Job Closed

This listing is no longer active.

Mozilla logo
Mozilla

The Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the

Staff Security Engineer, Product Security

Location

Germany

Posted

150 days ago

Salary

€80.7K - €107K / year

Seniority

Lead

5 yrs expEnglishJavaJavaScriptPythonSDLC

Job Description

Staff Security Engineer, Product Security

Mozilla

• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.

Job Requirements

  • 5+ years of relevant hands-on experience in product and application security.
  • 5+ years of experience and proficiency in secure coding practices, application security testing (SAST, DAST), threat modeling, and vulnerability assessment.
  • Experience in one or more languages like Python, Go, Java, or JavaScript, required for automation and code review.
  • Familiarity with security tools like Burp Suite, Nessus, and tools for CI/CD automation.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a builder’s mindset matter more.

Benefits

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Related Categories

Related Job Pages

More Security Engineer Jobs

ActiveFence logo

Security Red Teaming Specialist

ActiveFence

Protect your users. Protect your platform.

Security Engineer150 days ago
OtherRemoteTeam 201-500H1B No Sponsor

• Conduct analysis and testing of generative AI systems • Conduct sophisticated and comprehensive simulated attacks on generative AI models and their operating environments to uncover vulnerabilities. • Evaluate the security posture of AI models and infrastructure, identifying weaknesses and potential threats. • Perform thorough risk analysis to determine the impact of identified vulnerabilities and prioritize mitigation efforts. • Collaborate with development and security teams to develop effective strategies to mitigate identified risks and enhance model resilience. • Stay abreast of the latest trends and developments in AI security, ethical hacking, and cyber threats. • Maintain detailed documentation of all red team activities, findings, and recommendations. • Prepare and present reports to senior management and relevant stakeholders.

United States
Cyderes logo

Security Consultant II, OT/IC

Cyderes

Cyber Defense & Response. It's what we do.

Security Engineer150 days ago
OtherRemoteTeam 501-1,000Since 2020H1B No Sponsor

• Assist in designing and implementing security solutions for client IACS environments, following standards such as ISA/IEC 62443. • Support security maturity assessments and help develop prioritized mitigation plans. • Help identify and remediate vulnerabilities in OT components (PLCs, HMIs, SCADA systems). • Assist in maintaining compliance with regulations (e.g., NERC CIP) and security documentation. • Participate in OT security incident response efforts alongside client engineering, operations, and IT teams. • Contribute to evaluating OT/ICS security technologies (e.g., Claroty, Dragos, Nozomi Networks). • Support pre-sales activities for OT security initiatives. • Stay informed on evolving OT threat landscapes.

United States
Job Closed
Caesars Entertainment Corporation logo

Principal Cloud Security Architect

Caesars Entertainment Corporation

Caesars Entertainment is a public gaming corporation previously known as Harrah’s Entertainment. Caesar’s Entertainment is the fourth largest gaming company

Security Engineer150 days ago

• Develop and enforce secure-by-design principles for cloud-native applications on AWS and GCP. • Embed security into DevSecOps pipelines, ensuring early detection of vulnerabilities (Shift Left). • Architect zero-trust security models for cloud services, APIs, and microservices. • Multi-Cloud Security Engineering & Automation • Lead the deployment of AWS and GCP security services, including GuardDuty, Security Hub, IAM, WAF, Shield, Macie (AWS) and Security Command Center, IAM, and others. • Implement automated security testing in CI/CD pipelines to ensure infrastructure-as-code (IaC) security compliance using Terraform, CloudFormation, and Kubernetes (EKS/GKE). • Drive container security best practices in Kubernetes (EKS/GKE) and serverless security for Lambda and Cloud Functions. • Architect API security frameworks for high-traffic sports betting and gaming applications. • Design and enforce strong authentication, tokenization, and API gateway security. • Deploy advanced AWS WAF, Google Cloud Armor, and API security solutions to detect and mitigate abuse, fraud, and bot traffic. • Enhance cloud-native detection and response capabilities for fraud, arbitrage betting, identity abuse, and payment security. • Implement behavioral analytics and ML-driven security detection to combat fraud, money laundering, and account takeovers. • Work closely with AWS and GCP security teams to enhance cloud-native incident response capabilities. • Ensure cloud security architecture aligns with PCI-DSS, ISO 27001, NIST, and gaming compliance regulations. • Partner with fraud, legal, and compliance teams to enforce AML (Anti-Money Laundering) and KYC (Know Your Customer) security measures. • Automate compliance monitoring across AWS and GCP environments.

United States
Vantage Data Centers logo

Director, Physical Security Delivery

Vantage Data Centers

Experience | Scalability | Efficiency By Design

Security Engineer150 days ago
OtherRemoteTeam 1,001-5,000Since 2010H1B Sponsor

• Provide full accountability for physical security project delivery from project initiation through commissioning, closeout, and transition to operations • Ensure successful execution of new builds, expansions, remediation efforts, and incremental project enhancements • Serve as the senior escalation point for delivery challenges • Partner closely with Physical Security leadership and other internal teams • Lead, manage, and develop a team of Project Managers • Design, implement, and mature standardized delivery frameworks, workflows, and governance models • Translate physical security strategy into executable delivery roadmaps

United States
$175K - $180K / year
Job Closed