Staff Security Researcher, Offensive AI

The Browser Company

United States

Remote

USD 225,000 - 300,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Best-in-class benefits
Remote-friendly company
Office in Brooklyn, NY

Job summary

The Browser Company is seeking a Staff Security Researcher to drive offensive security research on Dia, its agent, and backend services. You will help threat model new surfaces, design automation for vulnerability discovery, and work with engineers to eliminate bug classes with robust, durable fixes.

The role emphasizes production-grade code in Go/TypeScript/Python/Swift, and requires 8+ years in security with strong QA mindset.

Qualifications

  • 8+ years in offensive security — vulnerability research, exploit development, red teaming, or product security testing.
  • Depth in at least one hard surface: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure.
  • Practical fluency using LLMs as instruments, not just as targets.
  • You write production-quality code in Go, TypeScript, Python, or Swift.
  • You write findings engineers act on and push for durable fixes.
  • You thrive in a high-trust environment with minimal hand-holding.
  • You resonate with our company values.
  • We require 4+ hours of overlap with Eastern Time Zone.

Responsibilities

  • Run original offensive research against Dia including the client, agent runtime, tools and integrations it calls, and services behind them.
  • Threat model new surface areas with the teams building them, and review features before they ship.
  • Design and build automated vulnerability discovery: model-driven scanning, fuzzing harnesses, and agentic hunting pipelines.
  • Eliminate entire classes of bugs in collaboration with engineers, making issues hard to reintroduce via invariants and platform changes.
  • Set the standard for what 'security tested' means before a feature ships.

Skills

Offensive security
Threat modeling
Code in Go/TS/Python/Swift
LLM/agent systems
Browser/Chromium internals
OS sandboxing
Cloud infrastructure
Bug discovery tooling

Tools

Go
TypeScript
Python
Swift

Job description

Hi, we're The Browser Company and we're building a better way to use the internet.

Browsers are unique in that they are one of the only pieces of software that you share with your parents as well as your kids. Which makes sense, they're our doorway to the most important things — through them we socialize with loved ones, work on our passion projects, and explore our curiosities. But on their own, they don’t actually do a whole lot, they’re kind of just there. They don’t help us organize our messy lives or make it easier to compose our ideas. We believe that the browser could do so much more — it can empower and support the amazing things we do on the internet. That’s why we’re building one: a browser that can help us grow, create, and stay curious.

To accomplish this lofty task, we’re building a diverse team of people from different backgrounds and experiences. This isn’t optional, it’s crucial to our mission, as we need a wide range of perspectives to challenge our assumptions and shape our browser through a bold, creative lens. With that in mind, we especially encourage women, people of color, and others from historically marginalized groups to apply.

About the Role

Dia is a browser enhanced with agentic capabilities. The agent reasons over untrusted content from the open web and takes real actions on the user's behalf, inside a client that sits next to everything the user is signed into. That combination produces a threat model that mostly doesn't have prior art — the interesting bugs aren't on a checklist, and the tooling to find them largely doesn't exist yet.

As a Staff Security Researcher on our security team, you'll do original offensive research against Dia including the client, agent runtime, tools and integrations it calls, and services behind them. You'll work ahead of the product, threat modeling new surfaces with the teams designing them, and reviewing features before they reach users.

You'll also eliminate bug classes by building model-driven scanning, fuzzing, and agentic hunting systems that run continuously against our code, our infrastructure, and our agent.

You’ll partner closely with the engineers who own remediation, rather than owning the fixes yourself. You'll report to the Head of Security and work across client, infrastructure, and product engineering.

Overall you will...
  • Run original offensive research against Dia, its agent, and backend services, focusing on prompt injection and indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, quota and abuse-scoring bypass.

  • Threat model new surface areas with the teams building them, and review features before they ship, identifying what is exploitable, what it costs an attacker, and what would have to be true to launch.

  • Design and build automated vulnerability discovery including model-driven code and infrastructure scanning, fuzzing harnesses, and agentic hunting pipelines that keep working after the engagement ends.

  • Eliminate entire classes of bugs in collaboration with the engineers who own the fix, then make the same issue structurally hard to reintroduce through an enforced invariant, a fail-closed default, a test, a lint, or a platform change.

  • Set the standard for what 'security tested' means before a feature ships, and raise the ceiling on what the whole team can find.

Technical Projects You'll Shape With Us…
  • Continuous AI-assisted vulnerability discovery (first project). You’ll survey commercial scanning services, frontier models, open-source security models, and stand up a working mix against our codebase, our infrastructure, and the agent runtime.

  • Agent red teaming. Plan and run regular AI-assisted red team exercises against Dia and our infrastructure, and build the attack corpus and harness that make each round cheaper than the last.

  • Pre-launch review as a practice. New tools and integrations, agent capabilities, enterprise controls, platform expansion. Enhanced with platforms to assist with testing

  • Structural fixes that eliminate classes of vulnerability. Define, with the product engineers, the changes that take a whole bug class off the table instead of fixing the same issue one report at a time.

  • Future tools and systems. The state of the art in vulnerability hunting is evolving faster than it ever has. We expect this person to track it and keep BCNY best in class, which means therea re opportunities to build far beyond the scope described above.

Qualifications
  • 8+ years in offensive security — vulnerability research, exploit development, red teaming, or product security testing — with a record of finding real bugs in software other people had already reviewed.

  • Depth in at least one hard surface: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure — and the excitement to learn the rest.

  • Practical fluency using LLMs as instruments, not just as targets, plus a working sense of when their output is noise.

  • You write production-quality code in one or more of Go, TypeScript, Python, or Swift. You'd rather build the thing that finds a bug a thousand times than find it once.

  • You write findings engineers act on, and you can stay in the fix conversation and push for the durable version without owning the remediation yourself.

  • You thrive in a high-trust, high-ambiguity environment: you seek feedback, but you don't need hand-holding.

  • You resonate with our company values.

  • We're primarily focused on hiring in North American time zones and require that folks have 4+ hours of overlap time with team members in Eastern Time Zone.

Compensation and Benefits
  • Our total compensation for full-time employees includes base salary, equity, and comprehensive benefits. The annual base salary range for this role is $225,000-$300,000 USD. The final offer will depend on your experience, expertise, and interview performance. Our goal is simple: if it feels like the right mutual fit, compensation shouldn’t be the thing that gets in the way. We’ve built a small, talent-dense team who cares deeply about their craft, and we pay competitively in line with current market benchmarks.

  • Benefits. We offer best-in-class benefits https://go.atlassian.com/perksandbenefits designed to support you, your family, and your life outside of work. Think big-company perks with startup-style impact, ownership, and ways of working — so you have the space and support to do the best work of your career.

  • Location. We’re a remote-friendly company and can hire in the US or Canada. If you live in New York (or want to visit), you’re welcome to work from our office in Williamsburg.

The Browser Company is an ambitious team of close to 100 people (and growing!) who are passionate about building great products. We are a remote-first, distributed team, with the option to work from office in Brooklyn, New York. We strongly support diversity and encourage people from all backgrounds to apply.

To read more about what we value as a company, check out Notes on Roadtrips on our blog.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Researcher, Offensive AI
Staff Security Researcher, Offensive AI

The Browser Company • Williamsburg (VA)

Remote
USD 225,000 - 300,000
Remote-friendly
Office Williamsburg option
Equity
Full Stack Software Engineer, Dia Enterprise
Full Stack Software Engineer, Dia Enterprise

The Browser Company • United States

Remote
USD 215,000 - 275,000
Best-in-class benefits
Remote-friendly environment
Office option in Williamsburg, NY (oc)
Security Engineer II, Application Security
Security Engineer II, Application Security

Trail of Bits • United States

Remote
USD 140,000 - 180,000
Health insurance
Fully company-paid insurance packages
401(k) with 5% match
+7
Member of Technical Staff, AI Engineer San Francisco, CA
Member of Technical Staff, AI Engineer San Francisco, CA

Parameter • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Senior Software Engineer, Browser Automation
Senior Software Engineer, Browser Automation

Horizon3 AI, Inc. • Chicago (IL), Northern (KY)

On-site
USD 169,000 - 208,000
Health insurance
Vision insurance
Dental insurance
+3
Senior Developer Relations Engineer (Security Advocate)
Senior Developer Relations Engineer (Security Advocate)

Trail of Bits Inc. • New York (NY)

On-site
USD 160,000 - 200,000
Full benefits package
Remote-first culture
Relocation assistance
+3
Senior Software Engineer, Agentic Systems
Senior Software Engineer, Agentic Systems

Horizon3 AI, Inc. • Chicago (IL), Northern (KY)

On-site
USD 169,000 - 208,000
Competitive pay
Equity
Health insurance
+3
Senior Software Engineer, Browser Automation
Senior Software Engineer, Browser Automation

horizon3ai • United States

Hybrid
USD 199,000 - 235,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Senior Product Manager, Integrity & Trust Experience
Senior Product Manager, Integrity & Trust Experience

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 210,000
Senior Product Manager, Browser Extension
Senior Product Manager, Browser Extension

United States Digital Space LLC • United States

On-site
USD 120,000 - 180,000
Equity plan
Comprehensive benefits
Career growth opportunities