DuckDuckGo logo
DuckDuckGo·

Senior Web Security Engineer, Browser Platform - DuckDuckGo

Who We Are

Hi, we're DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue now exceeds $100m USD and millions use our browser on Mac, Windows, iOS, and Android, our search engine, and the DuckDuckGo subscription. We also offer private, useful, and optional AI, including Duck.ai, which lets you chat privately with ChatGPT, Claude, and other AIs, all in one place. Our culture of trust, inclusivity, and empowered project management underpins everything we do, where each team member takes full ownership of their projects, from scoping and execution to postmortem.

Your Team and Role

Working on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, including our expanding AI offerings like Duck.ai and agentic browsing, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on related projects.

Recent Projects Include:

  • SERP security mitigations
  • Agentic browsing security mitigations
  • Agentic browser hardening
  • Browser and sync security audits

Key Responsibilities:

  • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code).
  • Manage application security scanning infrastructure setup.
  • Build and maintain harnesses that get security fixes out automatically.
  • Harden agentic browsing and DuckAI experiences against emerging threats like prompt injection.
  • Conduct browser and sync security audits (special pages, DuckAI integrations, password manager, etc.).
  • Deliver on internal red-team operations (simulated attack scenarios).
  • Support security triage and cross-functional advising.

About You

  • 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review).
  • Recent experience creating security-focused agentic harnesses.
  • Experience influencing large feature designs to have security built-in from the start.
  • Advanced programming or scripting experience with JavaScript. Additional experience with Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search) is a bonus.
  • Solid understanding of the web security model (such as the Same Origin Policy); experience with CSP, CORS, SameSite cookies, sec-fetch-*, CORB, CORP, Sanitizer API, and Trusted Types is beneficial.
  • Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.).
  • Familiarity with security testing tools and frameworks.
  • Experience partnering and collaborating with Product Engineers, advising on security matters, and helping teams ship secure code faster.
  • Experience shaping how an organization thinks about security—driving best practices, improving processes, and raising the bar across teams.

Compensation & Benefits

  • Base Salary: $178,500 USD annually + stock options.
  • Transparent Pay: All team members within the same professional level and global region receive the same compensation.
  • Health Benefits: Company-sponsored health benefits available to US-based team members.
  • Perks & Allowances: Paid parental leave, home office setup allowance, and co-working allowances.

Work Expectations

  • Flexible work arrangement with no core hours (~40 hours/week average commitment).
  • Required attendance at meetings on camera via video conferencing.
  • Company travel: Expect to travel at least twice per year (all-hands meetup and team retreat, each ~4-5 days).
  • Passing a background check is a condition of joining.

Culture

Async-friendly

Open to

Worldwide

Sign in to track applications and earn points.

More roles at DuckDuckGo

Similar remote roles