SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Researcher, Offensive AI

The Browser Company - Remote - Remote - posted 2026-09-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 225,000 - 300,000 / annual

The Browser Company is building Dia, a browser enhanced with agentic capabilities that reasons over untrusted web content and takes real actions on the user's behalf. This creates a novel threat model where the agent sits alongside everything the user is signed into, producing security challenges without prior art. As a Staff Security Researcher on the security team, you will conduct original offensive research against Dia's client, agent runtime, tools, integrations, and backend services. You'll work ahead of product launches, threat-modeling new surfaces with design teams and reviewing features before they reach users. A key focus is building automated vulnerability discovery systems—model-driven scanning, fuzzing harnesses, and agentic hunting pipelines—that run continuously against code, infrastructure, and the agent itself. You'll partner closely with engineers who own remediation (rather than owning fixes yourself) and report to the Head of Security, collaborating across client, infrastructure, and product engineering teams. Key responsibilities include: - Running original offensive research targeting prompt injection, indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, and quota/abuse-scoring bypass - Threat-modeling new surface areas with product teams and reviewing features pre-launch - Designing and building automated vulnerability discovery systems including model-driven scanning, fuzzing, and agentic hunting pipelines - Eliminating entire bug classes in collaboration with engineers, enforcing structural fixes through invariants, fail-closed defaults, tests, lints, or platform changes - Setting standards for "security tested" before feature launch and raising the team's capability ceiling Key technical projects include: continuous AI-assisted vulnerability discovery (surveying commercial scanners, frontier models, and open-source security tools); agent red teaming with regular exercises and attack corpus building; pre-launch review processes for tools, integrations, and capabilities; and structural fixes that eliminate vulnerability classes. REQUIREMENTS: - 8+ years in offensive security (vulnerability research, exploit development, red teaming, or product security testing) with a track record of finding real bugs in already-reviewed software - Deep expertise in at least one hard surface: LLM agent systems, browser/Chromium internals, OS sandboxing and native clients, or backend/cloud infrastructure; excitement to learn the rest - Practical fluency using LLMs as instruments (not just targets) with good judgment about signal vs. noise - Production-quality code in one or more of Go, TypeScript, Python, or Swift; preference for building systems that find bugs repeatedly rather than one-off findings - Ability to write findings that engineers act on; comfort staying in fix conversations and pushing for durable solutions without owning remediation - Thrives in high-trust, high-ambiguity environments; seeks feedback without needing hand-holding - Alignment with company values (see thebrowser.company/values) - Primary focus on North American time zones with 4+ hours overlap with Eastern Time Zone team members

Similar roles