Mozilla logo
Mozilla

Senior Security Engineer, Bug Bounty

Posted on 7 September 2026

About the role

💼 What you will do

• Own, manage, and administer the Mozilla Web Bug Bounty program. • Work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. • Protect the vision of an open, accessible internet by building, breaking, and hardening products that put privacy and safety first. • Join the Infrastructure team at a company whose products reach more than 225 million people each month. • Work for a technology company wholly owned by the non-profit Mozilla Foundation, accountable to its mission rather than shareholders. • Work fully remote from the UK.

📋 Job Requirements

• Bring 3+ years of demonstrated ability in a security engineering role. • Bring experience operating bug bounty programs, covering enhancements, automation, and scaling, or experience bug hunting. • Bring practical experience with modern cloud technologies such as AWS, Google Cloud Platform, Heroku, or Microsoft Azure. • Analyse code and systems to move from vulnerability to root cause to prevention. • Bring real-world experience in software development or engineering operations. • Communicate, collaborate, and solve problems strongly, influencing and guiding cross-functional teams. • Bring curiosity, passion, and a growth mindset, which Mozilla values above formal credentials.

🌟 Nice-to-have

• Develop your own tools in a variety of programming languages such as Python, Go, Rust, or JavaScript, which is a plus rather than a requirement. • Bring experience with HackerOne or similar bug bounty platforms. • Bring experience performing code reviews in JavaScript and Python. • Bring experience working alongside a Security Incident Response Team on active incidents and post-incident reviews. • Contact [email protected] if you need reasonable accommodations to take part in the application or interview process.

🎯 Responsibilities

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritisation, KPIs, and continuous improvement. • Act as the primary interface with external researchers and platforms such as HackerOne, fostering a high-quality and trusted research community. • Lead triage and technical validation of incoming reports across HackerOne, Bugzilla, and email. • Drive end-to-end vulnerability remediation, partnering with engineering teams on timely, effective fixes. • Identify root causes and systemic issues, influencing long-term improvements in secure development practices. • Collaborate with the Security Incident Response Team on active incidents and post-incident reviews. • Perform targeted code reviews, primarily in JavaScript and Python, during investigations and high-risk changes. • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights.

About Mozilla

😃 What Mozilla offers

• Earn a generous performance-based bonus as an eligible employee. • Access rich medical, dental, and vision coverage. • Receive generous retirement contributions with 100% immediate vesting, regardless of whether you contribute yourself. • Take quarterly all-company wellness days where everyone pauses together. • Take country-specific holidays plus a day off for your birthday. • Receive a one-time home office stipend. • Spend an annual professional development budget and a quarterly wellbeing stipend. • Take considerable paid parental leave. • Earn through the employee referral bonus program. • Access other benefits including life and AD&D cover, disability, and an EAP, varying by country.

💖 What makes Mozilla unique

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years, making brands such as Firefox, the privacy-minded web browser. More than 225 million people use its products each month, and its work spans AI, social media, security and more, without losing focus on its core mission to make the internet better for people. It is wholly owned by the non-profit Mozilla Foundation, so it answers to its mission rather than shareholders, and alongside thousands of volunteer contributors it builds and distributes open-source software.

Share This Page

Help others by sharing this with your network

Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.

For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.