Senior Web Security Engineer, Browser Platform

DuckDuckGo $178.5K/year Posted 3 days ago

100% remote Worldwide · Worldwide (remote)

About the role

DuckDuckGo is the online protection company, a remote-first team of 300+ on a mission to raise the standard of trust online. Millions use its browser on Mac, Windows, iOS, and Android, its search engine, and Duck.ai, which lets you chat privately with multiple AIs in one place. Working on the Security Functional Team, you will play a pivotal role in ensuring security capabilities keep pace with rapid product development, including expanding AI offerings like Duck.ai and agentic browsing, directly protecting users across all products. Recent projects include browser and sync security audits, SERP security mitigations, and agentic browser hardening.

Responsibilities

  • Harden agentic browsing and Duck.ai experiences against emerging threats such as prompt injection.
  • Conduct browser and sync security audits covering special pages, Duck.ai integrations, the password manager, and more.
  • Execute SERP security mitigations, including XSS prevention and tooling that helps engineers write safer code.
  • Build and maintain harnesses that get security fixes out automatically.
  • Manage application security scanning infrastructure setup.
  • Deliver internal red-team operations and simulated attack scenarios.
  • Support security triage and help maintain incident detection and response capabilities for the company.

Qualifications

  • 7+ years of experience in web or application security, performing security assessments, vulnerability research, penetration testing, or secure code review.
  • Recent experience creating security focused agentic harnesses.
  • Experience influencing large feature designs to have security baked in from the start.
  • Advanced programming or scripting experience with JavaScript. Additional experience with Swift, Kotlin, C#, Perl, or Go is a bonus.
  • Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView) and a solid understanding of browser security models: SOP, CSP, CORS, SameSite cookies.
  • Hands-on experience identifying and exploiting web vulnerabilities such as XSS, CSRF, injection attacks, and authorization flaws.
  • Familiarity with security testing tools and frameworks.
  • Experience partnering with product engineers, advising on security matters, and raising the security bar across teams.

Skills

How to apply

Apply directly on the employer's application page. Your application goes straight to them.

Republished listing

This opportunity was discovered on DuckDuckGo's public careers page and is republished here for discovery purposes. Applications are handled by the employer.

DuckDuckGo team? Claim this listing or ask us to remove it.