Remote Senior Web Security Engineer (ProdSec) in Manchester

Remote Senior Web Security Engineer (ProdSec) in Manchester

Manchester Full-Time No working from home possible
I

Senior Web Security Engineer

About iProov

iProov provides science-based biometric solutions that enable the world’s most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award-winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance.

This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose.

The Role

Reports to: Head of Red Team

Location: UK (Flexible)

Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits

We're looking for an experienced Senior Web Security Engineer to design, build, and secure high-performance web applications that run in some of the world's most demanding environments.

In this role, you'll work at the intersection of browser security, JavaScript runtimes, WebAssembly, anti-reverse engineering, and application hardening. You'll help protect client-side applications against tampering, reverse engineering, and sophisticated attacks while developing highly optimized code that performs consistently across modern browsers and devices.

This is a hands-on engineering position for someone who enjoys solving difficult technical problems, understands the realities of client-side security, and is passionate about pushing the boundaries of what's possible in the browser.

How you can make an impact

You'll work on technically challenging problems that few engineering teams tackle—protecting sophisticated client-side applications in hostile environments. You'll collaborate with experts in browser technology, security, cryptography, and systems engineering while building solutions used at global scale.

If you're passionate about JavaScript internals, WebAssembly, browser security, and solving complex engineering problems, we'd love to hear from you.

  • Design and implement secure JavaScript and WebAssembly components for production web applications.
  • Develop techniques to protect client-side code from tampering, reverse engineering, debugging, automation, and exploitation.
  • Design and implement anti-tamper, integrity verification, and runtime protection mechanisms.
  • Build high-performance WebAssembly modules using C++, Rust, or AssemblyScript.
  • Analyse browser behaviour, JavaScript engines, and WebAssembly runtimes to identify security risks and performance opportunities.
  • Research emerging attack techniques targeting web applications and develop practical mitigations.
  • Collaborate closely with developers, product, and red teams to integrate security into the development lifecycle.
  • Investigate vulnerabilities, perform root-cause analysis, and develop long-term remediation strategies.
  • Contribute to technical architecture and mentor other engineers on secure development practices.

What we would like to see from you

Within your first year, you'll have shipped secure, production-grade JavaScript and WebAssembly components that real users depend on every day. Along the way, you'll have introduced new techniques that materially strengthen our resistance to reverse engineering and client-side attacks, pushing the boundaries of what's possible in browser-based security. You'll have found ways to make the application faster without ever compromising its security guarantees, proving that performance and protection aren't a trade-off.

Beyond the code itself, you'll have helped define the engineering standards that shape how we approach browser security and secure client-side architecture, leaving a lasting mark on how we build. And by the end of that first year, you'll have become the person engineers across the organisation turn to when they need answers on web security, a trusted technical leader whose influence extends well beyond your own team.

Technical Expertise

  • Expert-level JavaScript (ES6+) and TypeScript.
  • Strong experience developing production WebAssembly applications.
  • Experience with Rust, C++, or another systems programming language used to produce WASM modules.
  • Deep understanding of browser internals and modern web platform APIs.
  • Experience securing client-side applications against:
    • Reverse engineering
    • Runtime modification
    • Instrumentation frameworks
    • Code injection
  • Experience with secure software architecture.

Security Knowledge

Experience in several of the following:

  • JavaScript de-obfuscation and obfuscation techniques
  • WASM binary analysis
  • Static and dynamic analysis
  • Anti-debugging techniques
  • Anti-tamper technologies
  • Runtime integrity verification
  • Secure code signing and integrity checking
  • Software protection techniques
  • Secure SDLC practices

Engineering Experience

  • 5+ years of software engineering experience.
  • Experience designing highly performant browser-based applications.
  • Strong testing, debugging, and profiling skills.
  • Experience working with CI/CD pipelines and automated security testing.
  • Comfortable working across Windows, macOS, Linux, and mobile browsers.
  • Excellent communication skills with the ability to explain complex technical concepts clearly.

Nice to Have

  • Experience with V8, SpiderMonkey, JavaScriptCore, or Chromium internals.
  • Knowledge of WebGPU, WebRTC, or WebCodecs.
  • Experience with binary instrumentation and compiler toolchains.
  • Experience building SDKs or developer platforms.
  • Knowledge of mobile browser security.
  • Experience with biometrics, identity verification, or fraud prevention technologies.
  • Contributions to open-source security tools or security research publications.

Benefits

  • 25 days Annual Leave, plus 8

Remote Senior Web Security Engineer (ProdSec) in Manchester employer: iProov

iProov is an exceptional employer that champions diversity and inclusion, fostering a culture where every individual feels valued and empowered to contribute their unique talents. With a hybrid working model in the UK, employees enjoy a wealth of benefits including generous annual leave, personal career coaching, and access to an award-winning learning platform, all while being part of a dynamic team dedicated to innovation in biometric security solutions.

I

Contact Details:

iProov Recruitment Team