
Senior Security Engineer, Bug Bounty
Mozilla
Completely RemoteFull TimeInformation Technology
Posted Today
Job description
Responsibilities
- Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
- Act as the primary interface with external researchers and platforms like HackerOne
- Lead triage and technical validation of incoming reports across multiple intake channels
- Drive end-to-end vulnerability remediation by partnering with engineering teams
- Identify root causes and systemic issues to influence secure development practices
- Collaborate with the Security Incident Response Team (SIRT) on active incidents
- Perform targeted code reviews in JavaScript and Python
- Develop or leverage tooling to improve triage efficiency and program insights
Requirements
- 3+ years of experience in a security engineering role
- Experience operating bug bounty programs or bug hunting
- Practical experience with modern cloud technologies (AWS, GCP, Heroku, or Azure)
- Experience analyzing code and systems to move from vulnerability to root cause prevention
- Real-world experience in software development or engineering operations
- Strong communication, collaboration, and problem-solving skills
Preferred Qualifications
- Ability to develop tools in Python, Go, Rust, or JavaScript
Benefits
- Performance-based bonus plans
- Medical, dental, and vision coverage
- Retirement contributions with 100% immediate vesting
- Quarterly all-company wellness days
- Country specific holidays plus a day off for your birthday
- One-time home office stipend
- Annual professional development budget
- Quarterly well-being stipend
- Paid parental leave
About the Company
Mozilla Corporation is a non-profit-backed technology company dedicated to making the internet a global public resource that is open and accessible to all. We are the creators of Firefox and focus on privacy, security, and open-source software.
Skills & tools
PythonCybersecurity
What the team is looking for
Use this list as a quick fit check before you apply.
- 013+ years security engineering experience
- 02Bug bounty program operation experience
- 03Cloud technology experience (AWS/GCP/Azure)
- 04Software development experience
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches
Mozilla
Job details
- Work model
- Completely Remote
- Commitment
- Full Time
- Category
- Information Technology
- Posted
- Today
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches