Bug Bounty Security Engineer: Protect the Open Web

Mozilla Corporation

United States

Remote

USD 116,000 - 183,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Performance bonus
Medical, dental, and vision coverage
Retirement contributions with 100% v2
Wellness days
Holidays + birthday
Home office stipend
Well-being stipend
Parental leave
Employee referral program
Life/AD&D, EAP

Job summary

Mozilla Corporation seeks a Security Engineer to own and manage the Web Bug Bounty program, working with product and SIRT teams to mitigate security risks. You will lead triage and validation of reports from HackerOne, Bugzilla, and email, and drive end-to-end remediation with engineering partners.

Ideal candidates bring 3+ years in security engineering, bug bounty program experience, and strong cloud skills.

Qualifications

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting.
  • Practical experience working with modern cloud technologies (AWS, GCP, Heroku, Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability > root cause > prevention.
  • Real-world experience in software development and/or engineering operations.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

Responsibilities

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

Skills

Security engineering
Bug bounty programs
Cloud technologies
Code & systems analysis
Software development
Communication & collaboration
Growth mindset

Job description

Mozilla Corporation seeks a Security Engineer to own and manage the Web Bug Bounty program, working with product and SIRT teams to mitigate security risks. You will lead triage and validation of reports from HackerOne, Bugzilla, and email, and drive end-to-end remediation with engineering partners.

Ideal candidates bring 3+ years in security engineering, bug bounty program experience, and strong cloud skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Web Bug Bounty & Security Engineer
Lead Web Bug Bounty & Security Engineer

Mozilla Corporation • United States

Remote
USD 120,000 - 180,000
Generous bonus plans
Medical, dental, vision coverage
100% vesting retirement contributions
+4
Lead Web Bug Bounty Security Engineer
Lead Web Bug Bounty Security Engineer

Mozilla • United States

On-site
USD 126,000 - 183,000
Bonus plans
Medical/dental/vision coverage
Retirement contributions
+7
Senior Bug Bounty Security Engineer — Remote
Senior Bug Bounty Security Engineer — Remote

Nerdleveltech • Germany (OH)

On-site
USD 78,000 - 105,000
Performance-based bonus
Medical, dental, vision coverage
Retirement contributions
+5
Bug Bounty Program Lead - Security Engineer
Bug Bounty Program Lead - Security Engineer

Doist • Germany (OH)

Hybrid
USD 78,278 - 104,754
Generous bonus plans
Medical, dental, vision coverage
Retirement contributions with vesting
+4
Lead Bug Bounty & Security Program Engineer
Lead Bug Bounty & Security Program Engineer

Mozilla • Germany (OH)

On-site
USD 77,000 - 104,000
Bonus plans based on performance
Medical, dental, and vision coverage
Retirement contributions with vesting
+3
Senior Security Engineer, Bug Bounty
Senior Security Engineer, Bug Bounty

Nerdleveltech • Germany (OH)

On-site
USD 78,000 - 105,000
Performance-based bonus
Medical, dental, vision coverage
Retirement contributions
+5
Senior Security Engineer, Bug Bounty
Senior Security Engineer, Bug Bounty

Mozilla • United States

On-site
USD 126,000 - 183,000
Bonus plans
Medical/dental/vision coverage
Retirement contributions
+7
Remote Bug Bounty Security Analyst
Remote Bug Bounty Security Analyst

United States Digital Space LLC • United States

Remote
USD 90,000 - 130,000
Technical Program Manager, Bug Bounty & Security
Technical Program Manager, Bug Bounty & Security

Amazon • Seattle (WA)

On-site
USD 127,100 - 172,000
Security Bug Bounty TPM: Lead Cross-Functional Vulnerability Programs
Security Bug Bounty TPM: Lead Cross-Functional Vulnerability Programs

Amazon • Austin (TX)

On-site
USD 127,000 - 172,000