cover
Full Time

Group Manager, Imunify360 CloudAV (remote-only, Europe)/ 3 days ago

CloudLinux
Attractive
Application ends: 2026-04-19

Quick Summary

CloudLinux is seeking an Engineering Leader to head the Cloud Antivirus Department at Imunify360, a remote-only role within Europe. This position involves leading three teams focused on malware detection, analysis, and cloud scanning infrastructure, requiring deep technical expertise in malware analysis and distributed systems, coupled with strong people management and strategic product vision. Candidates must have 8+ years of software engineering experience, including 3+ years in a multi-team management role, and deep expertise in antivirus technologies. The role includes owning the end-to-end malware detection pipeline, driving architectural decisions for distributed data processing (Python, Airflow, Kafka, ClickHouse, MongoDB, Redis), and managing infrastructure at scale.

CloudLinux is a global remote-first company driven by principles of doing the right thing, prioritizing employees, and delivering high-volume, low-cost Linux infrastructure and security products. We foster a supportive team environment where everyone contributes to collective success.

Imunify360 Security Suite, a product of CloudLinux Inc., is the #1 OS in security and stability for hosting providers. Imunify is an innovative, automated, and easy-to-use security solution designed for shared and VPS/Dedicated servers, offering comprehensive attack prevention through a six-layer approach.

Engineering Leader, Cloud Antivirus Department at Imunify360

We are seeking an experienced Engineering Leader to head the Cloud Antivirus Department at Imunify360. This role oversees three specialized teams crucial to Imunify's malware detection, analysis, and cloud scanning infrastructure. It requires deep technical expertise in malware analysis and distributed systems, combined with strong people management and strategic product vision.

The department is responsible for protecting millions of websites on shared hostings via the Imunify360/ImunifyAV product line, processing tens of millions of files through a cloud-based antivirus pipeline, and managing the malware signature lifecycle from creation to deployment.

Teams Under Management

  • Malware Team: Focuses on on-server malware scanning and detection stack, including signature-based and heuristic scanners, real-time file monitoring, malware cleaner, signature server, release engineering, and rollout.
  • Cloud Antivirus (CloudAV) Team: Manages cloud-based malware analysis infrastructure, including a large-scale Airflow data processing cluster (24+ nodes), PHP emulator sandbox, automated signature generation, file classification pipelines, and storage/hardware capacity planning.
  • Malware Processing Team: Handles malware analysis operations such as sample triage, signature creation, false negative/false positive remediation, ML-assisted classification, vendor integrations, and remediation tooling.

Key Responsibilities

Product & Strategy

  • Introduce, own, and continuously improve key metrics for antivirus products.
  • Define and prioritize the product roadmap across all three teams.
  • Drive product initiatives to achieve challenging key metrics.
  • Collaborate with Product Management on VIP customer requirements and competitive analysis.
  • Introduce more AI tools and instruments within the malware detection lifecycle.

Technical Leadership & Architecture

  • Own the end-to-end malware detection pipeline: from file ingestion through cloud analysis to on-server verdict delivery and cleanup.
  • Drive architectural decisions for distributed data processing (Airflow DAGs, async Python, ClickHouse, MongoDB, Redis, Kafka).
  • Oversee migration and modernization initiatives (e.g., AI malware analysis, AI rules creation).
  • Design and implement performance optimizations for cloud processing throughput (10M+ brand new samples added daily).
  • Manage infrastructure capacity planning: compute nodes, Ceph storage clusters, database scaling.

People Management

  • Lead 3 teams across multiple time zones.
  • Hire, mentor, and grow engineers and team leaders for 3 teams.
  • Coordinate cross-team dependencies with Server Team, Web Protection Team, QA, Infrastructure, and Support.

Operational Excellence

  • Ensure signature release quality through automated testing pipelines.
  • Monitor and improve detection rates, false positive rates, and cleanup success metrics.
  • Respond to production incidents (certificate expiries, infrastructure failures, processing bottlenecks).
  • Manage vendor and partner technical integrations.

Goals for the First 6 Months

  • Understand the full pipeline end-to-end: from file ingestion from clients' servers, pipelines processing in the cloud, verdict delivery, and on-server scanning/cleanup.
  • Maintain momentum on active initiatives, such as Rust migration.
  • Establish relationships with cross-functional stakeholders (Server Team, Web Protection Team, Product, Support, Infrastructure).
  • Identify and address the top 3 detection quality or infrastructure bottlenecks.
  • Define the department key metrics and start tightening them to excellence.

Requirements

Must-Have

  • Past experience leading security products/labs with/researches.
  • 8+ years of software engineering experience, with 3+ years in a management role leading multiple teams.
  • Deep expertise in malware analysis and antivirus technologies: static/dynamic analysis, signature-based detection, heuristic engines, file classification.

Nice-to-Have

  • Strong background in distributed systems and data engineering: experience with workflow orchestration (Airflow, Luigi, or similar), message queues (Kafka, RabbitMQ), and large-scale data processing.
  • Experience with infrastructure at scale: managing compute clusters, storage systems (Ceph, S3), databases (ClickHouse, MongoDB, PostgreSQL, Redis).
  • Strong understanding of CI/CD pipelines: Jenkins, GitLab CI, containerized deployments (Docker).
  • Experience with monitoring and observability: Grafana, Sentry, log aggregation.
  • Experience in the web hosting security domain (cPanel, Plesk, shared hosting environments).
  • Background in machine learning applied to malware detection (transformers, LLMs for code analysis).
  • Experience with GCP (Secret Manager, Cloud Storage).
  • Familiarity with PHP internals and PHP emulation for dynamic analysis.
  • Track record of building and scaling cloud antivirus / threat intelligence platforms.
  • Experience managing geographically distributed teams.

Technical Stack

  • Languages: Python (primary), Rust, PHP, SQL
  • Orchestration: Apache Airflow, Celery, Redis
  • Databases: ClickHouse, MongoDB, PostgreSQL, Redis
  • Storage: Ceph, S3-compatible storage
  • Infrastructure: Bare metal (Atman DC), Nebula, Docker, GCP
  • CI/CD: Jenkins, GitLab
  • Monitoring: Grafana, Redash, Sentry

Benefits

  • Focus on professional development.
  • Interesting and challenging projects.
  • Fully remote work with flexible working hours, allowing you to schedule your day and work from any location worldwide.
  • Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves.
  • Compensation for private medical insurance.
  • Co-working and gym/sports reimbursement.
  • Budget for education.
  • Opportunity to receive a reward for the most innovative idea that the company can patent.

By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (https://cloudlinux.com/candidate-privacy-notice), which provides detailed information on how we maintain and handle your data.

Share

CloudLinux

CloudLinux

  • Address
    Warszawa, mazowieckie
View Profile
Your experience on this site will be improved by allowing cookies Cookie Policy