Senior Security Engineer, Bug Bounty (Toronto)

Senior Security Engineer, Bug Bounty (Toronto)

04 Aug
|
Mozilla
|
Toronto

04 Aug

Mozilla

Toronto

Senior Security Engineer, Bug Bounty at Mozilla Corporation Team: Infrastructure Locations: Remote UK, Remote US, Remote Canada, Remote Germany To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu.

To learn more about our Hiring Range System, please click this Why Mozilla? Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years.

We make pioneering brands like Firefox, the privacy-minded web browser.

Now, with more than 225 million people around the world using our products each month, were shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies.

Our work focuses on diverse areas including AI, social media, security and more.

And were doing this while never losing our focus on our core mission to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation.

This means we arent beholden to any shareholders only to our mission.

Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role: At Mozilla, we believe the internet is a global public resourceopen and accessible to all.

As a Security Engineer, you''ll protect that vision by building, breaking, and hardening products that put peoples privacy and safety first.





We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What youll do: Own and scale Mozillas web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement Act as the primary interface with external researchers and platforms (e.g., Hacker

One), fostering a high-quality and trusted research community Lead triage and technical validation of incoming reports across multiple intake channels (Hacker

One, Bugzilla, email) Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes Identify root causes and systemic issues, and influence long-term improvements in secure development practices Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews Perform targeted code reviews (primarily Java

Script and Python) during investigations and high-risk changes Develop or leverage tooling to improve triage efficiency, signal quality, and program insights What youll bring:



3+ years of demonstrated ability in a security engineering role.

Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting Practical experience working with modern cloud technologies (eg.

Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) Experience analyzing code and systems to move from vulnerability root cause prevention Real-world experience in software development and/or engineering operations Ability to develop your own tools as needed in a variety of programming languages (eg.

Python, Go, Rust, Javascript, etc.) is a plus, but not required.

Solid communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.

Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What youll get: Generous performance-based bonus plans to all eligible employees - we share in our success as one team Rich medical, dental, and vision coverage Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute) Quarterly all-company wellness days where everyone takes a pause together Country specific holidays plus a day off for your birthday One-time home office stipend Annual professional development budget Quarterly well-being stipend Considerable paid parental leave Employee referral bonus program Other benefits (life/AD&D;, disability, EAP, etc. - varies by country)

📌 Senior Security Engineer, Bug Bounty (Toronto)
🏢 Mozilla
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security engineer, bug bounty (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior security engineer, bug bounty (toronto) / toronto