You will help make JetStream's browser extension a production-grade enterprise enforcement point for AI usage. The extension should be easy for IT teams to deploy across thousands of endpoints, difficult for end users to bypass, capable of making real-time AI policy decisions, and lightweight enough that users don't notice it is running. You will have significant ownership over the architecture and help define how browser-based AI governance evolves as AI increasingly becomes part of everyday enterprise workflow
Responsibilities:
- Design, build, and maintain JetStream's enterprise browser extension across Google Chrome, Apple Safari, Mozilla Firefox, Brave and other Chromium-based browsers.
- Build a common architecture where possible while handling browser-specific APIs, security models, permissions, lifecycle behaviour, and packaging requirements.
- Work deeply with browser capabilities including: Manifest V3 and WebExtensions APIs, Content scripts and service workers, DOM and network-level instrumentation, Browser storage and secure local state, Authentication and enterprise SSO flows, Native messaging where required.
- Extension permissions and security boundaries.
- Cross-browser packaging, signing, upgrades, and version management.
In-Browser AI / SLM Runtime:
- Help build and optimise JetStream's Small Language Model running directly within the browser.
- The SLM participates in real-time decisions around: Prompt and content classification, AI guardrails, Sensitive-data detection, Policy enforcement, Domain and application controls, AI usage governance, Context-aware security decisions.
- You should understand the challenges of running AI inference inside resource-constrained browser environments, including model size, memory consumption, initialisation time, caching, CPU/GPU utilisation, latency, and impact on the user's browsing experience.
- Experience with WebAssembly, WebGPU, ONNX, quantised models, or other browser/edge AI runtimes is highly desirable.
Enterprise Policy Enforcement:
- Build capabilities that allow enterprises to centrally control how employees interact with AI applications and other governed web services.
Examples include:
- Allowing or blocking AI applications and domains
- Controlling which corporate or personal domains/accounts users can authenticate with
- Prompt and data-upload controls
- Applying policies based on user, group, application, domain, and AI service
- Enforcing policies locally while synchronising configuration with the JetStream control plane
- Capturing policy decisions and relevant activity for audit and governance
- A major part of the role is designing enforcement that is reliable while keeping the browsing experience fast and transparent to the user.
Enterprise Deployment and Device Management:
- Own and improve enterprise deployment and lifecycle management of the extension.
You should have hands-on experience with technologies such as:
- Microsoft Intune / MDM
- Windows MSI packaging
- Enterprise browser policies
- Managed extension deployment
- Silent installation and uninstall
- Forced extension installation
- Configuration profiles and policy distribution
- Extension upgrades and rollback
- macOS enterprise deployment
- Windows enterprise environments
- Experience troubleshooting large enterprise deployments across thousands of managed endpoints is especially valuable.
Performance, Reliability and Scale:
Browser extensions run continuously in a user's environment, so performance is critical.
You will be responsible for understanding and optimising:
- Browser startup impact
- Page-load impact
- CPU utilization
- Memory footprint
- SLM inference latency
- Extension/service-worker lifecycle
- DOM processing overhead
- Network overhead
- Local storage and caching
- Policy evaluation latency
- Behaviour across large numbers of tabs and long-running browser sessions
- You should be comfortable profiling browser behavior and identifying performance regressions before they affect enterprise users.
Backend Integration:
- JetStream's backend services are primarily written in TypeScript, JavaScript, Java, and Python.
You should be comfortable working with backend engineers and understanding APIs used for:
- Authentication and identity
- Policy synchronization
- Configuration management
- Telemetry and audit events
- AI governance
- Extension health and version management
- Strong Python knowledge is preferred, although deep backend specialisation is not required.
Requirements:
- 5-8+ years of software engineering experience with significant hands-on experience building production browser extensions.
- Deep knowledge of Chrome/Chromium extension architecture and Manifest V3
- Experience building and maintaining cross-browser extensions.
- Experience with Safari and Firefox extension architectures.
- Strong JavaScript/TypeScript skills, Java and Python.
- Strong understanding of browser security models, permissions, isolation, content scripts, service workers, and extension lifecycle.
- Experience with enterprise deployment through Intune, MDM, MSI, or equivalent technologies.
- Experience designing extension installation, upgrade, rollback, and uninstall workflows.
- Strong understanding of browser-extension performance and profiling.
- Experience building software deployed across large numbers of enterprise endpoints.
- Ability to debug complex browser, OS, policy, and enterprise-environment issues.
- Working knowledge of Python and REST/API-based backend systems.
AI Experience:
AI knowledge is critical for this position.
We are looking for someone who understands modern AI applications and ideally has experience with one or more of:
- LLMs and Small Language Models
- Browser/edge AI inference
- WebGPU / WebAssembly
- ONNX or similar inference runtimes
- Model quantization and optimization
- Prompt and content classification
- AI guardrails
- AI agents and agentic applications
- AI security
- AI governance and policy enforcement
You don't need to be an ML researcher, but you should understand how modern AI systems work and be comfortable building products where AI inference is part of the runtime architecture.
Nice to Have:
Experience in any of the following would be a strong plus:
- Browser or endpoint security products
- DLP / sensitive-data protection
- CASB / SSE / SASE technologies
- Identity and enterprise SSO
- OAuth/OIDC
- Security policy engines
- AI governance
- AI compliance
- AI activity monitoring and auditing
- Shadow AI discovery
- Security telemetry and observability
- Enterprise endpoint agents
- Web proxy or network security technologies

