Remote Corgi Becomes WFH JobsRead more
Mozilla Corporation logo
Mozilla Corporation

Senior Security Engineer, Bug Bounty

Posted on 31 July 2026

About the role

💼 What you will do

• Own, manage, and administer the Mozilla Web Bug Bounty programme, working with product and SIRT teams to ensure risk mitigation of security incidents and events. • Protect the vision of the internet as a global public resource by building, breaking, and hardening products that put people's privacy and safety first. • Act as the primary interface with external researchers and platforms, fostering a high-quality and trusted research community.

📋 Job Requirements

• Bring 3+ years of demonstrated ability in a security engineering role. • Have experience operating bug bounty programmes, including enhancements, automation, scaling, and/or bug hunting. • Bring practical experience working with modern cloud technologies such as AWS, Google Cloud Platform, Heroku, or Microsoft Azure. • Have experience analysing code and systems to move from vulnerability to root cause to prevention. • Bring real-world experience in software development and/or engineering operations. • Demonstrate strong communication, collaboration, and problem-solving skills with the ability to influence and guide cross-functional teams.

🌟 Nice-to-have

• Have the ability to develop your own tools in a variety of programming languages such as Python, Go, Rust, or JavaScript. • Hold formal security credentials or certifications. • Bring a curiosity-driven mindset and passion for continuous learning and growth.

🎯 Responsibilities

• Own and scale Mozilla's web bug bounty programme, including strategy, prioritisation, KPIs, and continuous improvement. • Act as the primary interface with external researchers and platforms such as HackerOne, fostering a high-quality and trusted research community. • Lead triage and technical validation of incoming reports across multiple intake channels including HackerOne, Bugzilla, and email. • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely and effective fixes. • Identify root causes and systemic issues, and influence long-term improvements in secure development practices. • Collaborate with the Security Incident Response Team on active incidents and post-incident reviews. • Perform targeted code reviews, primarily in JavaScript and Python, during investigations and high-risk changes. • Develop or leverage tooling to improve triage efficiency, signal quality, and programme insights.

About Mozilla Corporation

😃 What Mozilla Corporation offers

• Receive generous performance-based bonus plans. • Access rich medical, dental, and vision coverage. • Benefit from generous retirement contributions with 100% immediate vesting. • Enjoy quarterly all-company wellness days. • Take country-specific holidays plus a day off for your birthday. • Receive a one-time home office stipend. • Use an annual professional development budget. • Receive a quarterly well-being stipend. • Take considerable paid parental leave. • Participate in the employee referral bonus programme. • Access additional benefits including life/AD&D, disability, and EAP (varies by country).

💖 What makes Mozilla Corporation unique

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. It makes pioneering brands like Firefox, the privacy-minded web browser, used by more than 225 million people worldwide each month. Wholly owned by the non-profit 501(c) Mozilla Foundation, Mozilla isn't beholden to shareholders — only to its mission to make the internet better for people.

Share This Page

Help others by sharing this with your network

Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.

For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.