Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Engineer, Bug Bounty

$137k - $183k
Full-time

Mozilla

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people. 

The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms. 

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. 

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla 

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientation s, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at View email address on codingjobboard.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R3105

Hiring Ranges:

US Tier 1 Locations

$137,000—$183,000 USD

US Tier 2 Locations

$126,000—$168,000 USD

US Tier 3 Locations

$116,000—$155,000 USD

Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer, Bug Bounty in Remote vacancy
  • Senior Security Engineer- Product SecurityAugusta, GaWork Location & ScheduleThis is a hybrid position based in our Augusta, GA office. Team...  ...risks, conducting security assessments, managing TaxSlayer's bug bounty program, and supporting compliance and risk management... 
    Senior
    Full time
    Temporary work
    For contractors
    Fixed term contract
    Work at office
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    TaxSlayer

    Augusta, GA
    1 day ago
  •  ...are we?Cohere is the leading security-first enterprise AI company....  ...Cohere is a team of researchers, engineers, designers, and more, who are...  ...and Paris. Join us!As a Senior Security Engineer you will:Serve...  ...speedDriving and supporting bug bounty program, application security... 
    Senior
    Work at office
    Local area
    Remote work
    Home office
    Flexible hours

    Cohere

    New York, NY
    4 days ago
  • $130k

    About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security...  ...security experience (iOS/Android)Pen testing or bug bounty experienceFamiliarity with GRC tools and frameworks#LI-Hybrid... 
    Senior
    Full time
    Work at office
    Local area
    Remote work

    Chime

    San Francisco, CA
    1 day ago
  •  ...of the world’s largest community of security researchers to continuously discover,...  ...and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic...  ...inclusion, respect, and accountability.Senior Security Engineer, Detection and ResponseRemote Location... 
    Senior
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    3 days ago
  • Role Description As a security-focused software engineer, you will go beyond traditional application security: ~Assist in developing Secure Software...  ...analysis, anomaly detection, and threat mitigation. ~Bug Bounty & Vulnerability Management – Manage bug bounty... 
    Senior
    Contract work
    Remote work

    Parity

    Remote
    4 days ago
  • $220k - $260k

     ...Senior / Staff Security Engineer | AI Infrastructure Startup I'm working with a fast-growing AI infrastructure startup that's looking for its...  ...through activities such as CTFs, vulnerability research, bug bounties, or open-source security projects Bachelor's degree in... 
    Senior
    Remote work

    Lawrence Harvey

    San Francisco, CA
    1 day ago
  • $130k

     ...About the role We are looking for a versatile Security Software Engineer to join our team and operate across product security, application...  ...Mobile security experience (iOS/Android) Pen testing or bug bounty experience Familiarity with GRC tools and frameworks... 
    Senior
    Full time
    Work at office
    Local area
    Remote work

    Chime Financial, Inc

    New York, NY
    4 days ago
  • $170k - $215k

     ...turnkey AI-powered credit intelligence solution.  As our security engineer, you'll own security end-to-end for our platform — standing...  ...executives; Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing... 
    Senior
    Full time
    Home office
    Flexible hours

    Credit Sesame

    Mountain View, CA
    4 days ago
  • $180k - $210k

     ...Join Gauntlet as a Senior Security Engineer, partnering with the Head of Security to build, operate and scale our security program. You'll work...  ...matters, and reduce noise. Triage vulnerability and bug-bounty findings by real exposure, drive remediation, and support... 
    Senior
    Full time
    Work at office
    Remote work
    Work from home

    Gauntlet

    New York, NY
    5 days ago
  • $208k - $312k

     ...to production with speed, security, and exceptional developer...  ...misuse.We're looking for a Senior (IC4) software engineer with a strong security background...  ...building features, fixing bugs, shipping to production...  ...OSCP, OSWE) or notable bug bounty / CTF history. Nice to have... 
    Senior
    Full time
    Work from home
    Worldwide
    Flexible hours

    Vercel

    San Francisco, CA
    2 days ago
  • $160k - $220k

    Join to apply for the Senior Application Security Engineer role at Zip The simple task of buying software, services, or tools at work has become hopelessly...  ..., triage, and coordinate security findings from bug bounty and third‑party pentests. Mentor security analysts and... 
    Senior
    Full time
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    4 days ago
  • $160k - $250k

     ...Description Our team is growing, and we’re looking for a Senior Product Security Engineer to dig deep into our endpoint products, find design and...  ...lives easier. ~Validate and replicate some kinds of bug bounty reports, and hunt for similar issues in affected applications... 
    Senior
    Full time
    Work at office

    CrowdStrike

    Remote
    2 days ago
  •  ...nutshell: ~You are a deeply technical engineer who gets restless when pipelines aren't...  ...locked down. ~You care about shipping secure software! ~This is an individual-contributor...  ...research or offensive security (bug bounty, CTF, penetration testing). Benefits... 
    Senior
    Full time
    Remote work
    Flexible hours

    Chainguard

    Remote
    7 days ago
  •  ...You will operate the Product Security programe for Blockchain.com’...  ...and MRE lines. This is a senior, hands-on role: you’ll design...  ...debt lifecycle for product engineering teams, and architect the automated...  ...secure coding baselines. Bug Bounty Leadership: Oversee the... 
    Senior
    Full time
    Contract work
    Apprenticeship
    Work at office
    Remote work
    Worldwide
    Flexible hours

    Blockchain

    United Kingdom
    5 days ago
  • $117.17k - $175.76k

     ...responsible for executing and advancing the security posture of Comcast’s core network...  ...environments, partnering with architecture, engineering, cybersecurity, compliance, operations,...  ...implementation, including security review, bug scrub, test case validation, and... 
    Senior
    Full time
    Work at office
    Remote work
    Worldwide

    Comcast

    Mount Laurel, NJ
    3 days ago
  • $130k - $218k

     ...importance to us that we keep our users as safe and secure as possible. We are looking for a Senior Application Security Engineer to join our rapidly growing security team to...  ...vulnerabilities reported to us through our bug bounty platform. ~Interface with ethical hackers... 
    Senior
    Full time
    Remote work

    Consensys

    Remote
    6 days ago
  • $192k - $240k

    Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform...  ...CVEs, presentations, etc. ~Experience submitting to bug bounty programs or responsible disclosure programs.... 
    Senior
    Full time
    Work experience placement

    Brex

    Remote
    7 days ago
  • $180k - $215k

    Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting...  ...offensive security experience — red teaming, bug bounty, or broader penetration testing beyond web/API surfaces... 
    Senior
    Full time
    Work at office
    Remote work
    Weekend work

    Monarch Money

    Remote
    6 days ago
  • Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly...  ...vulnerabilities (SAST/DAST/HackerOne). ~Own the bug bounty program end to end – issue evaluation, reproduction, and... 
    Senior
    Full time
    Remote work

    BioRender

    Remote
    7 hours ago
  • $190k - $273k

    Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software...  ...analysis. ~Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling... 
    Senior
    Full time
    Flexible hours

    Apollo.io

    Remote
    7 days ago
  • $251k - $325k

     ...hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come...  ...]( event. About the Team The Security team at Tools for Humanity operates at...  ...mobile, from triaging mobile-specific bug bounty submissions to driving remediation with... 
    Senior
    Casual work
    Worldwide
    Flexible hours

    Tools for Humanity

    San Francisco, CA
    3 days ago
  •  ...for a borderless global economy. Your Challenge As a Senior Application Security Engineer, you’ll be a hands-on technical expert responsible for...  ...experience or an offensive security background. Bug bounty participation or responsible vulnerability disclosure experience... 
    Senior
    Full time
    Local area

    Unlimint

    Remote
    16 days ago
  • $180k - $205.5k

    Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to...  ...or automated risk analysis. ~Experience managing a bug bounty or vulnerability disclosure program. ~Experience in... 
    Senior
    Full time
    Work experience placement
    Remote work
    Sleeping nights

    Spring Health

    Remote
    1 day ago
  •  ...considered for employment.What You'll Do:Join our dynamic Security Engineering team as a Senior Associate and make a significant impact on our...  ...Hashi, PKI), including implementing hot fixes, resolving bugs, troubleshooting issues, performing break-fixes, managing... 
    Senior
    Full time
    Remote work
    2 days per week

    The Options Clearing Corporation

    Chicago, IL
    4 days ago
  • $180k - $210k

     ...experience into a simple, secure, and enjoyable process. Our...  ...WORK ON We're hiring a Senior Application Security Engineer to join a small, high-...  ...for leadership, and write a bug report an engineer actually...  ...meaningfully contributing to a bug bounty program Experience with... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    Qualia

    Remote
    10 days ago
  • $234k - $286k

     ...Senior Security Engineer United States About Ngrok Inc. Ngrok is an all-in-one cloud networking platform that secures, transforms, and...  ...actually mean it. Take the time you need. Your manager will bug you if you're not taking enough. Parental leave that's realistic... 
    Senior
    Permanent employment
    Full time
    Work at office
    Local area
    Remote work
    Home office
    Flexible hours
    Shift work

    ngrok

    Washington DC
    3 days ago
  • $132.4k - $251.6k

     ...and transferable U.S. government issued security clearance is required prior to start date...  ...100 years of experience and renowned engineering expertise to meet the needs of today’s mission...  ...software configuration management and bug tracking toolsExperience with Python /... 
    Senior
    Temporary work
    Work experience placement
    Interim role
    Work at office
    Remote work
    Flexible hours

    Raytheon

    Tucson, AZ
    3 days ago
  • Position: Senior Security Engineer - PKI & Detection, Aircraft SecurityLocation: Fort Worth Texas (Hybrid - onsite Tuesday through Thursday; remote Monday and Friday)Duration: ContractJob ID: 178660Job Overview:We are seeking a Senior Security Engineer to support aircraft... 
    Senior
    Full time
    Remote work
    Monday to Friday

    Pinnacle Group

    Fort Worth, TX
    2 days ago
  • $178.4k - $226.7k

    AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds... 
    Senior
    Internship
    Remote work
    Flexible hours

    Amazon

    Arlington, VA
    7 hours ago
  • $210k - $260k

     ...What you'll do:We're looking for aStaff Security Engineer, Application Security to help scale and...  ...autonomy while partnering with senior engineers and security leadership to scale...  ...or multi-tenant systemsExperience with bug bounty programs and penetration testingSecurity... 
    Work at office
    Remote work
    Worldwide
    Monday to Friday
    Flexible hours

    NinjaTrader Group

    Chicago, IL
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Engineer, Bug Bounty. Be the first to apply!