← Back to job listings
MO
Senior Security Engineer (Bug Bounty)
Mozilla · London, United Kingdom
About The Role
Join Mozilla as a Senior Security Engineer, where you'll lead and manage the Mozilla Web Bug Bounty program, ensuring the security and privacy of our products. You'll collaborate with engineering teams, the Security Incident Response Team, and external researchers to drive vulnerability remediation and improve secure development practices. Enjoy comprehensive health and wellness benefits, generous time off, parental leave, financial incentives, and opportunities for professional development.
- Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
- Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community.
- Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email).
- Real-world experience in software development and/or engineering operations
- Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
- Experience analyzing code and systems to move from vulnerability → root cause → prevention
- Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required
- Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more
- 3+ years of demonstrated ability in a security engineering role
- Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams
- Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring