Skip to content
DuckDuckGoDuckDuckGo

Senior Web Security Engineer, Browser Platform

Conducts browser security audits, implements SERP mitigations like XSS prevention, manages SAST/DAST infrastructure, and leads red-team operations. Requires 7+ years in web security, advanced JavaScript, WebView experience, and vulnerability exploitation skills.

About the job

Responsibilities

  • Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.)
  • Execute SERP security mitigations (XSS prevention, tooling development to help engineers write safer code)
  • Manage application security scanning infrastructure setup (SAST/DAST integrations in GitHub)
  • Deliver internal red-team operations (simulated attack scenarios)
  • Support security triage and incident detection/response
  • Work on general security related projects

Requirements

  • 7+ years of experience in web or application security (security assessments, vulnerability research, penetration testing, secure code review)
  • Advanced programming or scripting experience with JavaScript
  • Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView) and understanding of browser security models (SOP, CSP, CORS, SameSite cookies)
  • Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws)
  • Familiarity with security testing tools and frameworks
  • Experience partnering with Product Engineers, advising on security matters

Nice-to-Haves

  • Experience with stack: Swift, Kotlin, C#, JavaScript (native apps), JavaScript, Perl, Go (search)
  • Experience shaping organization-wide security best practices and processes

Compensation

  • $178,500 USD annually and stock options

Skills

JavaScript, Webkit, Webview2, Chromium Webview, Sop, Csp, Cors, Samesite Cookies, Xss, Csrf, SAST, DAST, GitHub, Penetration Testing, Vulnerability Research

Virta Health

Virta Health

United States

DevSecOps Engineer
$179k+/yrRemote7+ YOESecurity Engineering

Build and mature Virta’s application security program by securing GCP and Kubernetes environments, automating vulnerability and compliance processes, and embedding security across engineering. The role requires 5–7+ years of experience, strong cloud and application security expertise, and proficiency with Terraform and Go or Python.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Valon

Valon

United States

Senior Security Engineer, Threat & Offensive Security
$180k+/yrRemote5+ YOESecurity Engineering

Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.

Anyscale

Anyscale

India
Senior Product Security Engineer
$180k+/yrOn-site8+ YOESecurity Engineering

Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.

Anyscale

Anyscale

San Francisco, CA

Compliance Manager
$180k+/yrOn-site7+ YOESecurity Engineering

Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.