Security Backend Engineer

CommIT

Remote· senior

CommIT is hiring a Backend Engineer to join its Security Research group. You'll build the systems that power real intelligence work—ingesting data from package ecosystems like NPM and PyPI, monitoring them at scale, and catching malicious behavior. If you want to own projects end-to-end and see your code stop actual threats, this is a direct path.

You'll design scraping and ingestion pipelines, maintain distributed systems using APIs and databases, and develop detection mechanisms for malicious installs, embedded binaries, and suspicious package behavior. You'll also build risk-scoring algorithms to surface the critical threats that actually matter. Working closely with security researchers, you'll turn prototypes into production systems.

This role expects 5+ years of backend development with Python and/or Node.js/TypeScript. You should be comfortable building systems at scale and have experience with distributed architectures. A portfolio or GitHub showing your backend work will help your application stand out.

This is a remote position based in Poland. To apply, submit your resume and a brief note about what security or backend systems work interests you most. Apply directly through CareerJumpShip.

About this role

Description Company is the pioneer of Active ASPM, securing the modern software supply chain. We cut through alert noise to surface the critical 5% of risks that are truly reachable and exploitable. We're hiring a Backend Engineer for our Security Research group to build the systems thatpower our open-source intelligence work - ingesting public package ecosystems (NPM, PyPI),monitoring them continuously, and detecting malicious behavior at scale.This is a highly autonomous IC role where you’ll own projects end-to-end - transforming researcher prototypes into scalable production systems. Responsibilities: Build scalable scraping and ingestion pipelines for public package registries (NPM, PyPI, etc.) Design and maintain distributed systems based on APIs, workers, queues, and databases Develop detection mechanisms for: malicious install hooks, embedded binaries, obfuscation techniques, suspicious package behavior Build and improve risk-scoring algorithms to prioritize real threats Work closely with security researchers to productionize detection capabilities Requirements Requirements: 5+ years of backend development experience with Python and/or Node.js / TypeScript Hands-on experience with large-scale scraping systems Strong knowledge of distributed architectures: queues, workers, PostgreSQL, Redis Production experience with Docker / docker-compose Strong ownership mindset and ability to work autonomously Full professional English proficiency Strong Advantage: Malware analysis or reverse engineering experience Familiarity with ELF / PE / Mach-O formats Background in security research or software supply-chain security Originally posted on Himalayas

Ready to apply?

Similar remote openings sourced directly from company career pages.

Unlock CareerJumpShip

Pick a plan. Start applying.

Every plan unlocks the full product — cancel anytime.

Secured by Stripe · No hidden fees