
Senior Security Engineer
About this team and role: At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. What you’ll do: - Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement - Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community - Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) - Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes - Identify root causes and systemic issues, and influence long-term improvements in secure development practices - Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews - Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes - Develop or leverage tooling to improve triage efficiency, signal quality, and program insights What you’ll bring: - 3+ years of demonstrated ability in a security engineering role. - Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting - Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) - Experience analyzing code and systems to move from vulnerability → root cause → prevention - Real-world experience in software development and/or engineering operations - Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. - Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. - Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.
The text above is the employer's original job description, extracted as written. Other details on this page, like salary, responsibilities, and requirements, are interpreted from that text by our system, not values the employer explicitly confirmed, so treat them as our best interpretation rather than verified facts.
Estimated from 3 comparable listings
- Own and scale Mozilla’s web bug bounty program strategy, prioritization, and KPIs
- Act as primary interface with external researchers and platforms like HackerOne
- Lead triage and technical validation of reports from HackerOne, Bugzilla, and email
- Drive end-to-end vulnerability remediation with engineering teams
- Identify root causes and influence long-term secure development practices
- Collaborate with the Security Incident Response Team (SIRT) on incidents and reviews
- Perform targeted code reviews in JavaScript and Python
- Develop tooling to improve triage efficiency and program insights
- 3+ years of experience in a security engineering role
- Experience operating bug bounty programs (enhancements, automation, scaling) or bug hunting
- Practical experience with modern cloud technologies (AWS, GCP, Heroku, Azure, etc.)
- Experience analyzing code and systems to move from vulnerability to root cause and prevention
- Real-world experience in software development or engineering operations
- Strong communication, collaboration, and problem-solving skills
| Location | Active listings |
|---|---|
| Remote - Global | 60 |
| Remote - Finland | 55 |
| Remote - Germany | 53 |
| Remote - France | 52 |
| Remote - Netherlands | 52 |
| Remote - Sweden | 51 |
| Remote - Belgium | 50 |
| Remote - UK | 50 |
| Remote - Spain | 49 |
| Remote - Poland | 41 |
| Remote - Canada | 38 |
| Remote - US | 19 |
| Remote - Denmark | 6 |
| Remote - New Zealand | 5 |
| Remote - Australia | 5 |
| Role type | Active listings |
|---|---|
| Software Engineer | 60 |
| Senior Software Engineer | 5 |
| Product Manager | 5 |
| Machine Learning Engineer | 4 |
| Security Engineer | 3 |
| Executive Assistant | 3 |
| Solutions Engineer | 2 |
| Program Manager | 2 |
| Frontend Engineer | 2 |
| Site Reliability Engineer | 2 |
| Product Director | 1 |
| Fundraising Strategist | 1 |
| Public Policy & Government Relations Manager | 1 |
| Strategic Finance and Investment Strategy | 1 |
| Application Engineer | 1 |
| Security Student Worker | 1 |
| Privacy Counsel | 1 |
| Marketing Data Scientist | 1 |
| Engineer | 1 |
| Senior Engineering Manager | 1 |
| Data Scientist | 1 |
| Operations Engineer | 1 |
| Grassroots Engagement Director | 1 |
| Creative Producer | 1 |
| Senior Staff Product Manager | 1 |
| Quantitative User Researcher | 1 |
| Business Development Manager | 1 |
| iOS Engineer | 1 |
| Test Engineering Manager | 1 |
| Web Apps Manager | 1 |
| Integrated Marketing Consultant | 1 |
| Software Test Engineering | 1 |
| Social Media & Content Strategist | 1 |
| Strategic Account Executive | 1 |
| Head of Global and Strategic Intelligence | 1 |
| AI & Agentic Systems Engineer | 1 |
| Marketing Specialist | 1 |
| Role level | Active listings |
|---|---|
| Senior | 61 |
| Mid-Level | 40 |
| Manager | 8 |
| Director | 6 |
Mozilla Corporation is a non-profit-backed technology company dedicated to making the internet a global public resource. They create pioneering brands like the Firefox browser and focus on AI, social media, and security to ensure the web remains open and accessible to all.
Never miss a new Security Engineer job in Remote - US
Weekly or daily digest. Unsubscribe anytime.
Similar jobs
From JobCrawls search: same role title and primary location as this listing (this job excluded). Up to 8 results.






