Who We Are Hi, we're DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable since 2014, annual revenue now exceeds $100m USD and millions use our browser on on
Mac,
Windows,
iOS, and
Android, our
search engine, and the
DuckDuckGo subscription. We also offer private, useful, and optional AI, including
Duck.ai, which lets you chat privately with ChatGPT, Claude, and other AIs, all in one place. Our
culture of trust, inclusivity, and empowered project management underpins everything we do, where each team member takes full ownership of their projects, from scoping and execution to postmortem.Your Team and RoleWorking on the Security Functional Team, you'll play a pivotal role in ensuring our security capabilities keep pace with our rapid product development, including our expanding AI offerings like Duck.ai and agentic browsing, directly protecting our users across all our products. You'll also maintain incident detection and response capabilities for the company, and work on related projects. Recent projects include:SERP security mitigationsAgentic browsing security mitigationsAgentic browser hardeningBrowser and sync security auditsAs a Senior Security Engineer, App Sec, you'll execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code), manage application security scanning infrastructure setup, build and maintain harnesses that get security fixes out automatically, harden our agentic browsing and DuckAI experiences against emerging threats (like prompt injection), conduct browser and sync security audits (special pages, DuckAI integrations, password manager, etc.), deliver on internal red-team operations (simulated attack scenarios), support security triage, and more!About You7+ years of experience in web or application security (performing security assessments, vulnerability research, penetration testing, or secure code review)Recent experience creating security focused agentic harnessesExperience influencing large feature designs to have security baked in from the startAdvanced programming or scripting experience with JavaScript. Any additional experience with our stack is a bonus: Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search).An understanding of the web security model (such as the Same Origin Policy); experience with CSP, CORS, SameSite cookies, sec-fetch-*, CORB, CORP, Sanitizer API, and Trusted Types is beneficialHands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection attacks, authorization flaws, etc.)Familiarity with security testing tools and frameworksExperience partnering and collaborating with Product Engineers, advising on security matters and helping teams ship secure code fasterExperience shaping how an organisation thinks about security - driving best practices, improving processes, and raising the bar across teamsCompensation$178,500 USD annually and stock options. Compensation is transparent across the organization, and all team members within the same professional level and global region receive the same compensation.Eligibility for company-sponsored health benefits is limited to team members based in the United States. This program does not extend to team members located in other countries, such as Canada or the UK.Our
Team Member Support Guide explains how we prioritize your wellbeing including paid parental leave, office setup, and co-working allowances.Hiring ProcessHiring works best when it's a two-way street. Learn how we help you get to know DuckDuckGo, envision your future role here, and find out more about
how we hire.Diversity, Equity and InclusionDuckDuckGo provides equal work opportunities to all team members and applicants, and it prohibits discrimination and harassment of any type on the basis of race, color, ethnicity, caste, religion, age, sex (including pregnancy), national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by our policies or federal, state, or local laws.We want to ensure that our hiring process is accessible. If you need reasonable accommodation for any part of the application process because of a medical condition or disability, please send an email to
careers@duckduckgo.com to let us know the nature of your request.Please note that:You’ll be required to attend meetings on camera via video conferencingExpect to travel at least two times a year: once for our all-hands meetup and again for a team retreat (each around 4-5 days). While extenuating circumstances may impact attendance, everyone is strongly encouraged to attend.While we offer a flexible work arrangement with no core hours, expect an average full-time commitment of 40 hours per week.A successful candidate must pass a background check as a condition of joining the team.By applying for this role, you confirm that all information submitted is accurate and complete. You further acknowledge that providing false or fraudulent information during the application process is cause for denial of an offer, revocation of any existing offer, or other adverse action, up to and including termination after the start of your commencement of work.