Skip to main content
Mozilla Corporation

Senior Security Engineer, Bug Bounty

RemoteUnited States only
Published
Role
Security
Experience
Senior
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior security engineer with 3+ years in security engineering and experience operating bug bounty programs or bug hunting. Needs cloud experience and ability to analyze vulnerabilities from report to root cause and prevention. Software development or engineering operations experience is required.

Core skills

Bug bountyHackerOneVulnerability triage

Required skills

AWS/GCP/Heroku/Microsoft Azure

Optional skills

PythonGoRustJavaScript

What you'll do

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms such as HackerOne, fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels including HackerOne, Bugzilla, and email
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team on active incidents and post-incident reviews
  • Perform targeted code reviews, primarily JavaScript and Python, during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What they require

  • 3+ years of demonstrated ability in a security engineering role
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies such as Amazon Web Services, Google Cloud Platform, Heroku, or Microsoft Azure
  • Experience analyzing code and systems to move from vulnerability to root cause to prevention
  • Real-world experience in software development and/or engineering operations
  • Preferred: Ability to develop your own tools as needed in a variety of programming languages such as Python, Go, Rust, or JavaScript
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams
  • Formal credentials are valued, but real-world experience, curiosity, passion, and a growth mindset matter more

Benefits

  • Generous performance-based bonus plans to all eligible employees
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting regardless of whether you contribute
  • Quarterly all-company wellness days
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits including life/AD&D, disability, and EAP, varying by country

Mozilla Corporation is a non-profit-backed technology company that makes products like Firefox and builds open-source software to make the internet better for people. Ecosystem Services builds and operates back-end platforms powering Mozilla products and services, including privacy, security, notifications, real-time updates, and configuration delivery.

TechnologyEnterprisemozilla.org

What people say about this company

4.1/ 5

  • Employees value the company's commitment to open-source principles and its mission to promote internet privacy.
  • The work-life balance is often highlighted as a significant benefit.
  • Some employees have noted challenges with management and communication within teams.

Details

Apply routeGreenhouse
Salary not disclosed