Staff Security Researcher @The Browser Company
All Others
Salary $225,000 - $300..
Remote Location
Employment Type full-time
Posted 6d ago

[Hiring] Staff Security Researcher @The Browser Company

6d ago - The Browser Company is hiring a remote Staff Security Researcher. πŸ’Έ Salary: $225,000 - $300,000 usd per year πŸ“Location: USA, Canada

Role Description

Dia is a browser enhanced with agentic capabilities. The agent reasons over untrusted content from the open web and takes real actions on the user's behalf, inside a client that sits next to everything the user is signed into. That combination produces a threat model that mostly doesn't have prior art β€” the interesting bugs aren't on a checklist, and the tooling to find them largely doesn't exist yet.

As a Staff Security Researcher on our security team, you'll do original offensive research against Dia including the client, agent runtime, tools and integrations it calls, and services behind them. You'll work ahead of the product, threat modeling new surfaces with the teams designing them, and reviewing features before they reach users.

You'll also eliminate bug classes by building model-driven scanning, fuzzing, and agentic hunting systems that run continuously against our code, our infrastructure, and our agent.

Overall you will:

  • Run original offensive research against Dia, its agent, and backend services, focusing on prompt injection and indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, quota and abuse-scoring bypass.
  • Threat model new surface areas with the teams building them, and review features before they ship, identifying what is exploitable, what it costs an attacker, and what would have to be true to launch.
  • Design and build automated vulnerability discovery including model-driven code and infrastructure scanning, fuzzing harnesses, and agentic hunting pipelines that keep working after the engagement ends.
  • Eliminate entire classes of bugs in collaboration with the engineers who own the fix, then make the same issue structurally hard to reintroduce through an enforced invariant, a fail-closed default, a test, a lint, or a platform change.
  • Set the standard for what "security tested" means before a feature ships, and raise the ceiling on what the whole team can find.

Technical Projects You'll Shape With Us:

  • Continuous AI-assisted vulnerability discovery (first project).
  • Agent red teaming.
  • Pre-launch review as a practice.
  • Structural fixes that eliminate classes of vulnerability.
  • Future tools and systems.

Qualifications

  • 8+ years in offensive security β€” vulnerability research, exploit development, red teaming, or product security testing β€” with a record of finding real bugs in software other people had already reviewed.
  • Depth in at least one hard surface: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure β€” and the excitement to learn the rest.
  • Practical fluency using LLMs as instruments, not just as targets, plus a working sense of when their output is noise.
  • You write production-quality code in one or more of Go, TypeScript, Python, or Swift. You'd rather build the thing that finds a bug a thousand times than find it once.
  • You write findings engineers act on, and you can stay in the fix conversation and push for the durable version without owning the remediation yourself.
  • You thrive in a high-trust, high-ambiguity environment: you seek feedback, but you don't need hand-holding.
  • You resonate with our company values.
  • We're primarily focused on hiring in North American time zones and require that folks have 4+ hours of overlap time with team members in Eastern Time Zone.

Benefits

  • Our total compensation for full-time employees includes base salary, equity, and comprehensive benefits. The annual base salary range for this role is $225,000-$300,000 USD.
  • The final offer will depend on your experience, expertise, and interview performance.
  • We offer best-in-class benefits designed to support you, your family, and your life outside of work.
  • We’re a remote-friendly company and can hire in the US or Canada. If you live in New York (or want to visit), you’re welcome to work from our office in Williamsburg.
Before You Apply
️
remote Be aware of the location restriction for this remote position: USA, Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Staff Security Researcher @The Browser Company
All Others
Salary $225,000 - $300..
Remote Location
Employment Type full-time
Posted 6d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: USA, Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,383+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later