DuckDuckGo logo
DuckDuckGo

Senior Web Security Engineer, Browser Platform

Posted on 22 September 2026

About the role

💼 What you will do

• Join DuckDuckGo, the online protection company, in a full-time remote-first role. • Work on the Security Functional Team, keeping security capabilities in step with rapid product development. • Protect users across the browser, search and expanding AI offerings such as Duck.ai and agentic browsing. • Harden agentic browsing experiences against emerging threats such as prompt injection. • Maintain incident detection and response capabilities for the company. • Run internal red-team operations and security audits. • Earn $178,500 a year plus stock options, on a transparent pay scale.

📋 Job Requirements

• Bring 7+ years of experience in web or application security, covering assessments, vulnerability research, penetration testing or secure code review. • Show recent experience creating security-focused agentic harnesses. • Bring experience influencing large feature designs so security is built in from the start. • Write advanced JavaScript, with programming or scripting depth. • Understand the web security model, including the Same Origin Policy. • Identify and exploit web vulnerabilities such as XSS, CSRF, injection attacks and authorization flaws. • Bring familiarity with security testing tools and frameworks. • Partner with product engineers, advising on security and helping teams ship secure code faster. • Shape how an organisation thinks about security by driving best practices and raising the bar. • Attend video meetings on camera and travel twice a year for the all-hands and a team retreat.

🌟 Nice-to-have

• Bring experience with CSP, CORS, SameSite cookies, sec-fetch headers, CORB, CORP, the Sanitizer API or Trusted Types. • Show experience with Swift, Kotlin or C# for native apps. • Bring experience with Perl or Go on the search side. • Show experience defending against prompt injection in AI products. • Bring experience running red-team operations.

🎯 Responsibilities

• Execute SERP security mitigations, including XSS prevention and tooling that helps engineers write safer code. • Manage the application security scanning infrastructure. • Build and maintain harnesses that ship security fixes automatically. • Harden agentic browsing and Duck.ai experiences against emerging threats. • Conduct browser and sync security audits across special pages, AI integrations and the password manager. • Deliver internal red-team operations and simulated attack scenarios. • Support security triage across the company.

About DuckDuckGo

😃 What DuckDuckGo offers

• Earn $178,500 a year plus stock options. • Benefit from transparent pay, the same for everyone at your level and region. • Work remotely from anywhere on the eligible country list. • Enjoy a flexible arrangement with no core hours, averaging 40 hours a week. • Take paid parental leave. • Get an office setup and co-working allowance. • Attend two company trips a year: an all-hands meetup and a team retreat. • Take full end-to-end ownership of your projects, from scoping to postmortem.

💖 What makes DuckDuckGo unique

DuckDuckGo is the online protection company and a remote-first team of more than 300 people on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, it now earns over $100m in annual revenue, with millions using its browser on Mac, Windows, iOS and Android, its search engine and its subscription. It also offers Duck.ai, which lets people chat privately with ChatGPT, Claude and other AI models.

Share This Page

Help others by sharing this with your network

Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.

For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.