1:00 PM - 2:00 PM
Senior Product Manager Interview
Sarah Jenkins

Cerby
·20 days agoCerby
·20 days agoLocation
remote, United States
Commitment
Full Time
Level
Senior (5+ years)
At Cerby, software engineers are at the heart of driving technology and product innovation. As a Senior Software Engineer on the Extension team, you will own and scale the browser extension at the core of Cerby's platform — the surface where users manage application passwords, autofill and inject credentials across the sites they use every day, and authenticate through passkeys and federated identity providers. The extension is a cross-browser Manifest V3 product shipping to Chrome, Edge, Firefox, and Safari, backed by service-worker-driven background synchronization, secure session lifecycle management.
In this role you will own the quality, performance, and security of the extension end-to-end, help lead a security-first engineering culture, and sharpen a product experience that our users' most sensitive credential interactions depend on. Because the extension injects UI into pages we don't control and brokers our users' most sensitive data, security is not a phase of the work — it is the work. You are also expected to embrace AI as a core part of how we build, actively exploring and incorporating AI-assisted tools and practices into your daily development workflow to improve team efficiency and accelerate impact.
Experience:
5+ years of professional software engineering experience, with a focus on building and scaling SaaS applications.
Prior experience developing and maintaining Distributed Applications
Previous experience mentoring junior developers and conducting security-first code reviews
Technical Expertise:
Manifest V3 service-worker model: ephemeral execution and state persistence across termination (chrome.alarms, keep-alive), plus the distributed-system concerns that come with it — cross-tab coordination, background sync, and token-refresh/session races.
Content scripts and injection into untrusted pages: isolated-world vs MAIN-world execution, Shadow DOM isolation, and MutationObserver-based DOM resilience.
Message passing across content scripts, service worker, popup/side panel, and offscreen documents, with sender/origin validation as a security boundary.
Cross-browser delivery to Chrome, Edge, Firefox, and Safari: API divergence (chrome.* vs browser.*), MV2/MV3 differences, Safari packaging, and per-store review/release (staged rollout, rollback, remote-code ban).
Native messaging with native host applications, plus extension-specific performance (service-worker cold-start, bundle size, content-script efficiency).
Proficiency in:
Strong React + TypeScript with utility-first CSS (e.g., TailwindCSS), building UI across extension surfaces (popup, options, side panel, in-page) that is responsive, accessible (WCAG/ARIA), and reusable via a design system.
Core frontend and browser fundamentals: browser API, client-side storage (localStorage, IndexedDB, chrome.storage), networking (fetch/XHR), and performance optimization.
Designing, consuming, and optimizing REST APIs with efficient data-fetching and caching (e.g., TanStack Query).
Front-end security: mitigating XSS, CSRF, and CORS, and applying CSP, including the extension's own CSP model.
Modern authentication and identity: OAuth 2.0 / OIDC, SAML, SCIM, and WebAuthn / FIDO2 / passkeys; prior IAM or security experience.
Testing (unit, integration, component) and observability (metrics, traces, logs; OpenTelemetry/Datadog a plus), owning delivery end-to-end from design to production in an Agile/CI-CD environment.
Nice to have:
Experience working with security compliance frameworks (SOC 2, GDPR, HIPPA, etc.)
Familiarity with encryption processes and key management.
Prior experience in a venture funded high-growth SaaS startup preferred.