Feel good about your work again.
Senior Security Engineer, Bug Bounty
Location
Germany
Posted
2 days ago
Salary
€68K - €91K / year
Seniority
Senior
Job Description
Senior Security Engineer, Bug Bounty
Mozilla
• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
Job Requirements
- 3+ years of demonstrated ability in a security engineering role.
- Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
- Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
- Experience analyzing code and systems to move from vulnerability → root cause → prevention
- Real-world experience in software development and/or engineering operations
- Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
- Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
- Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.
Benefits
- Generous performance-based bonus plans to all eligible employees - we share in our success as one team
- Rich medical, dental, and vision coverage
- Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
- Quarterly all-company wellness days where everyone takes a pause together
- Country specific holidays plus a day off for your birthday
- One-time home office stipend
- Annual professional development budget
- Quarterly well-being stipend
- Considerable paid parental leave
- Employee referral bonus program
- Other benefits (life/AD&D, disability, EAP, etc. - varies by country)
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights
• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering
• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering
• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering

