Langsung ke konten utama
Kembali ke Lowongan

Senior Web Security Engineer, Browser Platform

Tingkatkan keamanan browser dengan audit dan mitigasi kerentanan

Lakukan audit keamanan browser dan mitigasi kerentanan pada SERP, serta kelola integrasi pemindaian keamanan aplikasi di GitHub

Kenapa Menarik?

Bekerja dengan tim keamanan fungsional untuk melindungi pengguna di semua produk

Skills Wajib

Web SecurityJavaScriptWebView TechnologyBrowser Security Models

Keywords

Keamanan WebAudit KeamananMitigasi KerentananIntegrasi SAST/DASTRed Team Operations
Lihat Deskripsi Asli dari 4dayweek.io

Deskripsi asli dari 4dayweek.io

## **Who We Are** Hi, we're DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue now exceeds $100m USD and millions use our browser on [Mac](https://spreadprivacy.com/introducing-duckduckgo-for-mac/), [Windows](https://spreadprivacy.com/windows-browser-open-beta/), [iOS](https://spreadprivacy.com/duckduckgo-privacy-browser-ios14/), and [Android](https://spreadprivacy.com/introducing-app-tracking-protection/), our [search engine](https://duckduckgo.com/), and the [DuckDuckGo subscription](https://duckduckgo.com/pro). Our [culture](https://duckduckgo.com/how-we-work) of trust, inclusivity, and empowered project management underpins everything we do, where each team member takes full ownership of their projects, from scoping and execution to postmortem. If you're seeking end-to-end ownership of your work — you've come to the right place! ## **Your Team and Role** Working on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on general security related projects. Recent projects include: - Browser security audits - SERP security mitigations As a **Senior Web Security Engineer, Browser Platform**, you'll conduct browser security audits (special pages, DuckAI integrations, password manager, etc.), execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code), manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub), and deliver on Internal red-team operations (simulated attack scenarios), support security triage, and more! ## **About You** - 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review) - Advanced programming or scripting experience with JavaScript. Any additional experience with our stack is a bonus: Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search). - Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.) and understanding of browser security models (SOP, CSP, CORS, SameSite cookies) - Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.) - Familiarity with security testing tools and frameworks - Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster - Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams ## **Compensation** **$** _**178,500**_ **USD annually** and stock options. Compensation is [identical within professional levels](https://duckduckgo.com/how-we-work), regardless of geographic location or team. Compensation for each professional level is transparent across the organization. Our [Team Member Support Guide](https://duckduckgo.com/assets/hiring/team_support_guide.pdf) explains how we prioritize your wellbeing including **paid parental leave, office setup,** and **co-working allowances.** ## **Hiring Process** Hiring works best when it's a two-way street. Learn how we help you get to know DuckDuckGo, envision your future role here, and find out more about [how we hire](https://duckduckgo.com/how-we-hire). ## **Diversity, Equity and Inclusion** DuckDuckGo provides equal work opportunities to all team members and applicants, and it prohibits discrimination and harassment of any type on the basis of race, color, ethnicity, caste, religion, age, sex (including pregnancy), national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity

Lamar gratis

Akun gratis · tanpa kartu kredit · Masuk

Pro Rp39rb/bln · lamar tanpa batas + resume AI

Perusahaan
DuckDuckGo
Sumber
4dayweek.io
Gaji
$XX,XXX
Tipe Pekerjaan
full time
Lokasi
Worldwide Remote · Remote
Kategori
Engineering
Level
senior
Diposting
8 Apr 2026

Bagikan lowongan ini

Bantu temanmu nemu kerja remote berikutnya.

Lamar gratis

Akun gratis · tanpa kartu kredit · Masuk

Pro Rp39rb/bln · lamar tanpa batas + resume AI