Senior Security Engineer, Bug Bounty

🕒 July 20

🇺🇸 United States – Remote

💵 $137k - $183k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 2%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

🎯 Requirements

• 3+ years of demonstrated ability in a security engineering role. • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) • Experience analyzing code and systems to move from vulnerability → root cause → prevention • Real-world experience in software development and/or engineering operations • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees - we share in our success as one team • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) • Quarterly all-company wellness days where everyone takes a pause together • Country specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Apply Now

Similar Jobs

🕒 July 20

Red Cell Partners

11 - 50

🏥 Healthcare

🎖️ Defense

💼 Consulting

Forward Deployed Engineer developing AI solutions for federal customers in national security. Engaging with mission teams to build production-ready systems and solve operational challenges.

🕒 July 18

Cyclotron, Inc.

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Architect at Cyclotron designing enterprise deployments of Microsoft 365 Identity and Device Management tools. Collaborating with clients to enhance protection of Microsoft-based assets.

🕒 July 18

Packetlabs

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

OT Security Consultant at Packetlabs managing security assessments of Operational Technology environments. Collaborating with clients to improve security posture without operational disruptions.

🕒 July 18

Twilio

5001 - 10000

🔌 API

🤝 B2B

Senior Security Engineer leading incident response across Twilio’s global communications infrastructure. Improving threat mitigation through cloud security, automation, and scalable response processes.

🕒 July 17

Second Front Systems

51 - 200

☁️ SaaS

🎖️ Defense

🏛️ Government

Cybersecurity Assessment Engineer ensuring security posture of cloud platforms at Second Front Systems. Engaging with DevOps and Mission Success teams, focusing on vulnerability assessments and incident response.