Senior Web Security Engineer, Browser Platform
Job description
Senior Web Security Engineer, Browser Platform at Duck Duck Go.
About the role
You will own the security posture of our agentic browsing and DuckAI experiences, designing defenses against emerging threat vectors such as prompt injection and malicious adversarial inputs. You will conduct deep browser and sync security audits, scrutinizing special pages, DuckAI integrations, and the password manager to ensure robust protection of user data. You will execute on SERP security mitigations, focusing on XSS prevention and developing tooling that helps engineers write safer code across the codebase. You will build and maintain automated harnesses that enable rapid deployment of security fixes, manage application security scanning infrastructure setup, and deliver on internal red-team operations through simulated attack scenarios. You will support security triage, respond to incidents, and collaborate closely with engineering teams to remediate vulnerabilities as they arise. You will also partner with product and engineering stakeholders to embed security into feature designs from the start, ensuring that privacy and safety are foundational rather than afterthoughts. You will shape how the organization thinks about security by driving best practices, improving processes, and raising the bar across all teams, ultimately protecting millions of users across every DuckDuckGo product they trust.
Key facts
What you'll do
- Architect and implement security controls for agentic browsing and DuckAI features, mitigating risks like prompt injection and data leakage.
- Perform browser and sync security audits, focusing on special pages, DuckAI integrations, password manager modules, and related components.
- Design and execute SERP security mitigations, including XSS prevention and secure coding standards that reduce vulnerability surface area.
- Develop tooling and harnesses that automate the detection and remediation of security issues during development and CI/CD cycles.
- Manage application security scanning infrastructure setup, ensuring coverage across web, mobile, and backend systems.
- Lead internal red-team operations, creating realistic simulated attack scenarios to validate detection and response capabilities.
- Partner with product and engineering teams to advise on security requirements and integrate secure design patterns early in feature development.
- Drive incident detection and response processes, coordinating triage, analysis, and remediation efforts across the organization.
- Contribute to security strategy by defining best practices, improving processes, and evangelizing security awareness across cross-functional teams.
- Maintain and evolve security testing methodologies to keep pace with new browser features, AI integrations, and evolving threat landscapes.
Requirements
- Bring 7+ years of experience in web or application security, including performing security assessments, vulnerability research, penetration testing, or secure code review.
- Demonstrate recent experience creating security focused agentic harnesses that validate behavior and safety for AI-driven features.
- Show a track record of influencing large feature designs to have security baked in from the start, ensuring privacy and safety are prioritized.
- Apply advanced programming or scripting experience with JavaScript, leveraging deep knowledge of secure coding patterns and runtime behavior.
- Draw on any additional experience with our stack as a bonus, including Swift, Kotlin, C#, JavaScript for native apps, or JavaScript, Perl, Go for search infrastructure.
- Exhibit hands-on experience with at least one WebView technology such as WebKit, WebView2, or Chromium WebView, along with a solid understanding of browser security models including SOP, CSP, CORS, and SameSite cookies.
- Prove familiarity with identifying and exploiting web vulnerabilities, such as XSS, CSRF, injection attacks, and authorization flaws, through practical testing and responsible disclosure.
- Demonstrate familiarity with security testing tools and frameworks, using them to automate scans, analyze findings, and track remediation progress.
- Illustrate experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster without compromising functionality.
- Exhibit a history of shaping organizational security practices, driving best practices, improving processes, and raising the bar across multiple teams and products.
Nice to have
Only items indicated as preferred in SOURCE are listed here, and no additional preferences are added.
Practical notes
No information on hours, travel, or visa requirements, or application deadlines is provided within SOURCE, so this section is omitted.