Mozilla logo
Mozilla

Feel good about your work again.

Senior Software Engineer, Cryptography

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 501-1,000Since 1998H1B SponsorCompany SiteLinkedIn

Location

Canada

Posted

3 days ago

Salary

$104K - $139K / year

Seniority

Senior

Bachelor DegreeEnglishRust

Job Description

Senior Software Engineer, Cryptography

Mozilla

• Advance Firefox's security architecture and cryptography stack: Contribute to improvements in Firefox's core security systems, with a focus on cryptographic protocols, WebPKI, and security-sensitive web APIs. Help implement and maintain security features that support the evolution of public key infrastructure on the web. • Design and implement web platform security features: Develop and ship web platform features in collaboration with teammates and the broader web community. Contribute to standards-based, secure, and interoperable implementations across Firefox. • Improve browser reliability, performance, and resource efficiency: Investigate and resolve issues impacting stability, correctness, and performance. Analyze and improve memory usage and efficiency within a complex, multi-threaded browser environment. • Collaborate on security initiatives: Partner with engineers across teams to identify, prioritize, and address security issues. Participate in debugging, root cause analysis, and implementation of effective long-term solutions. • Contribute to technical design and planning: Participate in technical discussions, design reviews, and project planning for security-related initiatives. Help evaluate tradeoffs and contribute to engineering decisions within your area of work.

Job Requirements

  • Strong software engineering and security fundamentals: Experience in software engineering, with proficiency in C/C++ and a solid understanding of security principles, including cryptographic protocols and implementations.
  • Experience building and maintaining complex software systems: Ability to contribute to the design, implementation, testing, and maintenance of software in large-scale or security-sensitive environments.
  • Strong debugging and problem-solving skills: Expertise in diagnosing and resolving issues in multi-threaded, cross-platform native applications, including performance and memory-related challenges.
  • Collaborative and effective communicator: Ability to work effectively with distributed teams, communicate technical concepts clearly, and collaborate constructively to solve problems.
  • Growth mindset and willingness to learn: Demonstrated curiosity and desire to deepen expertise in browser security, cryptography, and systems programming while continuously improving engineering skills.
  • Web platform and modern systems experience: Familiarity with web technologies and interest or experience in Rust. Comfortable working within large, complex, multi-language codebases.

Benefits

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Drive the generation services and technologies business to meet or exceed quarterly and annual quota objectives in partnership with the account teams. • Following the Optiv Standardized Sales Operating Processes (SOPs) to achieve consistent success. • Understand and maintain knowledge of the client’s security environment, business operations, security needs, and risk appetite. • Identify their security concerns and how they correlate to Optiv’s strategic solutions across the assigned domains and holistic cybersecurity programs. • Actively participate in the Field Center of Excellence for the assigned domain and position Optiv services and our key technology partners and their products to deliver value to clients. • Identify cross-sell and upsell opportunities across clients and Optiv's partner relationships. • Qualify leads and partner with internal colleagues to determine scope, proposal management, and follow through to closure. • Participate in sales opportunities across Optiv's entire portfolio. • Clearly articulate how the necessary elements of the Optiv technology and services portfolio meet the specific needs of the client stakeholders at the leadership level. • Stay abreast of industry trends, news, and maintain a broad understanding of the security landscape to facilitate thought leadership, support, analysis, and guidance to clients and internal Optiv groups. • Collaborate with service delivery to ensure the team has the necessary supporting domain specialty materials that present a consistent and comprehensive approach. • Effectively work with multiple client personas across the security team, as well as other relevant personas, to develop a security strategy and define roadmaps to execute on the security strategy aligned with business goals, budgetary spend, and metrics based on return of investment. • Maintain advisory relationships with key stakeholders at clients by facilitating thought leadership, support, information, and guidance in conjunction with sales partners. • Maintain strong working relationships with relevant Optiv technology partners, based on client spend and Optiv focus. • Design and solution complete security programs to meet client objectives across technology and services including; facilitating new discussions by leveraging peer and industry network contacts performing requirements gathering analysis, and technology selection criteria coordinating demonstrations and security technology evaluations • Interface and partner with the internal Optiv teams, particularly service delivery liaisons, to align client expectations with the entire Optiv solution portfolio to ensure service delivery excellence and client satisfaction. • Listen for client feedback and continually share with internal teams to evaluate and cultivate continuous improvement. • Participate in account planning, forecasting, and pipeline management activities. • Participate in managing and prioritizing the proposal process to create business proposals, contracts, and respond to RFI/RFP’s. • Actively pursue personal development by maintaining and obtaining technical capabilities, soft skills, and security-specific knowledge through formal education, certification, and other avenues.

Minnesota + 3 moreAll locations: Minnesota | Missouri | Tennessee | Texas
$170K - $230K / year
First Merchants Corporation logo

Security Automation Engineer

First Merchants Corporation

Helping you prosper. Rated One of the Best Places to Work, Top 5 Best Banks in America(Forbes), Best Big Bank(Newsweek).

Full TimeRemoteTeam 1,001-5,000Since 1893H1B No Sponsor

Role Description First Merchants Bank is seeking a Security Automation Engineer to join our team! This position will be responsible for designing, engineering, and governing automated vulnerability remediation execution across the enterprise. This role owns the end-to-end remediation system, including automation, orchestration, validation, and reporting. The role is accountable for transforming remediation from manual, ticket-driven processes into event-driven, automated execution pipelines capable of achieving multi-day remediation timelines for critical vulnerabilities. Working across Cyber, Endpoint, Systems, Network, Cloud, and Application teams, this role establishes standardized remediation playbooks and ensures vulnerabilities are remediated consistently, efficiently, and in alignment with regulatory and operational expectations. - Remediation Automation & Orchestration - Design and implement event-driven automated workflows that leverage AI and scripting to drive remediation across endpoints, servers, networks, applications, and cloud platforms. - Integrate vulnerability scanning tools, ticketing systems, and change management platforms into cohesive, low-friction remediation pipelines. - Reduce manual handoffs and execution variance through automation-first remediation models. - Evaluate and integrate AI-assisted triage and prioritization capabilities to support compressed remediation timelines. - Eliminate manual ticket routing and approval dependencies for pre-approved remediation scenarios. - Enterprise Remediation Playbooks - Create and maintain standardized remediation playbooks by platform and asset class (endpoints, servers, network, cloud, applications). - Define patching, configuration hardening, mitigation, and exception handling paths for each asset class. - Build playbooks that enable autonomous execution without human intervention. - Ensure playbooks account for scenarios where patching cannot meet SLA windows, providing fallback mitigation workflows (containment, isolation, configuration controls) as valid operational alternative(s). - Execution Ownership & Validation - Own remediation tracking, validation scanning, re-scan scheduling, and formal closure across all asset classes. - Partner with execution teams to identify and resolve systemic blockers to remediation. - Partner with Cyber to maintain enterprise-wide visibility into remediation status and proactively escalate aging items. - Risk, Audit & Compliance Support - Produce audit-ready remediation evidence as part of automated workflows. - Ensure exception handling and risk acceptance processes are documented, approved, and time-bound. - Support regulatory and audit requirements (FFIEC, GLBA, PCI-DSS, SOX). - Tooling & Platform Integration - Administer and optimize integrations between vulnerability scanning platforms, ITSM systems, and automation tooling. - Evaluate emerging tools and capabilities to improve remediation velocity, coverage, and automation breadth. - Serve as a subject-matter expert on remediation tooling for IT Operations and Cyber/Information Security teams. - Continuous Improvement & Metrics - Define, track, and report on key remediation KPIs: Mean Time to Remediate (MTTR), SLA compliance rate, backlog aging, and automation coverage. - Identify recurring remediation failures and engineer durable solutions that reduce or eliminate manual intervention. - Present remediation program metrics and maturity updates to IT Operations and Information Security leadership on a regular cadence. Qualifications - High School Diploma or equivalent (GED). - At least five (5) years of experience in infrastructure engineering, security operations, or IT operations within a regulated enterprise environment. - At least two (2) years of experience with API-based integrations, SOAR platforms, automation frameworks, and building and operating automation or orchestration workflows in an enterprise context. - At least two (2) years of hands-on experience with enterprise vulnerability management and scanning platforms (Crowdstrike VM, Tenable.io/Nessus, Qualys, or Rapid7 InsightVM). Requirements - Bachelor’s degree in computer science, security, or a related field (preferred). - Industry certifications: CISSP, CompTIA Security+, CEH, GIAC GPEN, or equivalent (preferred). - Experience evaluating or operating AI-assisted security tooling and an ability to govern AI use in a compliance-sensitive context (preferred). - Previous experience in banking, financial services, or another heavily regulated industry (preferred). - Experience with ITSM and ticketing platforms (preferred). - Proficiency in scripting and automation (Python, PowerShell, Ansible, or equivalent) (preferred). - Strong working knowledge of vulnerability management lifecycles, CVSS scoring, and remediation prioritization strategies (preferred). - Proven ability to influence and coordinate cross-functional teams without direct management authority (preferred). - Excellent written and verbal communication skills (preferred). Benefits - Base Pay - PLUS Bonuses - Medical, Dental and Vision Insurance - 401k - Health Savings and Flexible Spending Accounts - Vacation/Sick Time - Paid Holidays - Paid Parental Leave - Tuition Reimbursement - Additional Benefits Company Description First Merchants is guided by a genuine philosophy of being a meaningful place to work and having a prosperous impact across all walks of life throughout the communities we serve, including consumers, businesses and other organizations. Our Vision, Mission and Team statement reflect and reinforce that authentic service philosophy. - Our Vision: To enhance the financial wellness of the diverse communities we serve. - Our Mission: To be the most responsive, knowledgeable, and high-performing financial organization for our clients, teammates, and shareholders. - Our Team: "We are a collection of dynamic colleagues with diverse experiences and perspectives who share a passion for positively impacting lives. We are genuinely committed to attracting and engaging teammates of diverse backgrounds. We believe in the power of inclusion and belonging." Apply today to begin your career with us!

United States
Lumen Technologies logo

SR INFORMATION SECURITY ENGINEER - Cybersecurity Incident Response

Lumen Technologies

Lumen Technologies is self-described as a global company of 40,000+ professionals empowering businesses, government, and communities to “produce amazing things.” Driven by the

Full TimeRemoteTeam 10,001

Role Description Cybersecurity Incident Response Team (CIRT) Engineers at Lumen are on the front lines of protecting the systems that power global connectivity. In this role, you’ll respond to and mitigate cybersecurity threats while proactively identifying risks and strengthening our defenses. At Lumen, this work goes beyond incident response; it’s an opportunity to solve complex problems, influence how we defend at scale, and help shape the future of our security capabilities. You’ll collaborate with internal teams and partners to drive innovation, improve detection, and anticipate emerging threats in a fast-paced, high-accountability environment. If you’re motivated by challenging work, continuous learning, and the chance to make a real impact, this role offers the flexibility, trust, and support to help you grow while contributing to meaningful outcomes across our infrastructure and services. Location This is a remote position open to candidates based anywhere in the U.S. Main Responsibilities - Shift hours are from 10:00am to 7:00pm Pacific Time. Analyst can be located in any US state. - Respond to, remediate, and document information security incidents not limited to dashboard (Advanced Threat Appliance & SIEM) alerts, tickets, emails, or phone calls. - Actively hunt the enterprise for insecure, suspicious, or malicious activity. - Review data that is processed within the SIEM to find incident evidence and suspicious events as well as out of scope events. - Verify and validate security notifications from both internal and external sources. - Identify and resolve incidents that are not defined by (or deviate from) an existing incident response guide. - Assist with significant incidents as needed or assigned, including outside of normal business hours. - Provide feedback for development and consistency of automated threat detection mechanisms. - Update and maintain response guides for accuracy. - Support Security projects to improve Cyber Defense Team or Lumen's security posture. - Demonstrate effective communication skills, both verbal and written. Qualifications - Bachelor’s in Computer Science, Engineering, or related field (or equivalent experience). - Strong understanding of security fundamentals: host/network hardening, networking protocols, intrusion techniques, and risk management. - Analytical/problem-solving skills across networking, operating systems, and malware analysis. - Relevant certifications (or willingness to obtain): Security+, CEH, OSCP, GCIH, CISSP, GPEN, GWAPT, GISEC, CISM, or CISA. - U.S.-based and able to obtain government suitability. - Strong communication skills; able to present technical concepts to both technical and non-technical audiences. - Experience with cloud security (AWS, Azure, GCP). - Broad knowledge of current and emerging technologies. Preferred Qualifications - 4+ years in incident response, forensics, risk assessments, application or network security. - Experience in network/firewall engineering, design, and implementation. - Familiarity with security tools (SIEM, IDS/IPS, endpoint protection). - Experience monitoring threats and performing initial triage. - Microsoft or UNIX/Linux administration. - Experience implementing controls to reduce risk and data exposure. - Scripting experience (Python or Perl). - Experience in large enterprise or carrier-scale environments. Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. - $84,629 - $112,838 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, WY. - $88,860 - $118,480 in these states: CO, HI, MI, MN, NC, NH, NV, OR, RI. - $93,092 - $124,122 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, WA. Benefits - Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing.

United States
$84.6K - $124.1K / year
Full TimeRemoteTeam 1,001-5,000Since 2025H1B No Sponsor

• Design, execute, and lead end-to-end penetration tests across a wide range of environments • Conduct penetration testing across software-as-a-service and platform-as-a service environments • Perform AI and machine learning application security assessments • Simulate real-world adversarial attack scenarios • Conduct vulnerability assessments, threat modeling, and risk analysis • Develop and maintain custom exploits, scripts, and tooling • Perform social engineering, phishing simulations, and physical security assessments • Architect and build a comprehensive, scalable penetration testing program • Define penetration testing standards, methodologies, playbooks, and reporting templates • Establish key performance indicators and metrics for the program • Serve as the primary point of contact for all internal and external penetration testing engagements • Collaborate with Engineering, DevSecOps, IT, Risk, and Compliance teams • Manage relationships with third-party vendors • Present findings, risks, and remediation strategies to executive leadership

Texas
$168.1K - $210.5K / year