Senior Security Engineer, Bug Bounty

🕒 July 27

🇩🇪 Germany – Remote

💵 €68k - €91k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 2%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

🎯 Requirements

• 3+ years of demonstrated ability in a security engineering role. • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) • Experience analyzing code and systems to move from vulnerability → root cause → prevention • Real-world experience in software development and/or engineering operations • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees - we share in our success as one team • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) • Quarterly all-company wellness days where everyone takes a pause together • Country specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Apply Now

Similar Jobs

🕒 July 27

intellux consulting GmbH

2 - 10

🔒 Cybersecurity

💼 Consulting

🤝 B2B

Senior Consultant leading SAP Security projects in a growing consultancy supporting client success. Direct collaboration with management in a startup environment.

🗣️🇩🇪 German Required

Cloud

🕒 July 23

ARES Consulting GmbH

11 - 50

🚘 Automotive

🏥 Healthcare

📦 Logistics

Senior Cloud Security Architect designing secure IT infrastructures and advising public sector clients for ARES. Implementing security standards, conducting risk assessments, and ensuring compliance with regulations.

🗣️🇩🇪 German Required

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

🕒 July 21

S + S Regeltechnik GmbH

51 - 200

💼 Consulting

📦 Logistics

🏭 Manufacturing

Senior IT-Security Expert building next-gen GovTech solutions for public sector. Collaborating with teams to implement IT security concepts and ensuring compliance with regulations.

🗣️🇩🇪 German Required

🕒 July 20

instellix

51 - 200

☁️ SaaS

💳 Fintech

🤝 B2B

Senior Manager for Compliance and Information Security at instellix, a SaaS platform transforming Subscription Management and Billing. Leading compliance and security governance with strategic partnerships across departments.

🗣️🇩🇪 German Required

🕒 July 15

XAAS

11 - 50

💼 Consulting

📣 Marketing

📦 Logistics

Senior Consultant in the field of information security and IT security advising clients based on BSI IT-Grundschutz. Responsible for building ISMS and conducting security checks and audits.

🗣️🇩🇪 German Required