• Play a pivotal role in ensuring DuckDuckGo's security capabilities keep pace with rapid product development, directly protecting users across all products.
• Conduct browser security audits, execute SERP security mitigations, manage application security scanning infrastructure, and deliver internal red-team operations.
• Maintain incident detection and response capabilities for the company.
• Join a remote-first, profitable company of 300+ team members with $100M+ annual revenue and a culture of end-to-end project ownership.
📋 Job Requirements
• Bring 7+ years of experience in web or application security including security assessments, vulnerability research, penetration testing, or secure code review.
• Have advanced programming or scripting experience with JavaScript.
• Have experience with at least one WebView technology (WebKit, WebView2, Chromium WebView, etc.) and understand browser security models (SOP, CSP, CORS, SameSite cookies).
• Demonstrate hands-on experience identifying and exploiting web vulnerabilities such as XSS, CSRF, injection attacks, and authorisation flaws.
• Be familiar with security testing tools and frameworks.
• Have experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster.
• Have experience shaping how an organisation thinks about security — driving best practices, improving processes, and raising the bar across teams.
🌟 Nice-to-have
• Have additional experience with Swift, Kotlin, or C# for native app security.
• Bring experience with Perl or Go in a search infrastructure context.
• Have experience setting up SAST/DAST integrations in GitHub or similar CI/CD pipelines.
• Have conducted red-team operations or simulated attack scenarios in a consumer product environment.
🎯 Responsibilities
• Conduct browser security audits covering special pages, DuckAI integrations, password manager, and other browser components.
• Execute SERP security mitigations including XSS prevention and tooling development to help engineers write safer code.
• Manage application security scanning infrastructure setup including SAST/DAST integrations in GitHub.
• Deliver internal red-team operations through simulated attack scenarios.
• Support security triage across DuckDuckGo's products.
• Partner with Product Engineers to advise on security matters and help teams ship secure code faster.
• Drive security best practices and raise the bar across engineering teams.
About DuckDuckGo
😃 What DuckDuckGo offers
• Work fully remotely from anywhere.
• Receive transparent, flat compensation of $178,500 USD annually plus stock options — the same for all team members at the same professional level regardless of location.
• Take paid parental leave.
• Receive an office setup and co-working allowance.
• Travel at least twice a year for an all-hands meetup and a team retreat.
• Enjoy a flexible work arrangement with no core hours.
💖 What makes DuckDuckGo unique
DuckDuckGo is a remote-first online protection company of 300+ team members on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue exceeds $100M USD. Millions use their browser on Mac, Windows, iOS, and Android, their search engine, and the DuckDuckGo subscription. They also offer private, useful AI through Duck.ai, which lets users chat privately with ChatGPT, Claude, and other AIs in one place.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.