Kernel

Browser Security Engineer

Kernel San Francisco, California, United States · $225K–$250K/yr

Biotechnology Research · 11-50 employees

Yesterday
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will harden and optimize Chromium-based browser runtimes within microVM environments while implementing robust network isolation and security policies. Additionally, you will collaborate on infrastructure security and build internal tooling for vulnerability monitoring and binary analysis.

What they look for

Chromium internals Browser sandboxing Linux kernel MicroVMs Container isolation Strace Gdb Perf Networking fundamentals DNS TCP/IP NAT Proxies TLS Security engineering Browser hardening

Requirements

Candidates must possess deep expertise in Chromium internals, browser sandboxes, and Linux kernel-level virtualization technologies. Strong proficiency in low-level debugging tools and networking fundamentals is essential for this role.

Benefits

Competitive salary Equity Medical coverage Dental coverage Dependent coverage Unlimited PTO 401k Company match Relocation assistance Daily lunches

Full description

About Kernel

Kernel is crazy fast, open source browser infrastructure for AI agents. We handle autoscaling, observability, and the messy details of web interaction, so developers can focus on what their agents do instead of how they do it.

Teams at Cash App, Framer, and 7000+ others use Kernel for deep research, QA automation, and real-time web analysis. We've raised $22M from Accel, YC, and Vercel.

If you're interested in building critical infrastructure for agents on the web, we'd love to chat.

About the role

We’re hiring a Browser Security Engineer to harden and extend our Chromium-based browser runtime. You’ll work at the intersection of sandboxing, networking, and virtualization — ensuring our browsers run securely and efficiently across thousands of concurrent users.

What you’ll do

Debug, patch, and optimize Chromium builds running inside Kernel’s microVM environments.

  • Implement and maintain network isolation, proxy routing, and IP handling for browsers.
  • Collaborate with infra engineers on unikernel-based isolation, process scheduling, and kernel security policies.
  • Build internal tooling for binary analysis, crash triage, and vulnerability monitoring.
  • Support the team in maintaining secure supply chain and reproducible builds for our browser images.

What we’re looking for

  • Deep familiarity with Chromium internals, browser sandboxes, or renderer/network stacks.
  • Experience with Linux kernel, microVMs (Firecracker, Cloud-Hypervisor, Kata, gVisor, etc.), or container isolation.
  • Strong debugging skills with strace, gdb, perf, or similar low-level tools.
  • Knowledge of networking fundamentals (DNS, TCP/IP, NAT, proxies, TLS).
  • Background in security engineering or browser hardening a plus.

What you can expect as a Kernel

  • Industry-competitive salary
  • Above market equity
  • Premium medical + dental coverage + dependent coverage
  • Small, trusting team of senior + staff engineers
  • Default async with minimal bureaucracy
  • Daily lunches on us
  • Unlimited PTO
  • 401k + company match
  • Relocation assistance

Hiring process

We have a simple process focused on real world collaboration and jointly getting to know each other:

  • 30 minute intro calls with one of Kernel’s co-founders
  • 45-minute technical interview (virtual)
  • Half-day on-site (in-person) working with our team on relevant technical challenges.
  • Offer!

Similar roles