远程工作雷达

高级网络安全部门工程师,浏览器平台

Senior Web Security Engineer, Browser Platform

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司DuckDuckGo
薪资$178,500/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间2026-04-08
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

## **关于我们**

嗨,我们是DuckDuckGo,一家在线保护公司,拥有300多名远程办公的团队成员,致力于提升在线信任标准。自2008年成立以来,我们自2014年起实现盈利,年收入现已超过1亿美元,数百万用户在[Mac](https://spreadprivacy.com/introducing-duckduckgo-for-mac/)、[Windows](https://spreadprivacy.com/windows-browser-open-beta/)、[iOS](https://spreadprivacy.com/duckduckgo-privacy-browser-ios14/)和[Android](https://spreadprivacy.com/introducing-app-tracking-protection/)浏览器上使用我们的产品,以及我们的[搜索引擎](https://duckduckgo.com/)和[DuckDuckGo订阅服务](https://duckduckgo.com/pro)。我们还提供私密、实用且可选的AI服务,包括[Duck.ai](https://duck.ai/),让您可以在一个地方与ChatGPT、Claude和其他AI进行私密聊天。我们的信任、包容和赋权项目管理文化贯穿于所有工作中,每位团队成员对其项目从规划、执行到事后分析都拥有完全的自主权。如果您希望对工作有全流程的掌控,那么您来对地方了!

## **您的团队和职位**

在安全功能团队工作,您将在确保我们的安全能力跟上快速的产品开发步伐方面发挥关键作用,包括我们不断扩展的AI产品如Duck.ai和代理浏览功能,直接保护我们所有产品中的用户。您还将维护事件检测和响应能力,并参与相关项目。最近的项目包括:

- 搜索结果页面(SERP)安全缓解措施

- 代理浏览安全缓解措施

- 代理浏览器加固

- 浏览器和同步安全审计

作为**高级安全工程师,应用安全方向**,您将执行SERP安全缓解措施(XSS预防、开发工具帮助工程师编写更安全的代码),管理应用安全扫描基础设施的设置,构建并维护自动发布安全修复的框架,针对新兴威胁(如提示注入)加固我们的代理浏览和DuckAI体验,进行浏览器和同步安全审计(特殊页面、DuckAI集成、密码管理器等),完成内部红队操作(模拟攻击场景),支持安全优先级处理,以及其他任务!

## **关于您**

- 在Web或应用安全领域有7年以上经验(进行安全评估、漏洞研究、渗透测试或安全编码)

查看英文原文

## **Who We Are**

Hi, we're DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue now exceeds $100m USD and millions use our browser on on [Mac](https://spreadprivacy.com/introducing-duckduckgo-for-mac/), [Windows](https://spreadprivacy.com/windows-browser-open-beta/), [iOS](https://spreadprivacy.com/duckduckgo-privacy-browser-ios14/), and [Android](https://spreadprivacy.com/introducing-app-tracking-protection/), our [search engine](https://duckduckgo.com/), and the [DuckDuckGo subscription](https://duckduckgo.com/pro). We also offer private, useful, and optional AI, including [Duck.ai](https://duck.ai/), which lets you chat privately with ChatGPT, Claude, and other AIs, all in one place. Our [culture](https://duckduckgo.com/how-we-work) of trust, inclusivity, and empowered project management underpins everything we do, where each team member takes full ownership of their projects, from scoping and execution to postmortem. If you're seeking end-to-end ownership of your work, you've come to the right place!

## **Your Team and Role**

Working on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, including our expanding AI offerings like Duck.ai and agentic browsing, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on related projects. Recent projects include:

- SERP security mitigations

- Agentic browsing security mitigations

- Agentic browser hardening

- Browser and sync security audits

As a **Senior Security Engineer, App Sec**, you'll execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code), manage application security scanning infrastructure setup, build and maintain harnesses that get security fixes out automatically, harden our agentic browsing and DuckAI experiences against emerging threats (like prompt injection), conduct browser and sync security audits (special pages, DuckAI integrations, password manager, etc.), deliver on internal red-team operations (simulated attack scenarios), support security triage, and more!

## **About You**

- 7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)

- Recent experience creating security focused agentic harnesses

- Experience influencing large feature designs to have security baked in from the start

- Advanced programming or scripting experience with JavaScript. Any additional experience with our stack is a bonus: Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search).

- An understanding of the web security model (such as the Same Origin Policy); experience with CSP, CORS, SameSite cookies, sec-fetch-*, CORB, CORP, Sanitizer API, and Trusted Types is beneficial

- Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)

- Familiarity with security testing tools and frameworks

- Experience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code faster

- Experience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teams

## **Compensation**

**$** _**178,500**_ **USD annually** and stock options. Compensation is transparent across the organization, and all team members within the same professional level and global region receive the same compensation.

Eligibility for company-sponsored health benefits is limited to team members based in the United States. This program does not extend to team members located in other countries, such as Canada or the UK.

Our [Team Member Support Guide](https://duckduckgo.com/assets/hiring/team_support_guide.pdf) explains how we prioritize your wellbeing including **paid parental leave, office setup,** and **co-working allowances.**

## **Hiring Process**

Hiring works best when it's a two-way street. Learn how we help you get to know DuckDuckGo, envision your future role here, and find out more about [how we hire](https://duckduckgo.com/how-we-hire).

## **Diversity, Equity and Inclusion**

DuckDuckGo provides equal work opportunities to all team members and applicants, and it prohibits discrimination and harassment of any type on the basis of race, color, ethnicity, caste, religion, age, sex (including pregnancy), national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by our policies or federal, state, or local laws.

We want to ensure that our hiring process is accessible. If you need reasonable accommodation for any part of the application process because of a medical condition or disability, please send an email to [careers@duckduckgo.com](mailto:careers@duckduckgo.com) to let us know the nature of your request.

## **Please note that:**

- You’ll be required to attend meetings on camera via video conferencing

- Expect to travel at least two times a year: once for our all-hands meetup and again for a team retreat (each around 4-5 days). While extenuating circumstances may impact attendance, everyone is strongly encouraged to attend.

- While we offer a flexible work arrangement with no core hours, expect an average full-time commitment of 40 hours per week.

- A successful candidate must pass a background check as a condition of joining the team.

- By applying for this role, you confirm that all information submitted is accurate and complete. You further acknowledge that providing false or fraudulent information during the application process is cause for denial of an offer, revocation of any existing offer, or other adverse action, up to and including termination after the start of your commencement of work.

**Disclosure Statement: Use of AI in Hiring Process**

As part of our commitment to enhancing our recruitment process, we utilize artificial intelligence (AI) technology to assist in reviewing and summarizing job applications and test projects, including those tools integrated into our recruitment vendor platforms. We use AI to flag potentially fraudulent applications, analyze and summarize applicants’ experience, interviews, and project performance, and help streamline our selection process.

**Key Principles:**

- **Data Privacy:** All information provided in your application will be handled in accordance with our [Recruiting Privacy Policy](https://duckduckgo.com/static-assets/files/pages/careers/DuckDuckGo-Recruiting-Privacy-Policy-effective-September-30-2025.pdf). We ensure that your personal information is protected and used solely for recruitment purposes.

- **Human Oversight and Accountability:** The AI technology is designed to support our hiring team by providing insights and summaries of applications and evaluations of test projects against scoring rubrics. All final evaluations and hiring decisions, however, will be made by our hiring team, who will consider the AI's input alongside other factors.

- **Transparency:** We believe in transparency regarding our hiring practices. If you have any questions about how AI is used in our recruitment process, please feel free to reach out to us.

By submitting your application, you acknowledge and consent to the use of AI technology in our review process. If you would like to request an alternative selection process, please contact us as at [careers@duckduckgo.com](mailto:careers@duckduckgo.com). Thank you for your interest in joining DuckDuckGo!

**#LI-DNI**

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级商务拓展经理

DuckDuckGoUnited States、Canada$200,267/年permanent29 天前
AI市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

付费营销总监(订阅业务)

DuckDuckGoUnited States$243,800/年permanent2026-07-20
市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位