CommIT is a pioneer in Active ASPM, dedicated to securing the modern software supply chain by identifying and mitigating critical risks. We are currently seeking a skilled Backend Engineer to join our Security Research group and build the systems that power our open-source intelligence operations.
Key responsibilities
- Build scalable scraping and ingestion pipelines for public package registries such as NPM and PyPI.
- Design and maintain robust distributed systems utilizing APIs, workers, queues, and databases.
- Develop advanced detection mechanisms for malicious install hooks, obfuscation techniques, and suspicious package behavior.
- Create and refine risk-scoring algorithms to effectively prioritize real-world threats.
- Collaborate closely with security researchers to transform prototypes into scalable production systems.
Requirements
- Over 5 years of professional backend development experience using Python, Node.js, or TypeScript.
- Proven hands-on experience in developing and managing large-scale scraping systems.
- Strong knowledge of distributed architectures, including PostgreSQL, Redis, and message queues.
- Practical production experience with Docker and container orchestration.
- Strong ownership mindset with the ability to work autonomously in a fully remote environment.
What we offer
- The opportunity to work on cutting-edge security technology in a highly autonomous role.
- A collaborative environment where you will directly influence the security of the software supply chain.
- Full remote flexibility, allowing you to contribute from anywhere.