Back to jobs
C
Cerby · posted Jul 25, 2026

Sr. Software Engineer (Frontend) - Extensions Team

Remote Remote (United States) Full-time Senior

// Job description

At Cerby, software engineers are at the heart of driving technology and product innovation. As a Senior Software Engineer on the Extension team, you will own and scale the browser extension at the core of Cerby's platform — the surface where users manage application passwords, autofill and inject credentials across the sites they use every day, and authenticate through passkeys and federated identity providers. The extension is a cross-browser Manifest V3 product shipping to Chrome, Edge, Firefox, and Safari, backed by service-worker-driven background synchronization, secure session lifecycle management. In this role you will own the quality, performance, and security of the extension end-to-end, help lead a security-first engineering culture, and sharpen a product experience that our users' most sensitive credential interactions depend on. KEY RESPONSIBILITIES - Design and Develop: Build scalable, high-performance software solutions that align with business goals and user needs. - Code Excellence: Write clean, maintainable, and efficient code, adhering to best practices and coding standards. - Security Mindset: Actively contribute to our security-first approach by proactively identifying vulnerabilities and implementing robust solutions. QUALIFICATIONS & REQUIRED SKILLS Technical Expertise: - Manifest V3 service-worker model: ephemeral execution and state persistence across termination (chrome.alarms, keep-alive), plus the distributed-system concerns that come with it — cross-tab coordination, background sync, and token-refresh/session races. - Content scripts and injection into untrusted pages: isolated-world vs MAIN-world execution, Shadow DOM isolation, and MutationObserver-based DOM resilience. - Cross-browser delivery to Chrome, Edge, Firefox, and Safari: API divergence (chrome.* vs browser.*), MV2/MV3 differences, Safari packaging, and per-store review/release (staged rollout, rollback, remote-code ban). Proficiency in: - Strong React + TypeScript with utility-first CSS (e.g., TailwindCSS), building UI across extension surfaces (popup, options, side panel, in-page) that is responsive, accessible (WCAG/ARIA), and reusable via a design system. - Core frontend and browser fundamentals: browser API, client-side storage (localStorage, IndexedDB, chrome.storage), networking (fetch/XHR), and performance optimization. - Designing, consuming, and optimizing REST APIs with efficient data-fetching and caching (e.g., TanStack Query). - Front-end security: mitigating XSS, CSRF, and CORS, and applying CSP, including the extension's own CSP model. - Modern authentication and identity: OAuth 2.0 / OIDC, SAML, SCIM, and WebAuthn / FIDO2 / passkeys; prior IAM or security experience. - Testing (unit, integration, component) and observability (metrics, traces, logs; OpenTelemetry/Datadog a plus), owning delivery end-to-end from design to production in an Agile/CI-CD environment.
// apply.now()

Interested? Ship your application.

You'll be taken to the original listing to view the full details and apply.

View original & apply