Mozilla

Senior Security Engineer, Bug Bounty

Remote, United States remote Entry Salary not listed
remote Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people. 

The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms. 

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. 

What you’ll do:

Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement

Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community

Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)

Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes

Identify root causes and systemic issues, and influence long-term improvements in secure development practices

Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews

Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes

Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

3+ years of demonstrated ability in a security engineering role.

Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting

Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)

Experience analyzing code and systems to move from vulnerability → root cause → prevention

Real-world experience in software development and/or engineering operations

Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.

Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.

Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

Generous performance-based bonus plans to all eligible employees - we share in our success as one team

Rich medical, dental, and vision coverage

Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)

Quarterly all-company wellness days where everyone takes a pause together

Country specific holidays plus a day off for your birthday

One-time home office stipend

Annual professional development budget

Quarterly well-being stipend

Considerable paid parental leave

Employee referral bonus program

Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla 

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Role
Technology & IT Javascript Operations Python Senior Security remote

Likely questions

  1. Tell us about work you have done that is close to the Senior Security Engineer, Bug Bounty role.
  2. How would you approach your first 30 days at Mozilla?
  3. Which of Javascript, Operations and Python have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you stay organised and communicate clearly when working remotely?

Prepare before the call

  • A recent example that proves your experience with Javascript, Operations and Python.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Senior Security Engineer, Bug Bounty role because I can bring practical experience in Javascript, Operations and Python, learn the team quickly, and contribute to the outcomes Mozilla needs from this hire.

Related jobs.

More roles from this company or category.