Browser Security Engineer
Location: Ramat Gan, Israel (IL)
Description
Reflectiz is a fast-growing cybersecurity company specializing in proactive website security. Our unique remote monitoring technology helps organizations reduce security, privacy, and compliance risks-protecting critical digital assets that traditional solutions can’t fully cover.
Since our founding in 2019, we’ve built a global customer base that includes Fortune 500 enterprises and leading brands across North America, EMEA, and APAC. With strong year-over-year growth and a financially solid foundation, Reflectiz offers both stability and exciting opportunities for personal and professional development. Our teams in Israel and the United States foster an inclusive, collaborative culture that combines innovation with professionalism-allowing us to consistently deliver exceptional value to our customers.
We’re looking for a hands-on Browser Security Engineer with a strong hacker mindset, someone who enjoys diving into complex systems, questioning assumptions, and breaking things to truly understand how they work.All scanning is authorized and performed on customer-owned assets or explicit allowlists. In this role, you will build and maintain a Chromium-based scanning runtime that executes and instruments JavaScript on real websites at scale. You will dive deep into server-side logic and underlying browser mechanisms, uncovering and neutralizing security risks across complex systems.
Responsibilities
- Design, build, and evolve a web scanning engine that actively probes, analyzes, and stress-tests complex web applications to uncover hidden security risks
- Develop secure, scalable backend services in Node.js and TypeScript to power large-scale scanning and analysis infrastructure
- Engineer high-performance systems optimized for heavy load, real-world traffic patterns, and adversarial environments
- Optimize performance, resilience, and security, balancing deep inspection capabilities with production-grade reliability
- Work at the runtime level (event loop, async patterns, memory management, worker threads, clustering, streams, networking, queues, retries, and backpressure) to ensure efficiency and stability
- Debug and extend Chromium-based browser internals to better understand rendering, networking, and JavaScript execution in modern web applications
- Collaborate closely with security researchers, think like an attacker, and translate offensive findings into robust defensive mechanisms
- Handle advanced web defenses including WAFs, bot managers (challenge pages, fingerprinting, behavioral detection), rate limiting, dynamic rendering, SPAs, heavy JavaScript applications, authentication flows, and geo-based restrictions
Requirements
- 3–5 years of hands-on experience building complex web applications using JavaScript/TypeScript
- Strong understanding of how browsers work (DOM, rendering flow, performance implications)
- Good understanding of web security principles and common vulnerabilities (XSS, CSRF, etc.)
- Experience working on complex production systems, with the ability to quickly grasp architectures, mentally map system components, and reason at a low level
- Experience collaborating with Technical Engineers, Customer Success, and Sales to deliver secure solutions
- Curious, investigative mindset - enjoys dissecting complex systems and understanding how things break
Advantage
- Experience with Chromium internals, enhancing low-level browser understanding for web security
- Hands-on experience with Docker and Terraform, enabling efficient deployment and infrastructure automation
- Deep familiarity with GCP services, leveraging cloud capabilities for scalable, secure backend systems
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
