We use cookies to improve your experience and measure how our site is used. Learn more.
Staff Security Researcher, Offensive AI
Hi, we're The Browser Company 👋 and we're building a better way to use the internet.
Browsers are unique in that they are one of the only pieces of software that you share with your parents as well as your kids. Which makes sense, they're our doorway to the most important things — through them we socialize with loved ones, work on our passion projects, and explore our curiosities. But on their own, they don’t actually do a whole lot, they’re kind of just there. They don’t help us organize our messy lives or make it easier to compose our ideas. We believe that the browser could do so much more — it can empower and support the amazing things we do on the internet. That’s why we’re building one: a browser that can help us grow, create, and stay curious.
To accomplish this lofty task, we’re building a diverse team of people from different backgrounds and experiences. This isn’t optional, it’s crucial to our mission, as we need a wide range of perspectives to challenge our assumptions and shape our browser through a bold, creative lens. With that in mind, we especially encourage women, people of color, and others from historically marginalized groups to apply.
Dia is a browser enhanced with agentic capabilities. The agent reasons over untrusted content from the open web and takes real actions on the user's behalf, inside a client that sits next to everything the user is signed into. That combination produces a threat model that mostly doesn't have prior art — the interesting bugs aren't on a checklist, and the tooling to find them largely doesn't exist yet.
As a Staff Security Researcher on our security team, you'll do original offensive research against Dia including the client, agent runtime, tools and integrations it calls, and services behind them. You'll work ahead of the product, threat modeling new surfaces with the teams designing them, and reviewing features before they reach users.
You'll also eliminate bug classes by building model-driven scanning, fuzzing, and agentic hunting systems that run continuously against our code, our infrastructure, and our agent.
You’ll partner closely with the engineers who own remediation, rather than owning the fixes yourself. You'll report to the Head of Security and work across client, infrastructure, and product engineering.
Set the standard for what "security tested" means before a feature ships, and raise the ceiling on what the whole team can find.
Future tools and systems. The state of the art in vulnerability hunting is evolving faster than it ever has. We expect this person to track it and keep BCNY best in class, which means therea re opportunities to build far beyond the scope described above.
We're primarily focused on hiring in North American time zones and require that folks have 4+ hours of overlap time with team members in Eastern Time Zone.
The Browser Company is an ambitious team of close to 100 people (and growing!) who are passionate about building great products. We are a remote-first, distributed team, with the option to work from office in Brooklyn, New York. We strongly support diversity and encourage people from all backgrounds to apply.
🚙 To read more about what we value as a company, check out Notes on Roadtrips on our blog.
USD 225,000 - 300,000
Annually
Health Insurance
Dental Insurance
Vision Insurance
Mental Health Benefits
Employee Assistance Program
Pay Transparency
Unlimited PTO
Paid Holidays
Company Shutdown Days
Flexible Schedule
Home Office Stipend
Company Offsites / Retreats
Parental Leave
Adoption Leave
Bereavement Leave