Full-time

Senior Security Engineer, Bug Bounty

Mozilla

Posted

Jul 20, 2026

Location

Remote

Type

Full-time

Mission

What you will drive

  • Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community.
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email).
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes.

Impact

The difference you'll make

This role protects Mozilla's products and users by ensuring vulnerabilities are identified and fixed, contributing to a safer, more private internet for over 225 million people worldwide.

Profile

What makes you a great fit

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting.
  • Practical experience working with modern cloud technologies (e.g., AWS, GCP, Azure).
  • Experience analyzing code and systems to move from vulnerability to root cause to prevention.

Benefits

What's in it for you

  • Generous performance-based bonus plans.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting.
  • Quarterly all-company wellness days.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.