DuckDuckGo is seeking a Senior Web Security Engineer, Browser Platform to join their remote-first team. The role involves conducting browser security audits, executing on SERP security mitigations, and managing application security scanning infrastructure setup. The ideal candidate will have 7+ years of experience in web or application security, advanced programming or scripting experience with JavaScript, and experience with at least one WebView technology.
Requirements
- 7+ years of experience in web or application security
- Advanced programming or scripting experience with JavaScript
- Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.)
- Understanding of browser security models (SOP, CSP, CORS, SameSite cookies)
- Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)
- Familiarity with security testing tools and frameworks
- Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster
- Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams
Benefits
- Paid parental leave
- Office setup
- Co-working allowances
