All jobs
Save

Senior Security Engineer, Bug Bounty

Mozilla
Contract type
Ongoing
Work mode
100% remote
Experience
Mid-level · 3+ years

Job description

Key details

  • Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
  • Company mission
  • Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled

Primary stack

Core technologies

Python (Programming Language)AWSGoogle Cloud Platform (GCP)Azure

Benefits

  • Generous performance-based bonus plans to all eligible employees
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting
  • Quarterly all-company wellness days
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Requirements & details

  • 3+ years of demonstrated ability in a security engineering role
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (e.g., Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure)
  • Experience analyzing code and systems to move from vulnerability to root cause to prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (e.g., Python, Go, Rust, JavaScript) is a plus, but not required
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams
  • Python, JavaScript, AWS, Google Cloud Platform, Heroku, Microsoft Azure, HackerOne, Bugzilla
  • Python (Programming Language)
  • AWS
  • Google Cloud Platform (GCP)
  • Azure

Apply