Senior Security Engineer, Bug Bounty

🕒 il y a 2 mois

🇺🇸 États-Unis – Télétravail

💵 $137 000 - $183 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

👻 Score fantôme 8%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Mozilla

Mozilla

501 - 1000 employés

Fondée en 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla est une organisation à but non lucratif dédiée à la promotion d’un internet ouvert et accessible. Elle est à l’origine du navigateur Firefox, très populaire, qui met l’accent sur la confidentialité des utilisateurs, la rapidité et le contrôle. Mozilla propose également une gamme de produits axés sur la sécurité et la confidentialité en ligne, notamment Mozilla VPN, Firefox Relay et Mozilla Monitor. L’organisation participe aussi à des projets open source, à l’innovation en IA et à la défense des droits numériques. Mozilla vise à donner aux utilisateurs les moyens d’agir grâce à des technologies fiables et à des politiques qui protègent la vie privée, soutiennent le développement d’une IA open source et favorisent la responsabilisation des entreprises technologiques.

Description

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

🎯 Exigences

• 3+ years of demonstrated ability in a security engineering role. • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) • Experience analyzing code and systems to move from vulnerability → root cause → prevention • Real-world experience in software development and/or engineering operations • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

🏖️ Avantages

• Generous performance-based bonus plans to all eligible employees - we share in our success as one team • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) • Quarterly all-company wellness days where everyone takes a pause together • Country specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Postuler Maintenant

Emplois Similaires

🕒 il y a 2 mois

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Intelligence artificielle

Software Assurance Engineer securing CrowdStrike’s cybersecurity software supply chain, GitHub organizations, and open-source dependencies. Automating threat detection and hardening code-hosting environments.

🇺🇸 États-Unis – Télétravail

💵 $100 000 - $145 000 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Red Cell Partners

11 - 50

🏥 Santé

🎖️ Défense

💼 Conseil

Forward Deployed Engineer developing AI solutions for federal customers in national security. Engaging with mission teams to build production-ready systems and solve operational challenges.

🇺🇸 États-Unis – Télétravail

💵 $180 000 - $240 000 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Cyclotron, Inc.

51 - 200

💼 Conseil

🏥 Santé

📦 Logistique

Security Architect at Cyclotron designing enterprise deployments of Microsoft 365 Identity and Device Management tools. Collaborating with clients to enhance protection of Microsoft-based assets.

🇺🇸 États-Unis – Télétravail

💵 $130 000 - $180 000 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Packetlabs

51 - 200

💼 Conseil

🏥 Santé

📦 Logistique

OT Security Consultant at Packetlabs managing security assessments of Operational Technology environments. Collaborating with clients to improve security posture without operational disruptions.

🇺🇸 États-Unis – Télétravail

💵 $80 000 - $120 000 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Twilio

5001 - 10000

🔌 API

🤝 B2B

Senior Security Engineer leading incident response across Twilio’s global communications infrastructure. Improving threat mitigation through cloud security, automation, and scalable response processes.

🗣️🇺🇸🇬🇧 Anglais requis