Kernel
Browser Security Engineer
- Location
- San Francisco, CA, US
- Arrangement
- On-site
- Employment type
- Full-time
- Posted
- 13 August 2026 (about a month ago)
Checked about a month agoApplications go to the employer, never to RoleSprint
About this role
About Kernel
Kernel is crazy fast, open source browser infrastructure for AI agents. We handle autoscaling, observability, and the messy details of web interaction, so developers can focus on what their agents do instead of how they do it.
Teams at Cash App, Framer, and 7000+ others use Kernel for deep research, QA automation, and real-time web analysis. We've raised $22M from Accel, YC, and Vercel.
If you're interested in building critical infrastructure for agents on the web, we'd love to chat.
https://www.onkernel.com/docs/careers/browser-security-engineer#about-the-role
About the role
We’re hiring a Browser Security Engineer to harden and extend our Chromium-based browser runtime. You’ll work at the intersection of sandboxing, networking, and virtualization — ensuring our browsers run securely and efficiently across thousands of concurrent users.
https://www.onkernel.com/docs/careers/browser-security-engineer#what-you%E2%80%99ll-do
What you’ll do
Debug, patch, and optimize Chromium builds running inside Kernel’s microVM environments.
- Implement and maintain network isolation, proxy routing, and IP handling for browsers.
- Collaborate with infra engineers on unikernel-based isolation, process scheduling, and kernel security policies.
- Build internal tooling for binary analysis, crash triage, and vulnerability monitoring.
- Support the team in maintaining secure supply chain and reproducible builds for our browser images.
https://www.onkernel.com/docs/careers/browser-security-engineer#what-we%E2%80%99re-looking-for
What we’re looking for
- Deep familiarity with Chromium internals, browser sandboxes, or renderer/network stacks.
- Experience with Linux kernel, microVMs (Firecracker, Cloud-Hypervisor, Kata, gVisor, etc.), or container isolation.
- Strong debugging skills with strace, gdb, perf, or similar low-level tools.
- Knowledge of networking fundamentals (DNS, TCP/IP, NAT, proxies, TLS).
- Background in security engineering or browser hardening a plus.
https://www.onkernel.com/docs/careers/browser-security-engineer#what-you-can-expect-as-a-kernel
What you can expect as a Kernel
- Industry-competitive salary
- Above market equity
- Premium medical + dental coverage + dependent coverage
- Small, trusting team of senior + staff engineers
- Default async with minimal bureaucracy
- Daily lunches on us
- Unlimited PTO
- 401k + company match
- Relocation assistance
https://www.onkernel.com/docs/careers/browser-security-engineer#hiring-process
Hiring process
We have a simple process focused on real world collaboration and jointly getting to know each other:
1. 30 minute intro calls with one of Kernel’s co-founders
2. 45-minute technical interview (virtual)
3. Half-day on-site (in-person) working with our team on relevant technical challenges.
4. Offer!
https://www.onkernel.com/docs/careers/browser-security-engineer#how-to-apply
Locations
- San Francisco, CA, US
- New York City, NY, US
- Seattle, WA, US
- Cincinnati, OH, US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Ashby under the board identifier Usekernel, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 13 August 2026, last checked about a month ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.