Senior Security Engineer, Bug Bounty

1 month, 4 weeks ago
Full-time
Senior
Cybersecurity
Mozilla

Mozilla

Mozilla, the maker of Firefox, is a non-profit organization ensuring an open, safe, and accessible internet for all users worldwide.

Internet Software & Services
251-1K
Founded 2005
$2M raised

Description

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Serve as the primary interface with external researchers and platforms such as HackerOne.
  • Lead triage and technical validation of incoming vulnerability reports across HackerOne, Bugzilla, and email.
  • Drive end-to-end vulnerability remediation in partnership with engineering teams.
  • Identify root causes and systemic issues and influence long-term improvements in secure development practices.
  • Collaborate with the Security Incident Response Team on active incidents and post-incident reviews.
  • Perform targeted code reviews, primarily in JavaScript and Python, during investigations and high-risk changes.
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights.
  • Work with Mozilla product and SIRT teams to mitigate security risks and incidents.

Requirements

  • 3+ years of demonstrated experience in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation, scaling, and/or bug hunting.
  • Practical experience with modern cloud technologies such as Amazon Web Services, Google Cloud Platform, Heroku, or Microsoft Azure.
  • Experience analyzing code and systems to move from vulnerability to root cause to prevention.
  • Real-world experience in software development and/or engineering operations.
  • Ability to develop tools as needed in programming languages such as Python, Go, Rust, or JavaScript is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills with the ability to influence cross-functional teams.
  • Formal credentials are less important than real-world experience, curiosity, passion, and a growth mindset.

Benefits

  • Generous performance-based bonus plans.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting.
  • Quarterly all-company wellness days.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits including life/AD&D, disability, and EAP, depending on country.
  • Remote work under #LI-REMOTE.
  • Salary range of $104,000–$139,000 CAD for Canada Tier 1 locations and $95,000–$126,000 CAD for Canada Tier 2 locations.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer

Lever 251-1K Professional Services

Latitude is hiring a fully remote Senior Security Engineer to lead security architecture, authorization, and risk remediation for supply chain and logistics software supporting a federal health customer.

Agile AWS Azure HIPAA
12 minutes ago

Security Engineer

Lever 251-1K Professional Services

Latitude is hiring a fully remote Security Engineer to secure supply-chain and logistics software for a federal health customer by designing controls, integrating security into delivery processes, and validating changes for safe release.

CI/CD HIPAA
12 minutes ago

MEDR Threat Engineer US work hours

Proficio 51-250 Professional Services

Proficio is seeking a Managed EDR Threat Engineer to guide the evolution of its managed endpoint detection, response, visibility, and prevention services while collaborating with engineering, SOC, MDR, sales, and customer teams.

Carbon Black Cybersecurity Linux macOS Network Security PowerShell Python
1 day, 23 hours ago

DevSecOps and Security Compliance Engineer

K.L. Scott & Associates 11-50 Professional Services

K.L. Scott & Associates, LLC is hiring a DevSecOps and Security Compliance Engineer to integrate security into SAP delivery and operations for federal clients while improving deployment controls, addressing vulnerabilities, and maintaining authorization evidence.

CI/CD DevSecOps SAP Secrets Management
1 day, 23 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers