We are looking for a Staff Security Engineer to join Mozilla’s Product Security team, whose mission is to make Mozilla products the most secure by default and by design. This includes building security into the DNA of products, consulting with product teams on security concerns, running internal training sessions, developing security infrastructure, and responding to security incidents.
About the role and team
- Build strong relationships with product teams and provide expert security guidance and education throughout the product development lifecycle.
- Perform security assessments including architecture reviews, design reviews, code reviews, and penetration testing against our applications, services, and infrastructure.
- Identify, prioritize, and help resolve security issues across a variety of product areas.
- Develop security tooling, automation, and infrastructure to enhance security capabilities.
- Drive security best practices and secure development processes within engineering teams.
- Participate in the incident response process and contribute to post-mortem analysis.
- Stay current with the latest security threats, vulnerabilities, and technologies and apply this knowledge to improve Mozilla’s security posture.
- Mentor junior security engineers and contribute to the growth of the team.
- Work in close collaboration with external security researchers and manage external security programs such as bug bounties.
What you bring
- 7+ years of professional experience in product security, application security, or a related field.
- Strong understanding of web application security vulnerabilities (OWASP Top 10, etc.) and security best practices.
- Experience with security assessments and penetration testing tools and methodologies.
- Proficiency in one or more programming languages (e.g., Python, JavaScript, Go, Rust, C++).
- Excellent communication, collaboration, and presentation skills.
- Ability to work independently and as part of a distributed team.
- Experience with cloud security (AWS, GCP, Azure) is a plus.
- Experience with incident response and forensics is a plus.
- Experience with open-source projects and communities is a plus.
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
Why Mozilla?
Mozilla is a mission-driven organization dedicated to keeping the internet open and accessible to all. We are committed to building a diverse and inclusive workplace where everyone feels welcome and valued. We offer competitive salaries, excellent benefits, and a flexible work environment.
If you are passionate about security and want to make a real impact, we encourage you to apply!
Mozilla is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.