Your global R&D in one place
Senior Low-Level Security Engineer – Team Lead
Location
Poland
Posted
45 days ago
Salary
0
Seniority
Lead
Job Description
Senior Low-Level Security Engineer – Team Lead
Newxel
Role Description This is the first Linux Team Lead hire on the platform — you'll set the technical direction for Linux endpoint security, build the team from the ground up, and stay deeply hands-on in C/C++ at the kernel boundary. The Linux track is being established now; the architectural decisions are yours. What You'll Be Doing - Lead the design and development of low-level Linux security components in modern C++ (C++17/20) — both architecture decisions and personal contribution - Drive the technical direction for endpoint protection on Linux — eBPF programs, kernel modules, LSM integration, netfilter hooks, container isolation primitives - Build security-sensitive code that interacts with Linux internals: processes, memory, VFS, IPC, networking, namespaces, cgroups - Hire, mentor, and grow the Linux engineering team — code reviews, technical guidance, recruiting - Reverse-engineer and analyze attacker techniques on Linux, then translate them into detection and prevention - Reason about correctness, safety, and performance in multithreaded environments where failures are security failures - Participate in cross-platform architecture as macOS and Windows scopes evolve Qualifications - 7+ years of low-level systems or security engineering experience - Proven leadership or mentorship — formal Team Lead or staff/senior with hands-on team influence - Strong C/C++ in security- or systems-oriented production code - Deep Linux kernel internals: kernel architecture, system calls, VFS, networking stack, memory model - Hands-on eBPF programming experience (tracing, security enforcement, network filtering) - Kernel modules development - LSM hooks (SELinux, AppArmor, BPF-LSM) or netfilter / iptables integration - Namespaces, cgroups, and container isolation primitives - Strong multithreading, synchronization, and concurrency in security-critical environments - Reverse engineering and low-level analysis (IDA / Ghidra / GDB) - Assembly-level understanding (x86 or ARM) - Familiarity with exploit mitigations (ASLR, DEP, CFG) from a defensive perspective - English B2+ Nice to Have - Background in an antivirus, EDR, or endpoint security product — particularly Linux-focused (Falcon, Aqua, Sysdig, Datadog CWP, etc.) - Kernel vulnerability research, fuzzing, or static/dynamic analysis - seccomp, AppArmor profile authoring, or other Linux hardening primitives - Cross-platform systems experience: macOS (ESF, System Extensions) or Windows (WFP, kernel drivers) - Background in early-stage or deep-tech product environments Why This Role Is Worth Your Time - First Linux TL hire — you set the architectural direction, build the team, and own the track end-to-end - Real endpoint security problems: the threat model is attacker tradecraft, not compliance checkboxes - Hands-on TL — not a people manager removed from the code; you design, build, and grow the team in parallel - AI-first engineering culture — modern AI tooling integrated into daily engineering work
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Product Security Engineer
Origami RiskOrigami Risk is a leading provider of integrated risk, compliance, safety, healthcare, and P&C insurance SaaS solutions.
• Conduct advanced penetration testing and vulnerability assessments on our products and infrastructure. • Develop and deploy realistic attacks to test security defenses. • Develop and maintain security documentation, including policies, procedures, and guidelines. • Carry out controlled attacks to evade detection, simulate real-world attacks to exploit potential weaknesses. • Prepare and deliver technical reports to internal stakeholders • Perform vulnerability assessments, triage and provide prescriptive remediation for identified vulnerabilities • Assist in incident response and forensic analysis when security incidents occur. • Collaborate with development teams to integrate security best practices into the software development lifecycle. • Stay current on exploitation and post-exploitation techniques and incorporate them into the penetration testing
Lead Artificial Intelligence Cyber Security Engineer
Raymond JamesRaymond James is a diversified financial services holding company that was founded in 1962. The company provides financial services to corporations, municipalit
Title: Lead Artificial Intelligence Cyber Security Engineer Location: FL - Saint Petersburg - 880 Carillon Pkwy Tower 2 Job Description: Job Description Summary The financial services industry is constantly under attack by sophisticated cyber adversaries that range from nation-states to criminals. In response, the Raymond James Cyber Threat Center (CTC) is charged with ensuring all equities are secure against all tiers of adversaries. We are the central hub for Computer Network Operations and are on the front lines of security incident response, threat hunting, and intelligence. You'll be working with emerging technologies to solve challenging security problems in a fast-paced and continually evolving environment while helping steer the direction and evolution of the team. This highly visible team within the organization evaluates threats to the environment and dynamically adjusts to the ever-changing threat landscape by applying practical security knowledge to developing new detective measures to protect the firm. The Lead Artificial Intelligence Cyber Security Engineer (SOAR/AI), is a key member of the Cyber Threat Center (CTC) responsible for driving the design, development, and operationalization of AI-enabled security capabilities within the organization. This role applies artificial intelligence (AI), machine learning (ML), and large language models (LLMs) to enhance threat detection, automate decision-making, and enable advanced cybersecurity use cases such as anomaly detection, threat hunting, and autonomous incident response. In addition, the engineer establishes and guides enterprise standards, policies, and governance frameworks for the responsible use of AI in cybersecurity, including model lifecycle management, risk mitigation, and compliance considerations. The role also leverages strong orchestration expertise and experience with ServiceNow to build and integrate intelligent automation solutions, utilizing technologies such as JavaScript, HTML, CSS, AngularJS, REST, and SOAP to support and scale security operations across the enterprise. Job Description Job Description This position follows our hybrid workstyle policy: Expected to be in a Raymond James office location a minimum of 10-12 days a month. Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future. Essential Duties and Responsibilities: - Establish and guide enterprise standards for the responsible use of AI in cybersecurity, including governance, risk management, and compliance considerations. - Define and promote best practices for AI/ML model development, validation, deployment, and lifecycle management within security operations. - Develop, enhance, configure, and support ServiceNow Security Operations workflows, applications, integrations, forms, scripts, and custom artifacts. - Design, build, and maintain scalable automation solutions—including AI-enabled workflows—to improve threat detection, triage, and incident response efficiency. - Leverage Python programming and data science techniques to develop, operationalize, and optimize machine learning models and data-driven security use cases. - Develop and implement advanced data correlation, enrichment, and processing strategies leveraging automation, data science, AI/ML, and LLM capabilities for threat hunting and incident response analysis. - Apply AI engineering principles within security operations to design, deploy, and maintain intelligent detection and response capabilities. - Design and execute automated and intelligent response actions to validate, contain, eradicate, and remediate security incidents. - Architect, integrate, and operationalize AI and automation capabilities across security platforms and enterprise workflows. - Prototype, evaluate, and deploy emerging AI-driven technologies to enhance detection accuracy, reduce false positives, and accelerate response times. - Ensure Security Operations applications, automation pipelines, and incident ingestion processes remain healthy, resilient, and performant. - Drive continuous improvement by identifying gaps, recommending enhancements, and implementing innovative SOAR and AI-driven solutions. - Collaborate with incident response, threat intelligence, and threat hunting teams to strengthen detection and response capabilities. - Act as a technical SME and leader in SOAR and AI-driven cybersecurity, providing mentorship, strategic guidance, and continuously advancing technical expertise. Experience and Skills: - Experience should include a minimum of 6 years of programming experience with at least one modern language such as JavaScript or Python - Experience with API development and integration. - ServiceNow application and component development; Security Operations applications is preferred. - Experience in modern software engineering practices and principles, including AI/ML/GenAI, Agile methodologies and DevSecOps Licenses/Certifications: - One or more of the following certifications highly preferred: ServiceNow CSA, ServiceNow CAD, ServiceNow CIS-SIR, ServiceNow CIS-VR, CISSP, SANS GCIH (Incident Handler), SANS GCIA (Intrusion Analyst), Offensive Security Certified Professional (OSCP) Education Bachelor’s: Computer and Information Science, Bachelor’s: Information Technology, High School (HS) (Required) Work Experience General Experience - 6 to 10 years Certifications Travel Less than 25% Workstyle Hybrid The total compensation for this position includes base salary orwages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com. At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view. We expect our associates at all levels to: • Grow professionally and inspire others to do the same • Work with and through others to achieve desired outcomes • Make prompt, pragmatic choices and act with the client in mind • Take ownership and hold themselves and others accountable for delivering results that matter • Contribute to the continuous evolution of the firm At Raymond James – as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs. #LI-TC1
Security Engineer, Threat Detection & Response
AirbnbAirbnb is a community based on connection and belonging.
• Perform investigations of security incidents using your knowledge of digital forensics and data analytics. • Use your coding, data analytics and investigation skills to hunt, detect and respond to threats. • Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale. • Hunt for threats in our corporate and production environments to proactively identify anomalous activity. • Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with partner teams to carry out complex investigations. • Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection. • Collaborate well with cross-functional partner teams, such as Legal, Privacy, and Engineering for efficient, large-scale response.
• Build and evolve secure frameworks, guardrails, and library-level controls that make common vulnerability classes harder to introduce. • Design security controls for AI-assisted development — including reusable rule packs and skills that shape how engineers and coding agents generate, review, and ship code. • Embed security into the workflows engineers already use. • Drive product security reviews for new launches and major architectural changes. • Identify and eliminate systemic security debt. • Shape strategy, influence architecture, and drive execution across teams.




