Full-Time

Senior Software Developer

AI Agents & Integrations

JetBrains

JetBrains

1,001-5,000 employees

Develops IDEs and developer tools

No salary listed

Madrid, Spain + 1 more

More locations: Berlin, Germany

Hybrid

Hybrid role with flexible location; up to 30 days remote from abroad.

Category
Software Engineering (1)
Required Skills
Kotlin
Data Structures & Algorithms
Observability
REST APIs

Get referred to JetBrains

See people who can refer or advise you

Requirements
  • Comprehensive experience in professional software development, demonstrating the technical maturity required for senior engineering problems.
  • Strong programming skills in at least one modern backend language, with the readiness to work primarily in Kotlin.
  • A deep practical understanding of concurrent and asynchronous programming, including coroutines, threads, async I/O, and synchronization primitives.
  • A proven track record of building and shipping application workflows, third-party integrations, or service-backed logic.
  • Hands-on experience working with AI-assisted development tools, alongside an understanding of task orchestration, tool usage, and prompt context management.
  • A solid understanding of software engineering fundamentals, including data structures, debugging, observability, and test-driven development.
  • Fluency in written and spoken English for day-to-day technical collaboration across distributed teams.
Responsibilities
  • Design, implement, and develop the core product and business logic for agent-based developer workflows in Air.
  • Build deep integrations between Air product surfaces, external APIs, local CLIs, and AI coding agents.
  • Improve the end-to-end user experience for agents, covering setup, context handling, task execution, and failure recovery.
  • Write highly concurrent and asynchronous logic to manage multi-step agent interactions reliably.
  • Use AI agents and assistants in your daily development work to analyze their limitations and improve our workflows from firsthand experience.
  • Write clean, maintainable code, lead technical design discussions, and participate in peer code reviews.
  • Partner with distributed product and ML engineering teams to break down complex architectural problems.
Desired Qualifications
  • None

JetBrains builds a suite of developer tools, chiefly Integrated Development Environments (IDEs) for languages like Java, Python, JavaScript, .NET, and C/C++, plus related products for testing and project management. Their IDEs provide deep code understanding, smart editing, and refactoring to help programmers write and maintain software, and are sold via subscriptions (including an All Products Pack) with options for perpetual licenses and free Community Editions for some tools and non-commercial use. The company differentiates itself with a tightly integrated tool suite, language-agnostic support, strong refactoring capabilities, and a track record of popular products like IntelliJ IDEA and Kotlin, along with newer AI features and lightweight Fleet editor. JetBrains aims to help developers work more efficiently across multiple languages, ecosystems, and teams.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Amsterdam, Netherlands

Founded

2000

Get referred to JetBrains

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • On August 6, 2026, JetBrains shipped RustRover's Solana Anchor plugin.
  • On July 8, 2026, JetBrains launched the Kotlin Benchmark for AI coding agents.
  • On August 4, 2026, JetBrains marked Kotlin's 15th birthday and expanded BlueJ support.

What critics are saying

  • CISA added CVE-2026-63077 to KEV on August 6, 2026, forcing urgent TeamCity patching.
  • JetBrains fixed 18 vulnerabilities on July 23, 2026, exposing recurring supply-chain attack surface.
  • Another TeamCity RCE in July 2026 threatens enterprise build pipelines, secrets, and trust.

What makes JetBrains unique

  • JetBrains' IDEs embed deep semantic code understanding and refactoring across languages.
  • Kotlin, launched by JetBrains, anchors Android and multiplatform workflows in its ecosystem.
  • TeamCity, YouTrack, and AI governance tie coding, CI, planning, and review together.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Conference Attendance Budget

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Solana Compass
Aug 7th, 2026
JetBrains releases RustRover plugin for Solana Anchor smart contract development.

JetBrains releases RustRover plugin for Solana Anchor smart contract development. JetBrains released a Solana plugin for RustRover on August 6, giving JetBrains released the Solana (Experimental) plugin for its RustRover IDE on August 6, giving Solana SOL$75.97+3.0% Anchor smart contract developers a built-in transaction and account explorer, ending the routine of tabbing out to an external block explorer during development. Keep up to date with the Solana eco The plugin is available on JetBrains Marketplace and was developed by Alex (@alexlst1) from the JetBrains team. The official RustRover account announced the release on August 6 at 13:00 UTC. Account and transaction explorer replaces the external browser tab. Solana smart contracts are written in Rust, which makes RustRover a natural fit for Anchor development. Until now, inspecting what a contract actually did after a deploy or test meant leaving the editor to query an external explorer such as Solana Explorer or SolScan. The plugin closes that gap. Developers can track transactions and inspect the specific accounts involved, including their state and data, from inside an active RustRover session. Community responses to the announcement singled out the embedded account explorer as the main practical gain: one developer described having account state inspection built into the editor as a significant quality-of-life improvement for anyone who has spent time switching between an IDE and a block explorer to verify transaction results. Anchor deploys, toolchain setup, and local validator support. The plugin's explorer is the headline feature, but the toolchain integration goes further. Installation runs in a single step: the plugin configures all required Solana tools and dependencies inside RustRover automatically, replacing a manual CLI setup. Anchor deploys and smart contract tests run through standard IDE run configurations, keeping the full workflow inside the editor. Local development is also covered. The plugin works with local test validators, local wallets, and Surfpool environments. For developers who need to step through compiled BPF/sBPF program execution, the plugin works alongside the community-driven Solana Debugger project, which is building a graphical debugger for on-chain Solana programs. The plugin carries an "Experimental" label on JetBrains Marketplace. RustRover is JetBrains' standalone Rust IDE, separate from the Rust plugin available for IntelliJ IDEA. Solana Compass is an independent Solana analytics and staking platform, operating a validator on Solana mainnet since September 2021. Its network statistics and...

JetBrains
Aug 4th, 2026
Kodee's Kotlin roundup: birthday wishes, Shipaton 2026, and the new Kotlin AI benchmark.

Kodee's Kotlin roundup: birthday wishes, Shipaton 2026, and the new Kotlin AI benchmark. August 4, 2026 Hi everyone! July gave me plenty to celebrate: Kotlin turned 15, got its first public benchmark for AI coding agents, became available in BlueJ, and shipped its 2.4.10 release. Developers can also demonstrate their skills at RevenueCat Shipaton 2026 by building a Kotlin Multiplatform app and competing for the Ship Kotlin Everywhere Award. Meanwhile, X has rebuilt its Android app to be 100% Kotlin, marking another milestone for the language. Here's what stood out to me most over the past month: Kodee-approved spotlight. Kotlin turned 15: Leave a birthday wish. This one is close to my heart - Kotlin recently turned 15! To mark the milestone, JetBrains is inviting the whole community to celebrate. You can create a birthday postcard, upload a photo to party with me, and share a wish or a prediction for Kotlin's next chapter. Now is the perfect moment to look back at how far JetBrains has come - and to look ahead together. Ship Kotlin Everywhere Award at RevenueCat Shipaton 2026. Already know Kotlin? RevenueCat Shipaton 2026 is the perfect opportunity to turn your Kotlin skills into a new app. From August 1 to September 30, build and ship for Android, iOS, desktop, or web and compete for the Ship Kotlin Everywhere Award. Use the KMP starter guide to get your project up and running. To earn bonus points, you can help others by sharing your development journey. Shipping is impressive, but helping someone else is even better. The Kotlin Benchmark for AI coding agents. Kotlin now has its very own public benchmark for AI coding agents. It ranks agents on 105 real engineering tasks drawn from open-source Kotlin repositories, so you can compare them by resolution rate, token cost, and latency - and dig into the methodology behind the numbers. As AI becomes a bigger part of coding in Kotlin, I love that JetBrains finally have an open, Kotlin-specific way to measure what actually works. Kotlin 2.4.10 and Kotlin 2.4.20-Beta2. July brought the Kotlin 2.4.10 bug fix release, alongside Kotlin Kotlin 2.4.20-Beta2 with coroutine stack trace recovery, faster klib compilation, expanded Swift export, and an experimental compiler native image. Try the Beta version and share your feedback while the release is still taking shape. Kotlin comes to BlueJ. Kotlin support is now available in BlueJ 6.0 thanks to a collaboration between JetBrains and the BlueJ team at King's College London. Students can create, edit, compile, and run Kotlin code, inspect class diagrams, and interact with objects through BlueJ's familiar workflow. For educators, a new onboarding guide and ready-to-use materials make it easier to include Kotlin's concise syntax and null safety in introductory object-oriented programming courses. A conversation with the Golden Kodee winners. The first Golden Kodee Community Awards recognized Matheus Leandro Ferreira, Jaewoong Eum, Nicole Terc, Eeva-Jonna Panula, and Yinlong Liu for their contributions to education, online presence, creativity, positive societal impact, and in-person community building. Read their interviews and watch the video to discover practical advice on learning in public, starting small, and helping the community grow. Showcase your JetBrains IDE experience on LinkedIn. The free LinkedIn Connected Apps plugin lets you connect a supported JetBrains IDE to your LinkedIn profile. Once connected, a profile statement highlights how you use your IDE in practice, based on usage data that stays on your machine. As your development habits evolve, the statement updates automatically to reflect your experience. It is designed to showcase practical tool usage - not to rank developers or replace formal certification. How I came to life. I didn't always look like this! My journey began with a simple robot-inspired concept. Then, with the help of research, creativity, and community feedback, I evolved into the Kodee you know and love today. Check out my origin story (including how I got my name!). KMP library spotlight: Ktor, Koin, and Kermit. Finding the right KMP library shouldn't slow down your project. klibs.io brings together more than 4,100 Kotlin Multiplatform libraries, with filters for developers and AI integrations that give coding agents access to accurate, up-to-date library data. This month, JetBrains is spotlighting Ktor, Koin, and Kermit - a practical trio for networking, dependency injection, and logging. X rebuilds its Android app in 100% Kotlin. Built from scratch, X's Android app is now written entirely in Kotlin. X Chat also uses Kotlin Multiplatform across Android, iOS, and web for end-to-end encryption, storage, sync, and business logic. It's exciting to see Kotlin and Kotlin Multiplatform used at this scale.

Cryptika
Jul 31st, 2026
Critical JetBrains flaw allows attackers to execute malicious code remotely - update Now.

Critical JetBrains flaw allows attackers to execute malicious code remotely - update Now. Spread the love July 31, 2026 JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects all versions of TeamCity On-Premises. An attacker only requires HTTP or HTTPS access to a vulnerable TeamCity server to exploit this issue, with no need for a valid account, password, or prior access. According to JetBrains, the flaw resides in the TeamCity agent polling protocol. A remote attacker can use this protocol to bypass authentication checks and execute operating system commands with the same privileges as the TeamCity server process. This level of access poses serious risks for organizations that use TeamCity to manage software builds, releases, and CI/CD pipelines. A successful attack could expose stored credentials, configuration files, build data, and project secrets. Additionally, attackers could alter build settings, modify artifacts, or inject malicious code into downstream software releases. JetBrains vulnerability. JetBrains assigned the identifier CVE-2026-63077 to this issue after it was privately reported on July 10, 2026, by security researcher Antoni Tremblay through the company's coordinated disclosure process. The company has patched the vulnerability in TeamCity versions 2025.11.7 and 2026.1.3. Administrators are urged to download and install one of these versions immediately or use the built-in automatic update feature where available. For organizations that cannot upgrade immediately, a dedicated security patch plugin can be installed. This plugin supports TeamCity versions 2017.1 and later and specifically addresses CVE-2026-63077. However, JetBrains emphasizes that applying the plugin is only a temporary solution, as a full version upgrade also provides important security fixes. For users of TeamCity version 2024.03 and later, the platform can automatically download available security patch plugins and, when notifications are enabled, notify administrators. Security updates can be checked from the Administration menu under Updates and Available Security Updates. It's important to note that servers running TeamCity versions 2017.1 through 2018.1 will require a restart after installing the plugin. In contrast, TeamCity version 2018.2 and later can enable the patch plugin without restarting the server. JetBrains has confirmed that TeamCity Cloud customers do not need to take any action, as the company has already implemented protections in its cloud environments and found no evidence of exploitation of this flaw in TeamCity Cloud instances. At the time of this announcement, JetBrains indicated that it was unaware of any active exploitation in the wild. Nevertheless, the risk of unauthenticated remote code execution makes immediate remediation crucial. Administrators should also restrict TeamCity access to trusted networks, place internet-facing instances behind a VPN or another access control layer, and run the TeamCity service with minimal operating system privileges. Hosting TeamCity servers separately from build agents can further mitigate the impact of a potential compromise. Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now. July 28, 2026 JetBrains has urgently released security updates for a critical vulnerability in TeamCity On-Premises that could allow remote attackers to bypass authentication and execute arbitrary operating system commands. This vulnerability, tracked as CVE-2026-63077, affects all versions of TeamCity On-Premises. The company has addressed the issue in TeamCity versions... July 28, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" July 2, 2026 JetBrains has released security updates for a cluster of critical vulnerabilities that enable authentication bypass, account takeover, and remote code execution (RCE) across its on-premise ecosystem, including Hub, YouTrack, IntelliJ-based IDEs, Kotlin, GoLand, and TeamCity. These flaws put development and CI/CD environments at direct risk of compromise... July 2, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" Vulnerability exploits are the third most common way that cybercriminals gain access to target organizations, surpassed only by credential stealing and phishing in 2023. Once illicit access is achieved, intruders can launch ransomware attacks, exfiltrate sensitive data for sale in darknet forums or execute account takeovers, among an extensive array... April 30, 2024 In "Cybersecurity News - Original News Source is cybersecuritynews.com"

HOSUNG MACHINERY IND., CO., LTD
Jul 28th, 2026
Critical TeamCity flaw could let attackers run OS commands without logging in.

Critical TeamCity flaw could let attackers run OS commands without logging in. JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026. "If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains said. The flaw allows unauthenticated remote code execution via the agent polling protocol to sidestep authentication checks and achieve command execution. Depending on the privileges granted to the TeamCity server process, a successful compromise can lead to the exposure of TeamCity data, configurations, and stored credentials, or modification of server state. Besides releasing versions 2025.11.7 and 2026.1.3, JetBrains has released a security patch plugin for versions 2017.1+ so that customers who are unable to apply an update can still patch their environments. There is no evidence to indicate that the flaw has been exploited in the wild. "The security patch plugin will address only the vulnerability described above (CVE-2026-63077)," JetBrains cautioned. "We always recommend upgrading your server to the latest version to benefit from many other security updates." As best practices, customers are advised to consider requiring VPN connections or implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers. "Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities," it added. Found this article interesting? Follow hosang I.T on Google News, Twitter and LinkedIn to read more exclusive content hosang I.T post.

CYCON Security
Jul 25th, 2026
JetBrains patches critical vulnerabilities in IntelliJ IDEA and TeamCity.

JetBrains patches critical vulnerabilities in IntelliJ IDEA and TeamCity. Incident overview. JetBrains recently disclosed and patched a set of high-severity vulnerabilities affecting its core product suite, specifically the IntelliJ IDEA integrated development environment and the TeamCity CI/CD server. These flaws, which included critical remote code execution (RCE) vectors, were identified through internal security audits and vulnerability research programs. If left unpatched, these vulnerabilities would have allowed unauthenticated attackers to execute arbitrary code on servers, potentially leading to full system compromise. There is currently no public evidence of active exploitation in the wild, and JetBrains has released updated software versions to mitigate these risks immediately. The affected platforms are widely utilized in enterprise software development lifecycles, making the rapid deployment of these patches vital to maintaining internal developer environment security. Strategic implications. The compromise of CI/CD tools like TeamCity presents a significant 'supply chain' risk, as these systems possess deep integration into the software build pipeline and access to sensitive source code repositories and deployment secrets. For security teams, this incident highlights the necessity of securing development infrastructure with the same rigor as production environments. Long-term risks include the potential for threat actors to inject malicious code into software artifacts during the build process, which could result in downstream distribution of tainted applications. Organizations must consider the operational disruption of forced patching cycles and potential non-compliance with secure development frameworks, such as SSDF or SLSA. This event underscores that development toolchains are high-value targets for advanced persistent threats seeking long-term persistence and intellectual property theft. Critical insights. Security teams should prioritize the immediate identification and patching of all TeamCity and IntelliJ IDEA instances across the enterprise. It is essential to conduct a forensic review of server logs for anomalous administrative logins or unexpected process executions that may indicate prior exploitation attempts. Mitigation strategies should focus on applying official vendor patches, enforcing least-privilege access controls for CI/CD pipeline configurations, and restricting network exposure of management interfaces behind VPNs or zero-trust gateways. Beyond patching, organizations should implement robust monitoring for unauthorized configuration changes within build environments and initiate threat hunting for evidence of lateral movement. Future security postures should emphasize the 'code signing' of software artifacts to ensure build integrity even if the CI/CD pipeline is temporarily compromised, reinforcing a defense-in-depth approach to development operations.