Job Closed
This listing is no longer active.
The Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the
Staff Security Engineer
Location
Canada
Posted
95 days ago
Salary
$128K - $171K / year
Seniority
Lead
Job Description
Staff Security Engineer
Mozilla
• Identify and respond to security incidents on a global scale. • Act as an incident commander to drive incidents through the entire response lifecycle. • Design and maintain a portfolio of security alerts, automated actions, playbooks and escalation workflows in support of a high-performing 24/7 incident response capability. • Conduct threat hunting activities, anticipate future threats, and maintain forward-thinking strategies for tools/technology/processes that combat sophisticated threat actors. • Research threat intelligence reports, triage and manage resulting workflows. • Partner with key stakeholders and communicate effectively to maintain a continuously improving feedback loop of preparation, identification, analysis, containment, and post mortem activities. • Participate in on-call rotation.
Job Requirements
- 5+ years of demonstrated ability managing security incidents at a global scale and/or experience working in Security Operations Centers (SOC), Product Security Incident Response Teams (PSIRT), and Computer Security Incident Response Teams (CSIRT).
- Expertise with security information and event management (SIEM) systems (eg. ELK, Google BigQuery, Splunk, etc.). Splunk proficiency is preferred.
- Expertise with integrating and leveraging threat intelligence for detection engineering.
- Expertise with security orchestration and automation (SOAR) platforms such as Tines or Splunk SOAR.
- Superb communication and leadership capacity; ability to partner effectively with diverse company stakeholders.
- Real-world experience in software development and/or engineering operations for consumer products and services; B.S. in a technology-focused field is helpful.
- Practical experience working with cloud technologies (eg. Google Cloud Platform, Amazon Web Services, Heroku, Microsoft Azure, etc.).
Benefits
- Generous performance-based bonus plans to all eligible employees - we share in our success as one team
- Rich medical, dental, and vision coverage
- Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
- Quarterly all-company wellness days where everyone takes a pause together
- Country specific holidays plus a day off for your birthday
- One-time home office stipend
- Annual professional development budget
- Quarterly well-being stipend
- Considerable paid parental leave
- Employee referral bonus program
- Other benefits (life/AD&D, disability, EAP, etc. - varies by country)
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
SIU Investigator
Crum & ForsterCrum & Forster, part of Fairfax Financial Holdings Limited, is an admitted property and casualty insurance company that's been A-rated by A.M. Best. As an emplo
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are seeking an experienced investigator to join our Special Investigations Unit (SIU). SIU is responsible for detecting, investigating and deterring insurance fraud committed against our companies, its policyholders and the insurance industry as a whole. This position offers a flexible workplace location for the right candidate, including with the ability to work largely remotely and/or with a hybrid in-office/remote presence in limited regional offices. - Provide investigative and anti-fraud advisory services across specialty and standard commercial lines insurance products - Conduct comprehensive investigations of questionable insurance claims and policies in compliance with legal and industry standards - Screen and extract source data from claim and policy files - Collaborate with file handlers in development and execution of investigation plans - Conduct and/or case manage claims and policy field investigations that include interviews, recorded statements, and scene investigation - Case manage vended services such as surveillance, activity checks, and medical canvases with a focus on quality, timeliness and cost control - Conduct desk-based investigations ranging from locating individuals to conducting comprehensive and detailed background investigations - Investigations require research, analysis and preservation of web-based OSINT records utilizing sources such as: - Proprietary public record databases - In-depth web presence mining of social media, photo/video sharing websites, business due diligence and news media/archives - County, state & federal repositories for records such as civil/criminal, liens/judgments, vehicle/properties, professional licensing - Claim history via ISO ClaimSearch and related products - National Insurance Crime Bureau (NICB) - Preserve physical and digital evidence - Provide timely communications with file handlers of ongoing investigative activities and case disposition - Prepare professional investigative reports that include detailed findings, supporting documents and recommendations - Develop and maintain network of anti-fraud enforcement/regulatory agency personnel, industry counterparts and law enforcement - Participate in regional anti-fraud industry training and task force meetings - Ensure knowledge and compliance with all anti-fraud regulatory requirements of any assigned territories - Refer and package cases that warrant mandatory reporting to state anti-fraud agencies - Participate in anti-fraud training and marketing for company personnel and customers - Periodic regional travel and an ability to work independently required Qualifications - BS/BA required - 6+ years’ experience as an SIU investigator with either an insurance carrier and/or government anti-fraud agency, in the investigation of property & casualty claims - Prior background in insurance claims and/or law enforcement preferred with a proven record of diligent and proactive anti-fraud efforts - Social media savvy, proficient in searching and preserving digital evidence; particularly using Google, Facebook, X, Instagram, TikTok, YouTube, LinkedIn, and other social/business media platforms - Advanced analytical skills and artificial intelligence awareness - Exceptional organizational and report writing skills - Computer proficient in Microsoft Office applications - Self-starter, high energy and detail oriented; ability to work with minimal supervision - Ability to build strong relationships across all levels of our organization - Credit security clearance, confirmed via a background credit check, is required for this position Benefits - Competitive compensation package - Generous 401K employer match - Employee Stock Purchase plan with employer matching - Generous Paid Time Off - Excellent benefits that go beyond health, dental & vision. Our programs are focused on your whole family’s wellness, including your physical, mental and financial wellbeing - A core C&F tenet is supporting your career development, so we provide a wealth of ways for you to keep learning, which may include tuition reimbursement, industry-related certifications and professional training to keep you progressing on your chosen path - A dynamic, ambitious, fun and exciting work environment - We believe you do well by doing good and want to encourage a spirit of social and community responsibility, matching donation program, volunteer opportunities, and an employee-driven corporate giving program that lets you participate and support your community
Information Security Officer (ISO)
Gainwell TechnologiesGainwell Technologies is an award-winning digital health technology company that supports the administration of healthcare and human services programs. In past flexible hiring, the
Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities. Working at Gainwell carries its rewards. You’ll have an incredible opportunity to grow your career in a company that values work flexibility, learning, and career development. You’ll add to your technical credentials and certifications while enjoying a generous, flexible vacation policy and educational assistance. We also have comprehensive leadership and technical development academies to help build your skills and capabilities. Your role in our mission • Lead Security operational governance activities - Drive security remediation efforts and SLA/SLO adherence • Compliance, operationally focused and security driven • Ensuring delivery excellence in security tooling and business operations (Ensuring avoidance of non-performance / non-compliance leading to contractual penalties). • Relationship management with Gainwell Technologies suppliers and the client. • Presentation skills that invoke confidence and provide clear Gainwell messaging • Create and maintain an account security plan for the selected account(s) and Products • Manage and report security incidents from start to finish • Manage audit preparation, facilitation and remediation • Manage security risks and exceptions • Ensure knowledge and implementation of security fundamentals, policies, and standards (regulatory and contractual) • Escalate and resolve security issues • Coordinate delivery of security metrics and reporting in support of contractual commitment What we're looking for • At least 10 years’ experience working in a risk management, audit, security, or technical delivery role • Bachelor or master’s degree in Computer Science, Computer Studies, Information Security (or equivalent combination of education and experience) • Experience with and understanding of the security and auditing regulations • Experience with audit and compliance programs, including leading audits and remediation efforts • Experience with HIPAA, NIST, MARS-E/ARC-AMPE, and FedRAMP • Excellent and effective communication skills • Ability to work effectively in diverse, multi-national and virtual environments • Self-motivated and tenacious • Demonstrate sound judgment and integrity • Ability to influence delivery personnel in the execution of security and compliance requirements • Experience as a Security consultant, architect and/or engineer • Experience in working with security management including information governance and compliance • Deep understanding and working knowledge of information security industry best practices with hands on experience • Experience of security processes and standards, in particular NIST 800-53 and/or ISO27001 • Knowledge of security audit and accreditation processes • Ability to adapt to new security regimes. • CALIFORNIA ONLY: SIMM and SAM working compliance experience What you should expect in this role - Remote position (California only) - Opportunities to travel through your work (0-10%) - Video cameras must be used during all interviews, as well as during the initial week of orientation - The deadline to submit applications for this posting is 3/30/2026 The pay range for this position is $121,700.00 - $173,800.00 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You’ll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a 401(k) employer match, comprehensive health benefits, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities. We believe nothing is impossible when you bring together people who care deeply about making healthcare work better for everyone. Build your career with Gainwell, an industry leader. You’ll be joining a company where collaboration, innovation, and inclusion fuel our growth. Learn more about Gainwell at our company website and visit our Careers site for all available job role openings. Gainwell Technologies is an Equal Opportunity Employer, where all qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical condition), age, sexual orientation, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Gainwell Technologies defines “wages” and “wage rates” to include “all forms of pay, including, but not limited to, salary, overtime pay, bonuses, stock, stock options, profit sharing and bonus plans, life insurance, vacation and holiday pay, cleaning or gasoline allowances, hotel accommodations, reimbursement for travel expenses, and benefits.
• Independently perform all aspects of the security controls assessment in alignment with NIST 800-53 Revision 5 • Ensure comprehensive understanding and application of ATO documentation requirements • Coordinate all aspects of testing with relevant stakeholders and team lead • Develop a security assessment plan with input from stakeholders • Conduct and lead assessment interviews and tests while managing evidence • Provide insightful recommendations to improve security posture
Security Architect
EmpowerWe are an equal opportunity employer with a commitment to diversity. All individuals, regardless of personal characteristics, are encouraged to apply. All qualified applicants will receive consideration for employment without regard to age, race, color, national origin, ancestry, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, religion, physical or mental disability, military or veteran status, genetic information, or any other status protected by applicable state or local law.
• Partner with business and technology teams to define security designs that meet security requirements and enable business objectives. • Create, maintain, and document security architectures and design patterns for use by technology teams. • Develop relationships, repeatable processes, and resources to establish security champions across the company. • Perform threat modeling as needed to substantiate recommendations and designs. • Participate in the development and maintenance of security policies, standards, and reference materials. • Review and contribute to infrastructure-as-code representations of architecture changes and designs.




