Skip to content
MozillaMozillaUnited States

Senior Security Engineer, Bug Bounty

Own and scale Mozilla's web bug bounty program as the primary interface with external researchers. Lead triage, validation, remediation of reports, collaborate with SIRT on incidents, perform code reviews, and drive secure development improvements. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

Salary not listed
Remote3+ YOESecurity Engineering

About the role

What you’ll do

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring

  • 3+ years of demonstrated ability in a security engineering role
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams

What you’ll get

  • Generous performance-based bonus plans to all eligible employees
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting
  • Quarterly all-company wellness days
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Skills

bug bountyhackeronebugzillaAWSGCPAzureJavaScriptPythonGoRustCloud SecurityVulnerability ManagementIncident ResponseCode Review
GitLab

Senior Software Security Engineer

GitLabUnited States

Senior engineer on Trust and Safety team building and maintaining abuse prevention systems, anomaly detection, and agentic AI tools for the GitLab SaaS platform. Requires strong Ruby/Rails software engineering background; security experience preferred but not required.

139k – 196k/yr
Remote5+ YOESecurity Engineering
Fluidstack

Senior Detection Engineer

FluidstackNew York, NY +3

Own end-to-end detection engineering program including threat modeling, detection-as-code pipelines, threat hunting, SIEM/EDR tuning, alert triage and incident response for rapidly scaling AI compute infrastructure. Requires 5+ years in detection engineering or threat hunting with deep SIEM/EDR and scripting experience.

176k – 218k/yr
On-site5+ YOESecurity Engineering
Mozilla

Senior Security Engineer, Bug Bounty

MozillaUnited States

Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

116k – 183k/yr
Remote3+ YOESecurity Engineering
Fluidstack

Regional Site Security Lead, Deployment & Ops

FluidstackAustin, TX +1

Lead physical security operations and teams across multiple data center sites in a region. Own end-to-end posture, standardize procedures, support customer audits, and integrate security into facility growth for frontier AI compute infrastructure.

225k – 325k/yr
On-site7+ YOESecurity Engineering
Fluidstack

Security Engineer, Network

FluidstackAustin, TX +3

Design and defend network security architecture for AI compute infrastructure at gigawatt scale, including segmentation, detection, and OT hardening across data centers, corp, and cloud. Requires experience securing large production networks with IT/OT mix, packet analysis, IaC for security controls, and real intrusion detection.

218k – 252k/yr
On-site7+ YOESecurity Engineering