Senior Security Engineer, Bug Bounty

Mozilla

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms like HackerOne
  • Lead triage and technical validation of incoming reports across multiple intake channels
  • Drive end-to-end vulnerability remediation by partnering with engineering teams
  • Identify root causes and systemic issues to influence secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents
  • Perform targeted code reviews in JavaScript and Python
  • Develop or leverage tooling to improve triage efficiency and program insights

Requirements

  • 3+ years of experience in a security engineering role
  • Experience operating bug bounty programs or bug hunting
  • Practical experience with modern cloud technologies (AWS, GCP, Heroku, or Azure)
  • Experience analyzing code and systems to move from vulnerability to root cause prevention
  • Real-world experience in software development or engineering operations
  • Strong communication, collaboration, and problem-solving skills

Preferred Qualifications

  • Ability to develop tools in Python, Go, Rust, or JavaScript

Benefits

  • Performance-based bonus plans
  • Medical, dental, and vision coverage
  • Retirement contributions with 100% immediate vesting
  • Quarterly all-company wellness days
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Paid parental leave

About the Company

Mozilla Corporation is a non-profit-backed technology company dedicated to making the internet a global public resource that is open and accessible to all. We are the creators of Firefox and focus on privacy, security, and open-source software.

Skills & tools

PythonCybersecurity

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 013+ years security engineering experience
  2. 02Bug bounty program operation experience
  3. 03Cloud technology experience (AWS/GCP/Azure)
  4. 04Software development experience
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches