines is live work.

Working with the Product Owner:

  • The Product Owner sets priorities, owns partner commitments and the roadmap narrative. You own the plan to deliver them and the technical risk in doing so.
  • Escalate scope-versus-capacity conflicts early and in writing, with at least two mitigation options.

First 90 days:

  • 30 days: Own the release train and the weekly status; be able to trace an inbound message and an outbound message end to end through the stack; complete 1:1s with every team member and produce a written read on the team's strengths and gaps.
  • 60 days: Own on-call and incident command for the product line; publish the current SLOs and the top three reliability risks with mitigations; land at least one non-trivial change yourself.
  • 90 days: Present a technical roadmap for the email stack agreed with the PO and the architecture group, including a debt-paydown line item and a staffing recommendation.

Requirements

Must have:

  • 5+ years as a software engineer, with 2+ years leading a team of engineers (team lead, tech lead with people responsibility, or engineering manager) in a product company.
  • Strong Linux proficiency at a software engineer (user) level; comfortable reading and reviewing production code in a modern high-level programming language (Python, Go, etc.), and debugging live systems on the box.
  • Track record of shipping and operating a distributed backend service under real production load — you have carried a pager and run incidents.
  • Experience mastering a complex technical domain quickly and making credible architectural decisions in it.
  • Practical fluency with observability and data tooling to judge quality yourself, not via reports (Grafana, Kibana/Elasticsearch, Redash or equivalents).
  • Demonstrated people leadership: 1:1s, performance conversations, hiring, and growing engineers.
  • Experience working in an agentic/AI-assisted development workflow.
  • Understanding of ML-driven systems, including model quality evaluation, training, and production operations.
  • Professional proficiency in English, written and spoken.
  • Availability to work EU hours.

Nice to have:

  • Working knowledge of email infrastructure: SMTP, SPF/DKIM/DMARC, rDNS, IP reputation and warm-up, RBLs, feedback loops.
  • Experience with open-source mail stacks — Rspamd, SpamAssassin, Postfix, Exim, Halon — or the web hosting ecosystem (cPanel/WHM and other control panels).
  • Exposure to the ML model lifecycle: training data quality, evaluation metrics, and the trade-offs in tuning detection systems.
  • Experience running incident and escalation management with external partners.

Benefits

What is in it for you

  • A focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours — schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leave.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • The opportunity to receive a reward for the most innovative idea that the company can patent.

Похожие вакансии Кибербезопасность

hh.ru
лига цифровой экономики

Инженер информационной безопасности

лига цифровой экономикиНа сервисе с: 12.08.26 13:45↑ Вакансия с автоподнятием
Зарплата не указанаРоссияМоскваОфис

Проекты по эксплуатации распределенной инфраструктуры гос. заказчиков в части обеспечения информационной безопасности

Твои задачи:

  • Администрирование и сопровождение средств защиты информации
  • Участие в процессе внутренней безопасности подразделения
  • Опыт работы с ОС семейства Windows и Linux
  • Будет плюсом опыт работы со средствами антивирусной защиты (например, Kaspersky), SIEM, системами контроля привилегированных пользователей (например, СКДПУ), реагирования на инциденты ИБ (например, R-Vision) и сканерами уязвимостей (например, MaxPatrol 8 / MaxPatrol VM).
  • Опыт работы с системами виртуализации (например, VMware/VirtualBox) и системами мониторинга (Zabbix или др.)
  • Знание актуальных техник и тактик кибератак, а также нормативной базы по ИБ (приказы ФСТЭК № 21, 117 и 239).
    Теоретические и практические знания сетевых технологий (TCP/IP, VLAN, Routing, Troubleshooting)
  • Навыки автоматизации процессов (написание скриптов, например Python и Bash)

Что мы обеспечим:

  • Технику для комфортной работы
  • ДМС, частичную компенсацию фитнеса, доступ к сервису корпоративных скидов, внутренние обучение и многое другое
  • Работу в профессиональной среде, состоящей из высококлассных экспертов, которая позволит тебе быстро расти как эксперту
  • Ежегодные сессии профессионального развития, результатом которой является план индивидуального развития каждого сотрудника и получение обратной связи
  • Сообщества по интересам: Лига Спорта, Лига Творчества, Лига Интеллекта и др., а также возможность организовать свое сообщество и получить поддержку от компании
Соц.сети
C
Зарплата не указанаРоссияМоскваГибрид

Руководитель группы дежурных аналитиков SOC

Локация: #Москва (гибрид)
Зарплата: ₽. Обсуждается на собеседовании.
Компания: ••••••••

Обязанности:
• Операционное управление сменой:

— Организация сдачи/приёмки дежурств
— Контроль укомплектованности и графика дежурств
— Распределение нагрузки между дежурными аналитиками
— Мониторинг и соблюдение KPI и SLA

• Управление инцидентами в зоне ответственности команды:
— Управление обработкой инцидентов в системе IRP и JiraSM
— Обеспечение эскалации инцидентов на команду CERT

• Работа с командой:
— Менторство и обучение команды L1
— Контроль метрик и качества работы дежурных аналитиков
— Распределение проектных задач и контроль за их выполнением
— Общее управление командой, проведение 1:1

• Коммуникации и отчётность:
— Формирование отчётностей по итогам смен
— Оперативное уведомление заинтересованных лиц об инцидентах
— Взаимодействие с другими подразделениями компании в своей зоне ответственности

• Технические и процессные задачи:
— Ведение базы знаний и документации подразделения
— Участие в создании контента SOC в своей зоне ответственности
— Тюнинг системы мониторинга, настройка исключений и фильтров

Требования:
• Глубокое понимание киберугроз, методов атаки и принципов работы сетей/систем
• Способность ясно мыслить и принимать решения при критических инцидентах
• Знание модели Kill Chain, фреймворка MITRE ATT&CK и цикла обработки инцидентов SANS Incident Response (SANS IR)

••••••••

#Гибрид

hh.ru
В

Специалист по информационной безопасности

винити ранНа сервисе с: 24.09.26 17:31
140k–160k ₽РоссияМоскваОфис
Обязанности:
  • организация категорирования объектов КИИ и актуализация результатов;

  • подготовка пакета организационно-распорядительных документов по защите информации (Приказ о назначении ответственных, Политика ИБ, Инструкции для администраторов и пользователей);

  • организация регистрации и реагирования на компьютерные атаки;

  • выдача УКЭП, МЧД, настройка работы в различных ГИС;

  • внедрение и эксплуатация программных и аппаратных средств информационной безопасности.

Требования:
  • высшее образование по специальностям «Информационная безопасность», «Компьютерная безопасность» или смежным техническим специальностям (информатика, вычислительная техника);
    - профессиональная переподготовка: наличие дипломов о профессиональной переподготовке по программам в области защиты информации (объем не менее 500 часов);
    - стаж в сфере обеспечения ИБ: от 3 лет.
    Опыт в организации защиты объектов КИИ или в государственных НИИ. Взаимодействие с регуляторами. Глубокое знание № 187-ФЗ, 149-ФЗ, 152-ФЗ, 63-ФЗ и др. Понимание категорирования объектов КИИ, разработки моделей угроз, создания Систем обнаружения атак.
  • Желательно наличие сертификатов: CISA, CISM, CISSP (международные); «Специалист по защите информации» (национальный стандарт).

Условия:
  • оформление по ТК РФ;

  • ежегодный оплачиваемый отпуск 28 дней;

    расположение: 5 мин. от м. Сокол;

    испытательный срок: 3 месяца;

    бесплатная парковка для сотрудников;

    полный соц. пакет.

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.