> Markdown version of [/jobs/ext/1361587-security-engineer](https://www.wearedevelopers.com/jobs/ext/1361587-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # security engineer - **Company:** Mozilla - **Location:** Latin America, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Amazon Web Services, Bugzilla, Cloud Computing, Code Review, Python (Programming Language), Software Engineering, Software Vulnerability Management, Google Cloud, Heroku, Programming Languages - **Published:** July 21, 2026 - **Apply:** https://www.workingnomads.com/job/go/1741672/ ## About the Role * 3+ years of demonstrated ability in a security engineering role. * Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting * Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.) * Experience analyzing code and systems to move from vulnerability * root cause * prevention * Real-world experience in software development and/or engineering operations * Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required. * Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams. * Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more. ## Description At Mozilla, we believe the internet is a global public resource-open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people's privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. What you'll do: * Own and scale Mozilla's web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement * Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community * Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) * Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes * Identify root causes and systemic issues, and influence long-term improvements in secure development practices * Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews * Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes * Develop or leverage tooling to improve triage efficiency, signal quality, and program insights ## Related Videos - [Explore new web features before everyone else](https://www.wearedevelopers.com/videos/316-explore-new-web-features-before-everyone-else) - [Coffee with Developers - Adam Wiggins](https://www.wearedevelopers.com/videos/919-coffee-with-developers-adam-wiggins) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)