×
Register Here to Apply for Jobs or Post Jobs. X

Security Researcher, Offensive AI

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: The Browser Company
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, AI Engineer (Applied/Software)
Salary/Wage Range or Industry Benchmark: 225000 - 300000 USD Yearly USD 225000.00 300000.00 YEAR
Job Description & How to Apply Below
Position: Staff Security Researcher, Offensive AI

Hi, we're The Browser Company and we're building a better way to use the internet.

Browsers are unique in that they are one of the only pieces of software that you share with your parents as well as your kids. Which makes sense, they're our doorway to the most important things — through them we socialize with loved ones, work on our passion projects, and explore our curiosities. But on their own, they don’t actually do a whole lot, they’re kind of just there.

They don’t help us organize our messy lives or make it easier to compose our ideas. We believe that the browser could do so much more — it can empower and support the amazing things we do on the internet. That’s why we’re building one: a browser that can help us grow, create, and stay curious.

To accomplish this lofty task, we’re building a diverse team of people from different backgrounds and experiences. This isn’t optional, it’s crucial to our mission, as we need a wide range of perspectives to challenge our assumptions and shape our browser through a bold, creative lens. With that in mind, we especially encourage women, people of color, and others from historically marginalized groups to apply.

About

the Role

Dia is a browser enhanced with agentic capabilities. The agent reasons over untrusted content from the open web and takes real actions on the user's behalf, inside a client that sits next to everything the user is signed into. That combination produces a threat model that mostly doesn't have prior art — the interesting bugs aren't on a checklist, and the tooling to find them largely doesn't exist yet.

As a Staff Security Researcher on our security team, you'll do original offensive research against Dia including the client, agent runtime, tools and integrations it calls, and services behind them. You'll work ahead of the product, threat modeling new surfaces with the teams designing them, and reviewing features before they reach users.

You'll also eliminate bug classes by building model-driven scanning, fuzzing, and agentic hunting systems that run continuously against our code, our infrastructure, and our agent.

You’ll partner closely with the engineers who own remediation, rather than owning the fixes yourself. You'll report to the Head of Security and work across client, infrastructure, and product engineering.

Overall you will...
  • Run original offensive research against Dia, its agent, and backend services, focusing on prompt injection and indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, quota and abuse-scoring bypass.

  • Threat model new surface areas with the teams building them, and review features before they ship, identifying what is exploitable, what it costs an attacker, and what would have to be true to launch.

  • Design and build automated vulnerability discovery including model-driven code and infrastructure scanning, fuzzing harnesses, and agentic hunting pipelines that keep working after the engagement ends.

  • Eliminate entire classes of bugs in collaboration with the engineers who own the fix, then make the same issue structurally hard to reintroduce through an enforced invariant, a fail-closed default, a test, a lint, or a platform change.

  • Set the standard for what 'security tested' means before a feature ships, and raise the ceiling on what the whole team can find.

Technical Projects You'll Shape With Us…
  • Continuous AI-assisted vulnerability discovery (first project). You’ll survey commercial scanning services, frontier models, open-source security models, and stand up a working mix against our codebase, our infrastructure, and the agent runtime.

  • Agent red teaming. Plan and run regular AI-assisted red team exercises against Dia and our infrastructure, and…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary