NewFull-timeRemotePosted today
Senior Security Engineer, Bug Bounty
mozilla · Remote
#infrastructure
About the role
<div class="gmail_default" style="font-size: small;">
<div>
<p><strong>Why Mozilla?</strong></p>
<p><span style="font-weight: 400;">Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people. </span></p>
<p><span style="font-weight: 400;">The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms. </span></p>
<p><strong>About this team and role:</strong></p>
<p><span style="font-weight: 400;">At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. </span></p>
<p><strong>What you’ll do:</strong></p>
<ul>
<li style="font-weight: 400;"><span style="font-weight: 400;">Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Identify root causes and systemic issues, and influence long-term improvements in secure development practices</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Develop or leverage tooling to improve triage efficiency, signal quality, and program insights</span></li>
</ul>
<p><strong>What you’ll bring:</strong></p>
<ul>
<li style="font-weight: 400;"><span style="font-weight: 400;">3+ years of demonstrated ability in a security engineering role.</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Experience analyzing code and systems to move from vulnerability → root cause → prevention</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Real-world experience in software development and/or engineering operations</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.</span></li>
</ul>
<p><strong>What you’ll get:</strong></p>
<ul>
<li style="font-weight: 400;"><span style="font-weight: 400;">Generous performance-based bonus plans to all eligible employees - we share in our success as one team</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Rich medical, dental, and vision coverage</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Quarterly all-company wellness days where everyone takes a pause together</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Country specific holidays…
Apply for this role
Apply right here on 9180 — we'll forward your application to mozilla. No external redirects, no lost candidates.
Originally listed on Arbeitnow. View the original posting ↗
