Skip to content
MozillaMozillaUnited States

Senior Security Engineer, Bug Bounty

Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

116k – 183k/yr
Remote3+ YOESecurity Engineering

About the role

What you’ll do

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring

  • 3+ years of demonstrated ability in a security engineering role
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams

What you’ll get

  • Generous performance-based bonus plans to all eligible employees
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting
  • Quarterly all-company wellness days
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Skills

bug bountyhackeronebugzillaAWSGCPAzureherokuJavaScriptPythonGoRustCloud SecurityVulnerability ManagementIncident Response
Navan

Sr. Security Engineer, Incident Response

NavanNew York, NY +2

Technical lead for incident response across multi-cloud environments. Owns triage, containment, automation, and detection tuning using CrowdStrike, Tines, and Cyberhaven DLP. Requires 5+ years in IR/SOC roles.

113k – 252k/yr
On-site5+ YOESecurity Engineering
Pinterest

Sr. Security Software Engineer, Corporate Security

PinterestSan Francisco, CA

Build automation, tooling, and secure software systems as part of Pinterest's Corporate Security team. Integrate security into development lifecycles, improve threat detection/remediation, and leverage AI while maintaining critical verification and ownership.

124k – 255k/yr
RemoteSecurity Engineering
Northwood Space

Corporate Security Lead

Northwood SpaceLos Angeles, CA +1

Builds and leads corporate IT security operations including helpdesk, endpoint management, SIEM deployment, and team hiring for a space communications company. Requires 5+ years in IT/security/DevSecOps, hands-on tools like Okta and AWS, and compliance knowledge.

125k – 206k/yr
On-site5+ YOESecurity Engineering
Clickhouse

Senior Security Automation Engineer

ClickhouseUnited States

Senior Security Automation Engineer building centralized security telemetry, universal identity provisioning, and agentic risk engines to enable continuous compliance, self-healing controls, and real-time risk visibility at ClickHouse. Requires strong IAM/IGA and automation experience with Python, JS/TS, or Go.

125k – 205k/yr
Remote5+ YOESecurity Engineering
Agency

Senior vCISO / GRC Consulting Manager

AgencyRichmond, VA

Lead client-facing vCISO and GRC consulting engagements for SOC 2, ISO 27001, NIST, and CMMC compliance. Manage a team of consultants while advising executives on security program design, risk prioritization, audit readiness, and control implementation.

125k – 125k/yr
On-site6+ YOESecurity Engineering