duck-duck-go
New
$178.5K • Offers Equity/yr

Senior Web Security Engineer, Browser Platform

Remotefull-timesenior
EngineeringSecurity Engineer
0 views0 saves0 applied

Quick Summary

Requirements Summary

7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review) Advanced programming or scripting experience with JavaScript.

Technical Tools
csharpjavascriptkotlincode-reviewproject-management

Hi, we're DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue now exceeds $100m USD and millions use our browser on Mac, Windows, iOS, and Android, our search engine, and the DuckDuckGo subscription. Our culture of trust, inclusivity, and empowered project management underpins everything we do, where each team member takes full ownership of their projects, from scoping and execution to postmortem. If you're seeking end-to-end ownership of your work — you've come to the right place!

Working on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on general security related projects. Recent projects include:

  • Browser security audits

  • SERP security mitigations

As a Senior Web Security Engineer, Browser Platform, you'll conduct browser security audits (special pages, DuckAI integrations, password manager, etc.), execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code), manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub), and deliver on Internal red-team operations (simulated attack scenarios), support security triage, and more!

  • 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)

  • Advanced programming or scripting experience with JavaScript. Any additional experience with our stack is a bonus: Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search).

  • Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.) and understanding of browser security models (SOP, CSP, CORS, SameSite cookies)

  • Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)

  • Familiarity with security testing tools and frameworks

  • Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster

  • Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams

What We Offer

~1 min read

What We Offer

~1 min read

Hiring works best when it's a two-way street. Learn how we help you get to know DuckDuckGo, envision your future role here, and find out more about how we hire.

DuckDuckGo provides equal work opportunities to all team members and applicants, and it prohibits discrimination and harassment of any type on the basis of race, color, ethnicity, caste, religion, age, sex (including pregnancy), national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by our policies or federal, state, or local laws.

We want to ensure that our hiring process is accessible. If you need reasonable accommodation for any part of the application process because of a medical condition or disability, please send an email to careers@duckduckgo.com to let us know the nature of your request.

  • You’ll be required to attend meetings on camera via video conferencing

  • Expect to travel at least two times a year: once for our all-hands meetup and again for a team retreat (each around 4-5 days). While extenuating circumstances may impact attendance, everyone is strongly encouraged to attend.

  • While we offer a flexible work arrangement with no core hours, expect an average full-time commitment of 40 hours per week.

  • A successful candidate must pass a background check as a condition of joining the team.

  • By applying for this role, you confirm that all information submitted is accurate and complete. You further acknowledge that providing false or fraudulent information during the application process is cause for denial of an offer, revocation of any existing offer, or other adverse action, up to and including termination after the start of your commencement of work.

As part of our commitment to enhancing our recruitment process, we utilize artificial intelligence (AI) technology to assist in reviewing and summarizing job applications and test projects, including those tools integrated into our recruitment vendor platforms. We use AI to flag potentially fraudulent applications, analyze and summarize applicants’ experience, interviews, and project performance, and help streamline our selection process.

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location

Listing Details

Posted
May 4, 2026
First seen
May 6, 2026
Last seen
May 8, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
72%
Scored at
May 6, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

duck-duck-goSenior Web Security Engineer, Browser Platform$178.5K • Offers Equity