Senior Security Engineer, Bug Bounty

🔥 12 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

🎯 Requirements

• 3+ years of demonstrated ability in a security engineering role. • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) • Experience analyzing code and systems to move from vulnerability → root cause → prevention • Real-world experience in software development and/or engineering operations • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees - we share in our success as one team • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) • Quarterly all-company wellness days where everyone takes a pause together • Country specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Apply Now

Similar Jobs

🔥 1 hour ago

Zepz

501 - 1000

💳 Fintech

👥 B2C

Senior Security Engineer in a remote role at Zepz, enhancing security operations and automation expertise. Fostering collaboration among engineering, operations, and business teams in a diverse environment.

🔥 2 hours ago

RISCO Group

501 - 1000

🔐 Security

🔧 Hardware

☁️ SaaS

Senior System & Information Security Administrator overseeing IT operations and security for the company. Responsible for system administration, infrastructure maintenance, and vendor coordination.

🔥 3 hours ago

Nucleus Financial

501 - 1000

💸 Finance

💳 Fintech

☁️ SaaS

Security Engineer for Nucleus addresses security needs via controls and systems integration. Collaborating across teams to deliver effective security measures and manage risks within a fast-paced environment.

🔥 4 hours ago

Glamox

1001 - 5000

🏭 Manufacturing

🔧 Hardware

🤝 B2B

Key Account Manager for Glamox managing Defence & Security account portfolio. Shaping strategy, winning projects, and collaborating with a trusted team.

🔥 4 hours ago

SOCOTEC UK & Ireland

1001 - 5000

🏗️ Construction

💼 Consulting

Certification Officer conducting audits and evaluations for fire and security doorset certifications at UKTC. Supporting compliance and overseeing certification processes within construction safety.