DuckDuckGo logo
Monthly
€12,913
Posted May 4, 2026 · 119 days agoLast seen August 31, 2026Est. expiry June 8, 2026

Web Security Engineer

Senior Web Security Engineer
How this salary compares
Salary Context: Web Security Engineer

Hover or tap a row for full statistics (EUR / month on this chart).

Salary analysis

Compared with the selected benchmark ("All roles in Remote - Global"), this listing's salary midpoint is about 68% higher. The offer still falls within the benchmark range (€2,500–€15,201). Range-width comparison is limited because one of the salary bands is incomplete. This benchmark is based on 519 comparable listings.

Monthly salary comparison for Web Security Engineer
MarketLower bound (25th percentile)MedianUpper bound (75th percentile)
All roles in Remote - Global€2,500/per month€7,476/per month€15,201/per month
About the role

Senior Web Security Engineer position on the DuckDuckGo Security Functional Team. You will be responsible for ensuring our security capabilities keep pace with rapid product development, including AI offerings like Duck.ai and agentic browsing, and for maintaining incident detection and response capabilities across products. You will execute on SERP security mitigations (XSS prevention, tooling to help engineers write safer code), manage application security scanning infrastructure, build and maintain harnesses to push security fixes automatically, harden agentic browsing and DuckAI experiences against emerging threats, conduct browser and sync security audits, and contribute to internal red-team exercises. You will also support security triage and partner with Product Engineers to ship secure code faster, while helping shape organizational security practices and raising the security bar across teams. About You: - 7+ years of experience in web or application security (security assessments, vulnerability research, penetration testing, secure code review) - Experience creating security-focused agentic harnesses - Experience influencing large feature designs to bake in security from the start - Advanced programming or scripting with JavaScript; experience with Swift/Kotlin/C#/JavaScript (native apps) or JavaScript/Perl/Go (search) is a bonus - Knowledge of web security models and concepts (CSP, CORS, SameSite, sec-fetch-*, CORB, CORP, Sanitizer API, Trusted Types) - Hands-on experience identifying and exploiting web vulnerabilities (XSS, CSRF, injection, authorization flaws) - Familiarity with security testing tools and frameworks - Experience collaborating with Product Engineers on secure shipping of code - Experience shaping how an organization thinks about security and raising the bar across teams Compensation: $178,500 USD annually and stock options. Compensation is transparent across the organization, and all team members within the same professional level and global region receive the same compensation. Eligibility for company health benefits is limited to team members based in the United States. Team Member Support Guide describes paid parental leave, office setup, and co-working allowances. Hiring Process and Diversity: Two-way hiring approach; we share how we hire and value diversity and inclusion. Accommodations available on request. Note: Meetings on camera required, travel at least twice a year, flexible hours with approx. 40 hours weekly, background checks required, and AI in Hiring disclosures.

Job Details

Responsibilities

  • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code)
  • Manage application security scanning infrastructure setup
  • Build and maintain harnesses that push security fixes automatically
  • Harden agentic browsing and DuckAI experiences against emerging threats
  • Conduct browser and sync security audits
  • Deliver on internal red-team operations
  • Support security triage and collaborate with Product Engineers on secure shipping

Requirements

  • 7+ years of experience in web or application security (security assessments, vulnerability research, penetration testing, or secure code review)
  • Recent experience creating security focused agentic harnesses

Skills & Technologies

JavaScriptSecurity testing toolsCSP/CORS/SameSiteXSS/CSRFAutomationGo/Perl/JavaScript (search)Swift/Kotlin/C#/JavaScript (native apps)

Recruitment Process

  1. 1
    Learn how we hire
  2. 2
    Two-way street
Seen 3 hours agoPartial Schema
DuckDuckGo logo
DuckDuckGo
View company

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.