Staff Security Researcher, Offensive AI

The Browser Company
New York, Canada
Workplace: RemoteFull timeUSD 225,000 - 300,000 annuallyFunction: Research & Scientific (R&D)Experience: 8+ yearsSkills: ["High-trust collaboration","High-ambiguity problem-solving","Security testing mindset","Iterative improvement"]

Conduct original offensive security research for an agentic browser product, focusing on novel threat models and vulnerability discovery. Threat model new agent and client surfaces, perform prompt-injection and exfiltration testing, and build continuous scanning, fuzzing, and agentic hunting pipelines. Partner with engineers to eliminate entire vulnerability classes via structural fixes and enforceable invariants, while helping define what “security tested” means before releases.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
The Browser Company
The Browser Company
2 days ago

Staff Security Researcher, Offensive AI

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 16 hours agoStatus: Live

Job Summary

Conduct original offensive security research for an agentic browser product, focusing on novel threat models and vulnerability discovery. Threat model new agent and client surfaces, perform prompt-injection and exfiltration testing, and build continuous scanning, fuzzing, and agentic hunting pipelines. Partner with engineers to eliminate entire vulnerability classes via structural fixes and enforceable invariants, while helping define what “security tested” means before releases.
Location: New York, Canada
Workplace: Remote
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Run original offensive research against an agentic browser (Dia), its agent, and backend services, focusing on prompt injection, exfiltration, tool-call abuse, provenance bypass, sandbox escape, and cross-profile access.
  • •Threat model new surface areas and review features before launch to identify exploitability, attacker cost, and launch prerequisites.
  • •Design and build automated vulnerability discovery systems including model-driven scanning, fuzzing harnesses, and agentic hunting pipelines that run continuously.
  • •Work with engineers who own remediation to eliminate entire bug classes via durable structural fixes and enforced invariants.
  • •Set the standard for what “security tested” means before a feature ships and raise the team’s discovery capabilities.

Pay and Benefits

Salary: USD 225,000 - 300,000 annually
Equity and Bonus:Equity

Key Requirements

  • •8+ years in offensive security (vulnerability research, exploit development, red teaming, or product security testing) with a record of finding real bugs.
  • •Deep experience in at least one hard surface such as LLM agent systems, browser/Chromium internals, OS sandboxing/native clients, or backend/cloud infrastructure.
  • •Practical fluency using LLMs as instruments (not just targets) with judgment about output quality.
  • •Production-quality coding in one or more of Go, TypeScript, Python, or Swift.
  • •Writes actionable findings and can drive durable fixes without owning remediation yourself.
Experience:8+ yearsOffensive securityLLM securityBrowser securityProduct securityRed teaming
Skills:High-trust collaborationHigh-ambiguity problem-solvingSecurity testing mindsetIterative improvement
Tech Stack:LLMsGoTypeScriptPythonSwiftChromiumLLM agent systemsFuzzingRed teamingPrompt injectionSandboxingContinuous scanning

Company Brief

The Browser Company
Builds Arc, a design-forward web browser and productivity platform that reimagines browsing with integrated tools, spaces, and collaboration features to help users organize and navigate the web more efficiently.
Industry: Enterprise Software
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2019
WebsiteLinkedIn