Mozilla logo

Mozilla

Senior Security Engineer, Bug Bounty

Work from home

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 4 weeks ago · Added 5 days ago

Been open since 4 weeks ago, still being checked, but it has been live a while.

Salary

$137,000 to $183,000

Location

United States only

Timezone

Not stated

Contract

Full-time

Experience

Senior

Category

Software

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote US"

What Nomaders makes of it

  • Residency required in United States
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement

Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community

Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)

Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes

Identify root causes and systemic issues, and influence long-term improvements in secure development practices

Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews

Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes

Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

3+ years of demonstrated ability in a security engineering role.

Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting

Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)

Experience analyzing code and systems to move from vulnerability → root cause → prevention

Real-world experience in software development and/or engineering operations

Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.

Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.

Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

Requirements

  • ·3+ years of demonstrated ability in a security engineering role.
  • ·Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • ·Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • ·Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • ·Real-world experience in software development and/or engineering operations

Benefits

  • ·Commitment to diversity, equity, inclusion, and belonging

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Mozilla, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 6d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$137,000 to $183,000 · You'll be taken to the employer's careers page.