JavaScript Security Engineer - Web Browser Vulnerabilities
English Required / Based in Lisbon, Portugal / Hybrid
We are seeking a skilled JavaScript Security Engineer with a strong background in web technologies and cybersecurity to analyze, reverse engineer, and secure browser‑based applications, with a particular focus on web extensions. This role involves identifying malicious behaviors, conducting security assessments, and driving automation and process improvements within the security analysis lifecycle.
Key Responsibilities
- Analyze web extension code using static and dynamic analysis techniques to detect security violations and malicious behavior.
- Perform JavaScript reverse engineering and debugging to understand complex or obfuscated codebases.
- Identify, document, and report security vulnerabilities, including root‑cause analysis and recommended remediation steps.
- Support the takedown and investigation of malicious browser extensions.
- Conduct regular code reviews and provide constructive feedback aligned with secure coding best practices.
- Define and implement detection rules and security patterns to identify violations at scale.
- Identify emerging threat patterns and share insights to enhance team detection capabilities.
- Drive innovative ideas, recommend improvements, and help design and implement automation for existing processes.
- Act as a technical consultant, providing guidance, clarification, and technical grooming to team members.
- Collaborate effectively with cross‑functional teams and maintain clear technical documentation.
- Contribute to continuous improvement of security workflows and tooling.
You Are Someone Who Brings
- Strong hands‑on experience with JavaScript, including advanced concepts such as closures, prototypes, variable scope, hoisting, callbacks, and OOP principles.
- Hands‑on experience with HTML and CSS.
- Knowledge of JSON, AJAX, and ES6/ES7 standards.
- Good understanding of Node.js and Webpack.
- Experience working with front‑end frameworks or libraries such as React, Angular, or jQuery.
- Strong code analysis, debugging, and reverse engineering skills, particularly in JavaScript applications.
- Ability to analyze JavaScript code and identify malicious activities effectively.
- Good communication skills and the ability to work as a collaborative team player.
Added Advantages (Nice To Have)
- Cybersecurity experience or strong security knowledge.
- Familiarity with DAST and SAST methodologies.
- Knowledge of cybersecurity open‑source tools such as Burp Suite, Nmap, or similar tools.
- Understanding of obfuscation and de‑obfuscation techniques.
- Experience writing technical and security assessment reports.