Dataflow Security logo
Dataflow Security

Integrity & Excellence

Browser Security Researcher

Location

United States

Posted

1 day ago

Salary

0

Seniority

Senior

Bachelor DegreeEnglish

Job Description

Browser Security Researcher

Dataflow Security

• Help develop and carry out the Browser team research strategy by doing vulnerability research, reverse engineering and exploit development on Web Browsers. • Provide unbiased insights and ideas to the research team. • Develop proof-of-concept code and exploits to the quality standard of DFSEC. • Remain on top of various developments related to Web Browsers such as security mitigations, new features, etc.

Job Requirements

  • Deep knowledge of Web Browsers architecture and internals.
  • Solid understanding of predominant bug classes and patterns.
  • Solid understanding of current and upcoming security mitigations.
  • Ability to conduct long-term and widely scoped security research projects as part of a broader team effort.
  • Exploitation experience is a plus, but not required.
  • Good written English.

Benefits

  • Highly competitive compensation package with an additional monetary bonus system based on exploitable vulnerability findings.
  • Further your career by joining a team of established and experienced security researchers.
  • Fully remote with flexible work schedule.
  • We allow researchers, at their discretion, to spend up to 15% of their time conducting research on other topics.
  • We offer a prime wellness program designed to promote a healthy lifestyle, which includes, but not limited to access to gyms around the world, health coaching, and more.

Related Categories

Related Job Pages

More Security Engineer Jobs

Togal.AI logo

Director of Security

Togal.AI

The AI-powered pre-construction takeoff software built BY estimators, FOR estimators

Full TimeRemoteTeam 11-50Since 2019H1B No Sponsor

• Own Togal's SOC 2 Type II program end-to-end — evidence collection, audit management, and control ownership in Vanta — so it's audit-ready year-round, not just before an audit. • Turn around customer security questionnaires and vendor security reviews quickly and accurately. • Be Togal's front-line security contact for customers and prospects, including calls with customer-side CISOs and security teams during deal cycles and MSA negotiations. • Design a written incident-response and notification policy — clear triggers, timelines, escalation paths, and roles — that's actually followed, replacing today's ad hoc handling by the CTO and CEO. • Lead incident response when something does happen: containment, investigation, and coordinating any outside help needed (e.g., an MDR/IR retainer for surge capacity) — this is "own it when it happens," not the day-to-day center of the role. • Evaluate whether to buy, outsource, or build additional security monitoring — assess managed detection/SIEM options against what we actually need before committing engineering time to standing anything up ourselves. • Assess and tighten cloud security posture (IAM, configuration, logging) alongside the CTO and engineering team. • Partner with Legal and the CEO on breach determination and external communication, as a defined process rather than a one-off scramble.

United States
Full TimeRemoteTeam 11-50H1B No Sponsor

• Perform vulnerability assessments on technology infrastructures; • Identify, prioritize and track vulnerabilities according to their risk level; • Manage remediation plans and follow up on security patches; • Participate in monitoring the security posture of technology environments; • Implement and maintain security dashboards and indicators; • Produce reports for various stakeholders; • Participate in automation activities related to vulnerability management; • Collaborate with operations, infrastructure and cybersecurity teams; • Conduct technology and security monitoring to stay up to date; • Contribute to the continuous improvement of security processes and practices.

Canada
VAILEXA logo

Senior Security Engineer

VAILEXA

Faster Solutions, Smarter Talent

Full TimeRemoteTeam 51-200Since 2020

• Support activities including data discovery, classification, tagging, labeling, risk prioritization, and remediation planning. • Partner with client security, DLP, SOC, and data governance teams • Triage findings surfaced through data security tooling • Drive remediation actions to closure • Coordinate with the SOC and response teams during findings • Document remediation decisions and closure evidence • Provide technical input into the remediation roadmap

United States
VAILEXA logo

Lead Data Security Architect

VAILEXA

Faster Solutions, Smarter Talent

Full TimeRemoteTeam 51-200Since 2020

• Understand objectives, scope, current-state challenges, governance expectations, and desired outcomes for the broader data security and remediation effort. • Review relevant SharePoint, OneDrive, Microsoft Purview, and Cyera context to identify where sensitive data exposure, oversharing, policy gaps, workflow constraints, or remediation backlog items are creating risk. • Connect discovery, classification, tagging, labeling, remediation, and governance activities into one integrated project approach that supports practical execution and long-term operating maturity. • Work with client teams to identify priority findings, ownership paths, decision points, remediation dependencies, and near-term actions requiring deeper technical validation. • Assess how sensitive data is currently discovered, classified, tagged, labeled, monitored, and remediated across SharePoint, OneDrive, Cyera, and Microsoft Purview. • Help define and refine classification, tagging, and labeling practices that support remediation, DLP policy alignment, access governance, and ongoing data protection objectives. • Provide architecture-level guidance on labeling strategy, DLP policy impacts, access exposure, exception handling, and control behavior across the client’s Microsoft 365 and DSPM environment. • Maintain and support client’s governance model, operational workflows, and risk reduction priorities. • Work hands-on in Cyera and Microsoft Purview to improve findings, validate root cause, confirm control behavior, and support remediation actions. • Support controlled validation activities in approved environments to confirm that remediation actions reduce exposure without creating unacceptable business disruption. • Partner with security operations, DLP, governance, compliance, and business stakeholders to ensure findings are triaged, assigned, remediated, and tracked consistently. • Define practical measures of remediation progress, including closure rate, exposure reduction, policy effectiveness, escalation clarity, and audit readiness. • Take action to integrate DSPM, Microsoft Purview, classification, labeling, DLP, access governance, and incident response workflows. • Document recommended ownership, cadence, escalation paths, and governance checkpoints so remediation can continue beyond the initial project window. • Apply solutions to business-case terms, connecting technical remediation to risk reduction, operational maturity, and governance outcomes.

United States