Senior Security Engineer, Bug Bounty
Core
Own, manage, and scale Mozilla's web bug bounty program while mitigating security risks across products.
Role type
Senior Security Engineer (Bug Bounty Program Management)
Builds
Mozilla's web bug bounty program infrastructure and processes
Domain
Internet security, open-source software, cloud infrastructure
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
bug bounty program management, vulnerability triage, root cause analysis, secure development practices, cloud technology operations, code review (JavaScript/Python), tool development
Preferred skills
automation, scaling security programs, programming in Python/Go/Rust/JavaScript
Technologies
Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, HackerOne, Bugzilla
Responsibilities
Own and scale the web bug bounty program strategy and KPIs; act as primary interface with external researchers; lead triage and technical validation of security reports; drive end-to-end vulnerability remediation with engineering teams; identify root causes and influence secure development practices; collaborate with SIRT on active incidents; perform targeted code reviews; develop tooling to improve triage efficiency.
Seniority
Senior, hands-on IC