Senior Security Engineer, Bug Bounty

🔥 14 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

🎯 Requirements

• 3+ years of demonstrated ability in a security engineering role. • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) • Experience analyzing code and systems to move from vulnerability → root cause → prevention • Real-world experience in software development and/or engineering operations • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees - we share in our success as one team • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) • Quarterly all-company wellness days where everyone takes a pause together • Country specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Apply Now

Similar Jobs

🔥 14 hours ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Information Systems Security Officer at CrowdStrike establishing security and compliance for Federal cloud environments. Focused on managing security controls and sustaining authorization for operation across federal systems.

AWS

Cloud

Cyber Security

🔥 18 hours ago

Red Cell Partners

11 - 50

⚕️ Healthcare Insurance

🔒 Cybersecurity

🔐 Security

Forward Deployed Engineer developing AI solutions for federal customers in national security. Engaging with mission teams to build production-ready systems and solve operational challenges.

Cloud

Distributed Systems

🕒 3 days ago

Matrix Design Group, Inc.

201 - 500

🏛️ Government

🚗 Transport

🤝 B2B

Federal Security & Compliance Consultant providing consulting and compliance support for Matrix Design Group's federal projects. Collaborating on security requirements and documentation while supporting client engagements.

Cyber Security

🕒 3 days ago

Cyclotron, Inc.

51 - 200

🏢 Enterprise

☁️ SaaS

⚡ Productivity

Security Architect at Cyclotron designing enterprise deployments of Microsoft 365 Identity and Device Management tools. Collaborating with clients to enhance protection of Microsoft-based assets.

Azure

Cloud

Jamf

🕒 3 days ago

rockITdata

11 - 50

🤖 Artificial Intelligence

Security Control Assessor supporting cybersecurity assessments and compliance activities for federal healthcare systems. Collaborating with teams to meet Federal security requirements and support modernization.

Cyber Security