Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Mozilla

Senior Security Engineer, Bug Bounty

Mozilla

Security Engineer managing Mozilla's web bug bounty program and working with the product and SIRT teams. Focusing on vulnerability remediation and ensuring security across all products.

Posted 7/20/2026full-timeRemote • 🇺🇸 United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing and scaling bug bounty programs, with a strong focus on vulnerability remediation and secure development practices. Proficient in collaborating with cross-functional teams and leveraging modern cloud technologies to enhance security operations.

Highest-signal resume keywords
Bug Bounty Program ManagementVulnerability RemediationCloud TechnologiesCode AnalysisSecurity Engineering

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
JavaScriptPythonVulnerability AnalysisRoot Cause AnalysisSoftware DevelopmentTool DevelopmentAutomationBug HuntingTriage EfficiencySecure Development Practices
Soft Skills
CommunicationCollaborationProblem-SolvingInfluencingGuiding Teams
Tools & Technologies
HackerOneBugzillaAmazon Web ServicesGoogle Cloud PlatformMicrosoft AzureHeroku
Industry Keywords
Security EngineeringIncident ResponseContinuous ImprovementResearch CommunityTechnical Validation

Tech Stack

Tools & technologies
AWSAzureCloudGoGoogle Cloud PlatformHerokuJavaScriptPythonRust

About the role

Key responsibilities & impact
  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

Requirements

What you’ll need
  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

Benefits

Comp & perks
  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)