PhiPhi
Left arrowReturn to job listings

Security Engineer

Category

Engineering

Available in

  • San Francisco
  • London
  • Beijing
  • Shanghai
  • Shenzhen
  • Qingdao

About Phinomenon

Phinomenon is built by browser and cloud veterans: our founders are behind FydeOS (a Chromium-based OS trusted by millions) and QingCloud (one of China's earliest API-first IaaS platforms, founded in 2012). Fresh off a healthy, eight-figure Series A raise, we have the runway to dream big without panicking about next week's payroll. With folks working from San Francisco, London, Beijing, Shanghai and Shenzhen, we are proudly global and friendly to your time zone, with overlapping hours so we can all actually talk. We ship fast and ship hard, but burnout is so last decade: we bake in wellness stipends, mandatory recharge days and flexible schedules, because great code comes from healthy lives. No timecards, no surveillance software, no weekend team-building. We'd rather hand you the best tools money can buy (Claude Max, ChatGPT Business and Cursor Ultra come standard) and trust you with them. We don't fetishise years of experience, degrees or big-tech logos, and fresh graduates are more than welcome: show us what you have built and how you think. If you want to build the nextgen browser that actually, you know, gets you, while still enjoying your evenings and maintaining upright posture, welcome home.

About the Role

As a Security Engineer at Phinomenon, you'll lead the charge on browser security: threat modeling, sandboxing, encryption, secure coding, incident response, the whole works. Your job is to make sure no hacker, malicious extension, or rogue network can compromise users' data or privacy as they interact with AI-powered features. You'll work closely with our C++, frontend, and cloud teams to build a defense-in-depth architecture that scales globally.

Responsibilities

  • Define and enforce browser security architecture: sandboxing, site isolation, CSP, and secure IPC
  • Threat model key components (rendering engine, extensions, AI integrations, network layers)
  • Implement and maintain secure storage and encryption for user profiles and sensitive data
  • Bake security into the development lifecycle: code reviews, static and dynamic analysis, security testing
  • Monitor, detect, and respond to security incidents or suspicious behaviour across platforms
  • Audit and harden dependencies, third-party libraries, browser extensions, and APIs
  • Partner with C/C++, frontend, and backend teams to remediate vulnerabilities fast
  • Build tooling and automation for penetration testing, fuzzing, and continuous security validation

Requirements

  • Demonstrated depth in application or browser security, systems security, or a related field. CVEs, write-ups, and war stories count for more than tenure; a brilliant new grad with real research is welcome.
  • Strong understanding of browser security features: sandboxing, CSP, site isolation, extension security
  • Experience threat modeling and implementing defense-in-depth architectures
  • Proficiency in secure coding practices (C/C++, Swift, JS), static analysis, and code review
  • Hands-on experience with encryption, secure storage, key management, and TLS/PKI
  • Skill in dynamic testing: fuzzing, penetration tests, and CI/CD security pipelines
  • Incident response experience: triage, root cause, mitigation
  • Excellent collaboration skills and comfort guiding developers toward secure implementations

Nice to Have

  • Experience working directly on Chromium or Blink/WebKit security layers
  • Background in extension security or mitigating man-in-the-browser and extension threats
  • Familiarity with browser profile security and privacy hardening
  • Knowledge of networking and protocol security (TLS, DNS, QUIC)
  • Certifications like OSCP or CISSP (nice, but your track record speaks louder)