Senior Web Security Engineer, Browser Platform
Posted 118ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Web Security Engineer at DuckDuckGo conducting security audits and managing application security. Collaborating with teams to enhance security practices and protect user data in web products.
Responsibilities:
- Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.)
- Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code)
- Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub)
- Deliver on Internal red-team operations (simulated attack scenarios)
- Support security triage
Requirements:
- 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)
- Advanced programming or scripting experience with JavaScript
- Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.)
- Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)
- Familiarity with security testing tools and frameworks
- Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster
- Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams
Benefits:
- paid parental leave
- office setup
- co-working allowances



















