Full-time
Senior Security Engineer, Bug Bounty
Mozilla
Posted
Jul 20, 2026
Location
Remote
Type
Full-time
Mission
What you will drive
- Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
- Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community.
- Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email).
- Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes.
Impact
The difference you'll make
This role protects Mozilla's products and users by ensuring vulnerabilities are identified and fixed, contributing to a safer, more private internet for over 225 million people worldwide.
Profile
What makes you a great fit
- 3+ years of demonstrated ability in a security engineering role.
- Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting.
- Practical experience working with modern cloud technologies (e.g., AWS, GCP, Azure).
- Experience analyzing code and systems to move from vulnerability to root cause to prevention.
Benefits
What's in it for you
- Generous performance-based bonus plans.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with 100% immediate vesting.
- Quarterly all-company wellness days.
- Country-specific holidays plus a day off for your birthday.
- One-time home office stipend.
- Annual professional development budget.
- Quarterly well-being stipend.
- Considerable paid parental leave.
- Employee referral bonus program.