DuckDuckGo logo

Senior Web Security Engineer, Browser Platform

DuckDuckGo

Remote · location unlistedFull-time$179K/yrPosted 9mo agoStill listed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$179K/yr
Location
Remote · location unlisted
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

DuckDuckGo is hiring a Senior Web Security Engineer, Browser Platform. DuckDuckGo is seeking a Senior Web Security Engineer for its Browser Platform to harden agentic browsing and AI experiences, conduct security audits, develop mitigations, and lead security best practices across its remote‑first product suite.

Key focus areas include Harden agentic browsing and DuckAI experiences against emerging threats, Conduct browser and sync security audits for special pages and integrations, and Execute SERP security mitigations such as XSS prevention and tooling development.

Successful candidates bring 7+ Years Web Or Application Security Experience and Pass Background Check. Important skills include Security Audits, Vulnerability Research, Penetration Testing, Secure Code Review, Creating Security Focused Agentic Harnesses, and Influencing Large Feature Designs For Security. Preferred (not required): Swift, Kotlin, C#, and Perl.

Skills & qualifications

RequiredNice to have

Skills

Security AuditsVulnerability ResearchPenetration TestingSecure Code ReviewCreating Security Focused Agentic HarnessesInfluencing Large Feature Designs for SecurityJavaScriptWebKitWebView2Chromium WebViewBrowser Security ModelsSOPCSPCORSSameSite CookiesIdentifying Web VulnerabilitiesExploiting Web VulnerabilitiesXSSCSRFInjection AttacksAuthorization FlawsSecurity Testing ToolsSecurity Testing FrameworksPartnering With Product EngineersAdvising on Security MattersShipping Secure CodeDriving Security Best PracticesImproving Security ProcessesSwiftKotlinC#PerlGo

Qualifications

7+ Years Web or Application Security ExperiencePass Background Check

Benefits

Medical Insurance
Parental Leave

Full job description

Who We Are Hi, we're DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue now exceeds $100m USD and millions use our browser on on Mac , Windows , iOS , and Android , our search engine , and the DuckDuckGo subscription . We also offer private, useful, and optional AI, including Duck.ai , which lets you chat privately with ChatGPT, Claude, and other AIs, all in one place. Our culture of trust, inclusivity, and empowered project management underpins everything we do, where each team member takes full ownership of their projects, from scoping and execution to postmortem. If you're seeking end-to-end ownership of your work, you've come to the right place!

Your Team and Role Working on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, including our expanding AI offerings like Duck.ai and agentic browsing, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on related projects. Recent projects include:

  • Browser and sync security audits

  • SERP security mitigations

  • Agentic browser hardening

As a Senior Web Security Engineer, Browser Platform , you'll harden our agentic browsing and DuckAI experiences against emerging threats (like prompt injection), conduct browser and sync security audits (special pages, DuckAI integrations, password manager, etc.), execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code), build and maintain harnesses that get security fixes out automatically, manage application security scanning infrastructure setup, deliver on internal red-team operations (simulated attack scenarios), support security triage, and more!

About You

  • 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)

  • Recent experience creating security focused agentic harnesses

  • Experience influencing large feature designs to have security baked in from the start

  • Advanced programming or scripting experience with JavaScript. Any additional experience with our stack is a bonus: Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search).

  • Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.) and understanding of browser security models (SOP, CSP, CORS, SameSite cookies)

  • Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)

  • Familiarity with security testing tools and frameworks

  • Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster

  • Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams

Compensation $ 178,500 USD annually and stock options. Compensation is transparent across the organization, and all team members within the same professional level and global region receive the same compensation.

Eligibility for company-sponsored health benefits is limited to team members based in the United States. This program does not extend to team members located in other countries, such as Canada or the UK.

Our Team Member Support Guide explains how we prioritize your wellbeing including paid parental leave, office setup, and co-working allowances.

Hiring Process Hiring works best when it's a two-way street. Learn how we help you get to know DuckDuckGo, envision your future role here, and find out more about how we hire .

Diversity, Equity and Inclusion DuckDuckGo provides equal work opportunities to all team members and applicants , and it prohibits discrimination and harassment of any type on the basis of race, color, ethnicity, caste, religion, age, sex (including pregnancy), national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by our policies or federal, state, or local laws.

We want to ensure that our hiring process is accessible. If you need reasonable accommodation for any part of the application process because of a medical condition or disability, please send an email to [email protected] to let us know the nature of your request.

Please note that:

  • You’ll be required to attend meetings on camera via video conferencing

  • Expect to travel at least two times a year: once for our all-hands meetup and again for a team retreat (each around 4-5 days). While extenuating circumstances may impact attendance, everyone is strongly encouraged to attend.

  • While we offer a flexible work arrangement with no core hours, expect an average full-time commitment of 40 hours per week.

  • A successful candidate must pass a background check as a condition of joining the team.

  • By applying for this role, you confirm that all information submitted is accurate and complete. You further acknowledge that providing false or fraudulent information during the application process is cause for denial of an offer, revocation of any existing offer, or other adverse action, up to and including termination after the start of your commencement of work.

Disclosure Statement: Use of AI in Hiring Process

As part of our commitment to enhancing our recruitment process, we utilize artificial intelligence (AI) technology to assist in reviewing and summarizing job applications and test projects, including those tools integrated into our recruitment vendor platforms. We use AI to flag potentially fraudulent applications, analyze and summarize applicants’ experience, interviews, and project performance, and help streamline our selection process.

Key Principles:

  • Data Privacy: All information provided in your application will be handled in accordance with our Recruiting Privacy Policy . We ensure that your personal information is protected and used solely for recruitment purposes.

  • Human Oversight and Accountability: The AI technology is designed to support our hiring team by providing insights and summaries of applications and evaluations of test projects against scoring rubrics. All final evaluations and hiring decisions, however, will be made by our hiring team, who will consider the AI's input alongside other factors.

  • Transparency: We believe in transparency regarding our hiring practices. If you have any questions about how AI is used in our recruitment process, please feel free to reach out to us.

By submitting your application, you acknowledge and consent to the use of AI technology in our review process. If you would like to request an alternative selection process, please contact us as at [email protected] . Thank you for your interest in joining DuckDuckGo!

#LI-DNI

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.