# Senior Security Engineer, Bug Bounty

**Company:** [Mozilla](https://hotfix.jobs/companies/mozilla)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 3+ years
**Skills:** bug bounty, hackerone, bugzilla, AWS, GCP, Azure, JavaScript, Python, Go, Rust, Cloud Security, Vulnerability Management, Incident Response, Code Review
**Posted:** 2026-07-20

> Own and scale Mozilla's web bug bounty program as the primary interface with external researchers. Lead triage, validation, remediation of reports, collaborate with SIRT on incidents, perform code reviews, and drive secure development improvements. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

## Job Description

## What you’ll do

- Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
- Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
- Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
- Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
- Identify root causes and systemic issues, and influence long-term improvements in secure development practices
- Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
- Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
- Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

## What you’ll bring

- 3+ years of demonstrated ability in a security engineering role
- Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
- Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
- Experience analyzing code and systems to move from vulnerability → root cause → prevention
- Real-world experience in software development and/or engineering operations
- Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required
- Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams

## What you’ll get

- Generous performance-based bonus plans to all eligible employees
- Rich medical, dental, and vision coverage
- Generous retirement contributions with 100% immediate vesting
- Quarterly all-company wellness days
- Country specific holidays plus a day off for your birthday
- One-time home office stipend
- Annual professional development budget
- Quarterly well-being stipend
- Considerable paid parental leave
- Employee referral bonus program
- Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

## Similar roles

- [Senior Software Security Engineer](https://hotfix.jobs/jobs/bd83bbb8-d7c1-42bd-811f-3cdd8a53d7ca) - GitLab - Remote - $139k – $196k/yr
- [Senior Detection Engineer](https://hotfix.jobs/jobs/6e9f5f26-7b5d-45a6-ad57-701c49e31283) - Fluidstack - New York, NY - $176k – $218k/yr
- [Senior Security Engineer, Bug Bounty](https://hotfix.jobs/jobs/5532c56d-7528-4966-9a33-ffec20c4a012) - Mozilla - Remote - $116k – $183k/yr
- [Regional Site Security Lead, Deployment & Ops](https://hotfix.jobs/jobs/230fbb8b-e9a3-4d1c-a92a-ddc985723452) - Fluidstack - Austin, TX - $225k – $325k/yr
- [Security Engineer, Network](https://hotfix.jobs/jobs/d2d098ff-3230-49b5-bb4f-542f7ba2a14a) - Fluidstack - Austin, TX - $218k – $252k/yr

**Apply:** https://hotfix.jobs/jobs/7b8b62b3-cb93-4615-9276-eea6ffc68ccf
**Canonical:** https://hotfix.jobs/jobs/7b8b62b3-cb93-4615-9276-eea6ffc68ccf