Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.
116k – 183k/yr
Remote3+ YOESecurity Engineering
About the role
What you’ll do
Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
Identify root causes and systemic issues, and influence long-term improvements in secure development practices
Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
What you’ll bring
3+ years of demonstrated ability in a security engineering role
Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
Experience analyzing code and systems to move from vulnerability → root cause → prevention
Real-world experience in software development and/or engineering operations
Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required
Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams
What you’ll get
Generous performance-based bonus plans to all eligible employees
Rich medical, dental, and vision coverage
Generous retirement contributions with 100% immediate vesting
Quarterly all-company wellness days
Country specific holidays plus a day off for your birthday
One-time home office stipend
Annual professional development budget
Quarterly well-being stipend
Considerable paid parental leave
Employee referral bonus program
Other benefits (life/AD&D, disability, EAP, etc. - varies by country)
Technical lead for incident response across multi-cloud environments. Owns triage, containment, automation, and detection tuning using CrowdStrike, Tines, and Cyberhaven DLP. Requires 5+ years in IR/SOC roles.
Build automation, tooling, and secure software systems as part of Pinterest's Corporate Security team. Integrate security into development lifecycles, improve threat detection/remediation, and leverage AI while maintaining critical verification and ownership.
124k – 255k/yr
RemoteSecurity Engineering
Corporate Security Lead
Northwood SpaceLos Angeles, CA +1
Builds and leads corporate IT security operations including helpdesk, endpoint management, SIEM deployment, and team hiring for a space communications company. Requires 5+ years in IT/security/DevSecOps, hands-on tools like Okta and AWS, and compliance knowledge.
125k – 206k/yr
On-site5+ YOESecurity Engineering
Senior Security Automation Engineer
ClickhouseUnited States
Senior Security Automation Engineer building centralized security telemetry, universal identity provisioning, and agentic risk engines to enable continuous compliance, self-healing controls, and real-time risk visibility at ClickHouse. Requires strong IAM/IGA and automation experience with Python, JS/TS, or Go.
125k – 205k/yr
Remote5+ YOESecurity Engineering
Senior vCISO / GRC Consulting Manager
AgencyRichmond, VA
Lead client-facing vCISO and GRC consulting engagements for SOC 2, ISO 27001, NIST, and CMMC compliance. Manage a team of consultants while advising executives on security program design, risk prioritization, audit readiness, and control implementation.