Staff Security Engineer – Product Security

Job not on LinkedIn

2 days ago

Apply Now
Logo of Mozilla

Mozilla

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

📋 Description

• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews. • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.

🎯 Requirements

• 5+ years of relevant hands-on experience in product and application security. • 5+ years of experience and proficiency in secure coding practices, application security testing (SAST, DAST), threat modeling, and vulnerability assessment. • Experience in one or more languages like Python, Go, Java, or JavaScript, required for automation and code review. • Familiarity with security tools like Burp Suite, Nessus, and tools for CI/CD automation. • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. • Formal credentials are great, but real-world experience, curiosity, passion and a builder’s mindset matter more.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees - we share in our success as one team • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) • Quarterly all-company wellness days where everyone takes a pause together • Country specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Apply Now

Similar Jobs

2 days ago

GitLab

1001 - 5000

🤖 Artificial Intelligence

🏢 Enterprise

☁️ SaaS

Principal Engineer driving security strategy for GitLab's cloud infrastructure. Leading initiatives and mentoring engineers to enhance security posture and efficiency.

November 25

TD

10,000+ employees

🏦 Banking

💸 Finance

Information Security Specialist managing technology controls and information security programs at TD Bank. Responsible for regulatory compliance and risk management in the financial sector.

🇨🇦 Canada – Remote

💵 $91.2k - $136.8k / year

💰 Grant on 2023-10

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

November 20

Narvar

201 - 500

🛍️ eCommerce

☁️ SaaS

🛒 Retail

Head of Information Security responsible for enterprise security programs at Narvar. Leading security efforts for SaaS products and collaborating with business units on risk management.

🇨🇦 Canada – Remote

💵 $200k - $300k / year

💰 $30M Series C on 2018-08

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

November 15

Fullscript

201 - 500

⚕️ Healthcare Insurance

🧘 Wellness

☁️ SaaS

Senior Security Engineer shaping technical vision for AI and product security at Fullscript. Leading design, implementation, and fostering a culture of security excellence across teams.

November 14

Desjardins

10,000+ employees

🏦 Banking

💸 Finance

Offensive Security Advisor performing adversary simulation and threat monitoring at Desjardins. Collaborating with cyber-defence teams and implementing security measures across IT systems.

🗣️🇫🇷 French Required

Developed by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com