M
Senior Security Engineer - Bug Bounty
Mozilla
Contract type
Ongoing
Work mode
100% remote
Experience
Mid-level · 3+ years
Job description
Key details
- Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
- Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
- Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
- Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
- Identify root causes and systemic issues, and influence long-term improvements in secure development practices
- Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
- Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
- Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
- Company mission
- Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled
Primary stack
Core technologies
AzurePython (Programming Language)AWSGoogle Cloud Platform (GCP)Go
Benefits
- Generous performance-based bonus plans to all eligible employees
- Rich medical, dental, and vision coverage
- Generous retirement contributions with 100% immediate vesting
- Quarterly all-company wellness days
- Country specific holidays plus a day off for your birthday
- One-time home office stipend
- Annual professional development budget
- Quarterly well-being stipend
- Considerable paid parental leave
- Employee referral bonus program
- Other benefits (life/AD&D, disability, EAP, etc. - varies by country)
Requirements & details
- 3+ years of demonstrated ability in a security engineering role
- Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
- Practical experience working with modern cloud technologies (e.g., Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
- Experience analyzing code and systems to move from vulnerability → root cause → prevention
- Real-world experience in software development and/or engineering operations
- Ability to develop your own tools as needed in a variety of programming languages (e.g., Python, Go, Rust, Javascript, etc.) is a plus, but not required
- Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams
- Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more
- Python, JavaScript, AWS, Google Cloud Platform, Heroku, Microsoft Azure, Go, Rust
- Azure
- Python (Programming Language)
- AWS
- Google Cloud Platform (GCP)
- Go
