
Senior Security Engineer, Bug Bounty
The role owns Mozilla’s web bug bounty program (strategy, KPIs, researcher relations), leads triage and technical validation across intake channels (HackerOne, Bugzilla, email), drives end-to-end vulnerability remediation with engineering teams, collaborates with the Security Incident Response Team on incidents and post-incident reviews, performs targeted code reviews (primarily JavaScript and Python), and develops or leverages tooling to improve triage and program insights. Requires 3+ years in a security engineering role and experience with cloud platforms.







