Senior Web Security Engineer, Browser Platform

Posted 118ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Web Security Engineer at DuckDuckGo conducting security audits and managing application security. Collaborating with teams to enhance security practices and protect user data in web products.

Responsibilities:

  • Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.)
  • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code)
  • Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub)
  • Deliver on Internal red-team operations (simulated attack scenarios)
  • Support security triage

Requirements:

  • 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)
  • Advanced programming or scripting experience with JavaScript
  • Experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.)
  • Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)
  • Familiarity with security testing tools and frameworks
  • Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster
  • Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams

Benefits:

  • paid parental leave
  • office setup
  • co-working allowances