Full-time

Senior Security Engineer, Bug Bounty

Mozilla

Posted

Jul 20, 2026

Location

Remote (Canada)

Type

Full-time

Compensation

$95000 - $139000

Mission

What you will drive

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community.
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email).
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes.

Impact

The difference you'll make

This role directly protects the privacy and safety of over 225 million users by securing Mozilla's products and fostering a trusted bug bounty community, contributing to a healthier, more open internet.

Profile

What makes you a great fit

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting.
  • Practical experience working with modern cloud technologies (e.g., AWS, GCP, Azure).
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention.

Benefits

What's in it for you

Generous performance-based bonus plans, rich medical/dental/vision coverage, generous retirement contributions with 100% immediate vesting, quarterly all-company wellness days, country-specific holidays plus birthday off, one-time home office stipend, annual professional development budget, quarterly well-being stipend, considerable paid parental leave, employee referral bonus program, and other benefits (life/AD&D, disability, EAP).