Mozilla

Senior Security Engineer, Bug Bounty

Mozilla$137K — $183K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in a security engineering role
  • Experience with bug bounty programs, including enhancements and scaling
  • Hands-on experience with cloud technologies (e.g. AWS, GCP, Azure)
  • Ability to analyze code for vulnerability prevention
  • Experience in software development or engineering operations
  • Tool development skills in languages like Python, Go, or Rust (optional)
  • Strong communication and collaboration skills, able to influence teams

Responsibilities

  • Own and scale Mozilla's web bug bounty program
  • Act as primary contact for external researchers and platforms
  • Lead triage and technical validation of security reports
  • Drive end-to-end remediation of vulnerabilities
  • Identify root causes and drive improvements in secure practices
  • Collaborate with the Security Incident Response Team during incidents
  • Perform targeted code reviews, focusing on JavaScript and Python
  • Develop or leverage tooling for program insights and efficiency

Benefits

  • Performance-based bonus plans for all eligible employees
  • Comprehensive medical, dental, and vision insurance
  • Generous retirement contributions with immediate vesting
  • Quarterly wellness days for all employees
  • Additional holiday for birthdays
  • One-time stipend for home office setup
  • Annual budget for professional development
  • Quarterly well-being stipends
  • Considerable paid parental leave
  • Employee referral bonus program
  • Variety of additional benefits based on country
Full Job Description
About this team and role:

At Mozilla, we believe the internet is a global public resource-open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people's privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you'll do:
  • Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you'll bring:
  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability 12 root cause 12 prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you'll get:
  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Hiring Ranges:

US Tier 1 Locations

$137,000-$183,000 USD

US Tier 2 Locations

$126,000-$168,000 USD

US Tier 3 Locations

$116,000-$155,000 USD

About Mozilla

Mozilla is a global community of technologists, thinkers, and builders working together to keep the internet open and accessible to all. The company is best known for its flagship product, the Firefox web browser, which is used by millions of people around the world. In addition to its browser, Mozilla also develops a range of other products and services, including a mobile operating system, a password manager, and a virtual private network (VPN) service.
Learn more about Mozilla
Size
1,000 employees
Industry
Founded
1998

Similar Jobs

More Jobs at Mozilla

More Information Technology Jobs

Find similar Senior Security Engineer, Bug Bounty jobs: