Mozilla logo
Est. Monthly
Estimated €5,279 - €7,125
Posted August 7, 2026 · 0 days agoLast seen August 7, 2026Est. expiry September 11, 2026

Security Engineer

Senior Security Engineer
Remote - US
Remote · Software Engineering
Full-time · Senior
English
No People Management
3 years experience
How this salary compares
Salary Context: Security Engineer

Hover or tap a row for full statistics (EUR / month on this chart).

Salary analysis

Compared with the selected benchmark ("All roles in Remote - Germany"), this listing's salary midpoint is about 92% lower. The offer sits below the benchmark range (€5,279–€7,125). The offer's range width is broadly in line with the benchmark. This benchmark is based on 1 comparable listings.

Monthly salary comparison for Security Engineer
MarketLower bound (25th percentile)MedianUpper bound (75th percentile)
Market Average: Security Engineer€6,000/per month€6,875/per month€7,950/per month
All roles in Remote - Germany€5,279/per month€6,202/per month€7,125/per month
Pay in our data — not quoted in ad (Senior)€440/per month€517/per month€594/per month
About the role

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. What you’ll do: - Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement - Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community - Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) - Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes - Identify root causes and systemic issues, and influence long-term improvements in secure development practices - Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews - Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes - Develop or leverage tooling to improve triage efficiency, signal quality, and program insights What you’ll bring: - 3+ years of demonstrated ability in a security engineering role. - Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting - Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) - Experience analyzing code and systems to move from vulnerability → root cause → prevention - Real-world experience in software development and/or engineering operations - Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. - Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. - Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

Job Details

Responsibilities

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, and KPIs
  • Act as the primary interface with external researchers and platforms like HackerOne
  • Lead triage and technical validation of incoming reports across multiple channels
  • Drive end-to-end vulnerability remediation in partnership with engineering teams
  • Identify root causes and systemic issues to improve secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and reviews
  • Perform targeted code reviews primarily in JavaScript and Python
  • Develop or leverage tooling to improve triage efficiency and program insights

Requirements

  • 3+ years of demonstrated ability in a security engineering role
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (e.g. AWS, GCP, Heroku, Azure)
  • Experience analyzing code and systems to move from vulnerability to root cause and prevention
  • Real-world experience in software development and/or engineering operations
  • Strong communication, collaboration, and problem-solving skills

Skills & Technologies

JavaScriptPythonAWSGoogle Cloud PlatformHerokuMicrosoft AzureHackerOneBugzillaGoRust
Seen 23 hours agoContent Complete
Mozilla logo
Mozilla · 581 open roles
Top locations: Remote - Global · 60 · Remote Finland · 49 · Remote Germany · 47+23 other locations
View company
Most-hired roles
Software Engineer
62
Senior Software Engineer
4
Machine Learning Engineer
4
Executive Assistant
3
Security Engineer
3
Role-level mix
Mid-Level (63)Senior (12)Mid-level (1)

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.