Mozilla logo
Mozilla·

Senior Security Engineer, Bug Bounty - Mozilla

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (e.g., AWS, GCP, Heroku, Azure)
  • Experience analyzing code and systems to move from vulnerability to root cause to prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (e.g., Python, Go, Rust, JavaScript)
  • Strong communication, collaboration, and problem-solving skills
  • Real-world experience, curiosity, passion, and a growth mindset

What you’ll get:

  • Generous performance-based bonus plans
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting
  • Quarterly all-company wellness days and well-being stipends
  • Country-specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Considerable paid parental leave
  • Employee referral bonus program

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Mozilla

Similar remote roles