Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
The Browser Company

Staff Security Researcher – Offensive AI

The Browser Company

. Run original offensive research against Dia, its agent, and backend services .

Posted 9/25/2026full-timeRemote • United States, CanadaLead💰 $225,000 - $300,000 per yearWebsite

Tech Stack

Tools & technologies
CloudPythonSwiftTypeScriptGo

About the role

Key responsibilities & impact
  • Run original offensive research against Dia, its agent, and backend services
  • Investigate prompt injection and indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, and quota and abuse-scoring bypass
  • Threat model new surface areas with product teams and review features before launch
  • Design and build automated vulnerability discovery, including model-driven code and infrastructure scanning, fuzzing harnesses, and agentic hunting pipelines
  • Collaborate with engineers to eliminate vulnerability classes and make issues structurally difficult to reintroduce
  • Define the standard for security testing before features ship
  • Survey commercial scanning services, frontier models, and open-source security models and deploy them against the codebase, infrastructure, and agent runtime
  • Plan and run regular AI-assisted red-team exercises and build attack corpora and harnesses
  • Shape pre-launch reviews for tools, integrations, agent capabilities, enterprise controls, and platform expansion
  • Report to the Head of Security and work across client, infrastructure, and product engineering

Requirements

What you’ll need
  • 8+ years in offensive security — vulnerability research, exploit development, red teaming, or product security testing — with a record of finding real bugs in software other people had already reviewed
  • Depth in at least one hard surface: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure — and the excitement to learn the rest
  • Practical fluency using LLMs as instruments, not just as targets, plus a working sense of when their output is noise
  • Production-quality coding in one or more of Go, TypeScript, Python, or Swift
  • Ability to write findings engineers act on and stay in the fix conversation without owning remediation
  • Ability to thrive in a high-trust, high-ambiguity environment
  • Resonance with company values
  • Primarily focused on hiring in North American time zones
  • 4+ hours of overlap with team members in Eastern Time Zone

Benefits

Comp & perks
  • Base salary, equity, and comprehensive benefits
  • Best-in-class benefits designed to support you, your family, and your life outside of work
  • Remote-first, distributed team
  • Option to work from the office in Brooklyn, New York
  • Startup-style impact, ownership, and ways of working