2 months ago
Remote, United StatesSenior
Responsibilities
- Design, build, scale, and maintain Cerby’s cross-browser Manifest V3 browser extension across Chrome, Edge, Firefox, and Safari.
- Develop responsive, accessible, reusable frontend interfaces for popup, options, side-panel, and in-page extension surfaces using React, TypeScript, and utility-first CSS.
- Own extension performance, reliability, quality, and security, including service-worker lifecycle management, background synchronization, session handling, and cross-tab coordination.
- Implement secure content-script injection, message passing, sender and origin validation, isolated-world and MAIN-world execution, Shadow DOM isolation, and resilient DOM interactions.
- Manage frontend dependency and supply-chain security through PNPM workspace governance, CVE auditing, patching SLAs, and transitive-dependency risk management.
- Design and consume REST APIs with efficient data fetching and caching, and deliver features end-to-end from design through production.
- Conduct code reviews, mentor engineers, share technical knowledge, improve engineering practices, and document systems through runbooks, ADRs, onboarding guides, and post-mortems.
- Collaborate with product managers, engineering managers, UX designers, and engineers in a remote-first environment while responsibly incorporating AI-assisted development tools.
Requirements
- At least 5 years of professional software engineering experience focused on building and scaling SaaS applications.
- Prior experience developing and maintaining distributed applications.
- Strong React and TypeScript experience with utility-first CSS such as TailwindCSS.
- Deep experience with browser extension development, including Manifest V3 service workers, content scripts, message passing, cross-browser APIs, native messaging, and extension performance.
- Strong knowledge of browser fundamentals, client-side storage, networking, REST APIs, data-fetching, caching, accessibility, and frontend performance optimization.
- Experience with frontend security practices including XSS, CSRF, CORS, CSP, secure authentication flows, dependency security, and supply-chain risk.
- Experience with OAuth 2.0, OIDC, SAML, SCIM, WebAuthn, FIDO2, passkeys, IAM, or security-related systems.
- Experience with unit, integration, and component testing, observability, and end-to-end software delivery.
- Previous experience mentoring junior developers and conducting security-first code reviews.
- Strong analytical, problem-solving, communication, collaboration, product-mindedness, and mentoring skills.
- Preferred experience with SOC 2, GDPR, HIPAA, encryption, key management, and venture-funded high-growth SaaS startups.
Benefits
- Remote-first work environment with collaboration across time zones.
- Opportunity to work on enterprise security, identity automation, browser extensions, and sensitive credential-management workflows.
- Culture that encourages experimentation with AI-assisted development tools and open sharing of technical learnings.
Tech Stack
Categories
About Cerby
Cerby builds an identity security platform for enterprise IT and security teams to secure and automate access to disconnected or nonfederated applications. Its SaaS pairs an access-management backend with a cross-browser extension for credential injection, passkeys, and lifecycle automation where SSO or SCIM are unavailable. Founded in 2020 and headquartered in Alameda, California, the company is privately held.
