[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Mozilla logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/mozilla.jpg)](https://jobicy.com/company/mozilla.md)Remote opportunity at[Mozilla](https://jobicy.com/company/mozilla.md)

# Senior Security Engineer, Bug Bounty

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/mozilla.md)Share22 Sep 2026Published35Listing views3Application actions22 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryMozilla is seeking a senior security engineer to own and scale its web bug bounty program. The role leads vulnerability intake, triage, technical validation, researcher relationships, remediation coordination, and improvements to secure development practices. It partners closely with product engineering teams and the Security Incident Response Team on active incidents and post-incident reviews. The position requires practical security engineering experience, bug bounty or bug-hunting expertise, cloud familiarity, code analysis skills, and strong cross-functional communication.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a senior, high-trust security role requiring independent technical judgment across vulnerability triage, incident response, remediation, and program strategy. The engineer must balance external researcher engagement with internal influence across multiple product and engineering teams.

## Salary analysis

Estimated compensation compared with the broader UK market for similar roles.

Estimated job medianBelow market£76,500UK market range£140k–£190k0£209k

AI insightThe disclosed UK yearly salary range is £66,000–£87,000 GBP, with a midpoint of £76,500. The estimated US market range for a senior security engineer specializing in vulnerability management and bug bounty operations is $140,000–$190,000 annually; this US range is an estimate and may vary by location, company size, equity, and scope of incident-response responsibility.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Bug bounty program management](https://jobicy.com/jobs?search_keywords=Bug%20bounty%20program%20management.md)[Vulnerability triage](https://jobicy.com/jobs?search_keywords=Vulnerability%20triage.md)[Vulnerability remediation](https://jobicy.com/jobs?search_keywords=Vulnerability%20remediation.md)[Security incident response](https://jobicy.com/jobs?search_keywords=Security%20incident%20response.md)[Application security](https://jobicy.com/jobs?search_keywords=Application%20security.md)[Secure code review](https://jobicy.com/jobs?search_keywords=Secure%20code%20review.md)[JavaScript](https://jobicy.com/jobs?search_keywords=JavaScript.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[Cloud security](https://jobicy.com/jobs?search_keywords=Cloud%20security.md)[Security automation](https://jobicy.com/jobs?search_keywords=Security%20automation.md)

Sample interview questionsHow would you prioritize incoming bug bounty reports across multiple intake channels?I would first validate reproducibility, affected assets, exploitability, user impact, and the presence of compensating controls. I would use a consistent severity framework, de-duplicate related findings, establish clear service-level targets, and escalate credible critical issues immediately to the appropriate security and engineering owners.

Describe how you would turn a recurring vulnerability pattern into a long-term security improvement.

After resolving the immediate issue, I would conduct root-cause analysis to identify the technical and process gaps that allowed it. I would partner with engineering to introduce targeted controls such as secure defaults, automated tests, linting or scanning rules, code-review guidance, and developer education, then track recurrence metrics over time.

How do you maintain productive relationships with external security researchers?

I prioritize respectful, transparent communication, prompt acknowledgements, clear scope and policy documentation, and consistent severity decisions. When a report is not actionable, I explain why with enough technical detail to preserve trust while protecting sensitive information.

What is your approach to reviewing JavaScript or Python during a high-risk investigation?

I start by mapping trust boundaries, data flows, authentication and authorization checks, external inputs, and sensitive operations. I then focus on common high-impact weaknesses such as injection, access-control bypasses, unsafe deserialization, SSRF, secrets exposure, and insecure cloud-service interactions, validating findings through safe reproduction where possible.

How would you measure whether a bug bounty program is improving security outcomes?

I would measure validated-report quality, time to triage, time to remediation by severity, duplicate rate, researcher responsiveness, recurrence of vulnerability classes, and coverage of high-risk assets. I would combine these metrics with qualitative feedback from researchers and internal engineering teams to identify where program changes create meaningful risk reduction.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

* Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
* Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
* Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
* Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
* Identify root causes and systemic issues, and influence long-term improvements in secure development practices
* Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
* Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
* Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

* 3+ years of demonstrated ability in a security engineering role.
* Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
* Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
* Experience analyzing code and systems to move from vulnerability → root cause → prevention
* Real-world experience in software development and/or engineering operations
* Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
* Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
* Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

* Generous performance-based bonus plans to all eligible employees – we share in our success as one team
* Rich medical, dental, and vision coverage
* Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
* Quarterly all-company wellness days where everyone takes a pause together
* Country specific holidays plus a day off for your birthday
* One-time home office stipend
* Annual professional development budget
* Quarterly well-being stipend
* Considerable paid parental leave
* Employee referral bonus program
* Other benefits (life/AD&D, disability, EAP, etc. – varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at [hiringaccommodation@mozilla.com](mailto:hiringaccommodation@mozilla.com) to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R3105

Hiring Ranges:

Remote UK

£66,000—£87,000 GBP

Show more

[Apply now >](https://jobicy.com/jobs/153893-senior-security-engineer-bug-bounty.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Goodleap logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/482c4fb7-221.png)
Goodleap  Sep 22

### [Senior Security Engineer, Product Security](https://jobicy.com/jobs/153887-senior-security-engineer-product-security.md)

About GoodLeap: GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more….

*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 22

### [Threat Detection Analyst (Japanese & English speaking)](https://jobicy.com/jobs/153871-threat-detection-analyst-japanese-english-speaking.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…

*
![Phantom logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/3d0a3a49-221.png)
Phantom  Sep 22

### [Staff Product Security Engineer (Security)](https://jobicy.com/jobs/153861-staff-product-security-engineer-security.md)

Phantom is on a mission to connect the world to the freedom of open markets. Tens of millions of people all over the world use Phantom to access global markets…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Sep 22

### [Security and Infrastructure Engineer](https://jobicy.com/jobs/153866-security-and-infrastructure-engineer.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 21

### [Principal Software Engineer, Infrastructure Security](https://jobicy.com/jobs/153845-principal-software-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 21

### [Principal Security Engineer, Infrastructure Security](https://jobicy.com/jobs/153841-principal-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![DeleteMe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c26c546a-221.png)
DeleteMe  Sep 21

### [Privacy Advisor](https://jobicy.com/jobs/153793-privacy-advisor.md)

DeleteMe is the leader in proactive privacy protection. We help Individuals, Families, Businesses and Security teams reduce their human attack surface by continuously monitoring and removing exposed personal data (PII)…

*
![Oddball logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/02/8c034287ffd7b6474f90645b1c72e60a.jpeg)
Oddball  Sep 21

### [ATO Specialist](https://jobicy.com/jobs/153774-ato-specialist.md)

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a…

*
![DuckDuckGo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/11/ab8415dd5798a360323ce06beaf30c35.png)
DuckDuckGo  Sep 21

### [Senior Web Security Engineer, Browser Platform](https://jobicy.com/jobs/151281-senior-web-security-engineer-browser-platform.md)

Who We Are Hi, we’re DuckDuckGo, the online protection company and remote-first team of 300+ on a mission to raise the standard of trust online. Founded in 2008 and profitable…

*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 20

### [Senior Security Technical Account Manager](https://jobicy.com/jobs/153750-senior-security-technical-account-manager.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…