The Role
We're looking for a full-stack software engineer / SRE hybrid to run ruthless triage and remediation of security vulnerabilities across legacy Java, Python, and JavaScript applications. Every vulnerability is flagged by Claude Mythos; this person owns each one end-to-end — triage, remediation options, hands-on code fixes, pipeline updates, and deployment — clearing it off the backlog. This is not feature work.
Must-Haves (Non-Negotiable)
Multi-language vulnerability remediation: hands-on, in-code fluency across Java, Python, and JavaScript — comfortable working inside legacy codebases you didn't write, across all three languages.
Proven CVE-to-deploy track record: has personally taken a vulnerability/CVE from flagged → triaged → remediated → deployed, including the dependency upgrades and resulting breakage that came with it.
Build/release + artifact pipeline depth: Jenkins, GitLab, Harness, Artifactory, ArgoCD — with real artifact-library ownership (versioning, promotion), not just triggering builds.
Solid Signals / Rarer Combos
Harness + ArgoCD (GitOps) together — an uncommon pairing; worth probing hard.
A legacy dependency upgrade that broke the build or app, and how they diagnosed and recovered from it.
Demonstrated comfort context-switching across Java, Python, and JavaScript remediation work within the same week.
What Success Looks Like
A steadily shrinking vulnerability backlog, with each item closed out from flag to production deploy — not just patched, but verified, pipelined, and shipped.
📌 Full Stack Engineer (India)
🏢 360 IDE
📍 India