Remotery

Senior Security Engineer, Bug Bounty

Posted Jul 20

This is a fully remote position, open to applicants in Canada.

📋 Description

• Take ownership of and expand Mozilla’s web bug bounty initiative, encompassing strategy, prioritization, key performance indicators, and ongoing enhancement.

• Serve as the main liaison with external researchers and platforms (such as HackerOne), nurturing a high-quality and trustworthy research community.

• Oversee the triage and technical validation of incoming reports from various intake channels (HackerOne, Bugzilla, email).

• Facilitate comprehensive vulnerability remediation by collaborating with engineering teams to guarantee timely and effective solutions.

• Detect root causes and systemic issues, and advocate for long-term enhancements in secure development practices.

• Work alongside the Security Incident Response Team (SIRT) on active incidents and conduct post-incident reviews.

• Execute targeted code reviews (mainly in JavaScript and Python) during investigations and high-risk modifications.

• Create or utilize tools to enhance triage efficiency, signal quality, and program insights.


⛳️ Requirements

• A minimum of 3 years of proven experience in a security engineering position.

• Background in managing bug bounty programs, including optimization, automation, scaling, and/or bug hunting.

• Hands-on experience with contemporary cloud technologies (e.g., Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.).

• Proficiency in analyzing code and systems to transition from vulnerability to root cause to prevention.

• Real-world experience in software development and/or engineering operations.

• Capability to develop personal tools as needed across various programming languages (e.g., Python, Go, Rust, JavaScript, etc.) is advantageous, but not mandatory.

• Excellent communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.

• While formal credentials are beneficial, practical experience, curiosity, enthusiasm, and a growth mindset are of greater importance.


🏝️ Benefits

• Competitive performance-based bonus plans for all eligible employees - we celebrate our achievements as one cohesive team.

• Comprehensive medical, dental, and vision insurance.

• Generous retirement contributions with immediate 100% vesting (irrespective of personal contributions).

• Quarterly wellness days for the entire company to collectively take a break.

• Country-specific holidays plus an additional day off for your birthday.

• One-time stipend for home office setup.

• Annual budget for professional development.

• Quarterly stipend for well-being.

• Substantial paid parental leave.

• Employee referral bonus program.

• Additional benefits (life/AD&D, disability, EAP, etc. - varies by country).

People also viewed

ASG Technologies6 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike6 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International7 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape7 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity8 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist10 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers