Staff Security Engineer – Product Security

About the role:

The Product Security team is a mission-critical part of Mozilla. We work to safeguard our products and user data, ensure security is built into every stage of the development lifecycle, and respond to security incidents as needed. Our team members work on a variety of security challenges, from architectural reviews and threat models to security tool development and incident response. This role focuses on helping us ensure that products and services across Mozilla are built and operated securely. In this role, you will have an opportunity to make a big impact on security across all of Mozilla’s products and services.

What you’ll do:

  • Conduct security reviews of new and existing products and features, performing threat modeling and risk assessments to identify and mitigate potential security vulnerabilities.
  • Design, implement, and audit security controls and best practices, working closely with engineering teams to integrate security into the CI/CD pipeline and development processes.
  • Participate in the incident response process, analyzing and responding to security incidents to minimize impact and prevent recurrence.
  • Develop and maintain security tools, frameworks, and guidelines to enhance our security posture and enable developers to build secure applications.
  • Mentor junior engineers, fostering a security-first culture within engineering teams through training, documentation, and evangelization efforts.
  • Stay current with the latest security trends, technologies, and threats, continuously improving our security strategies and practices.

What you’ll bring:

  • 8+ years of experience in product security, application security, or a related field.
  • Strong understanding of web security vulnerabilities (e.g., OWASP Top 10, common attack vectors) and practical experience in identifying and mitigating them.
  • Proficiency in one or more programming languages (e.g., Python, Go, Rust) for security tooling, automation, and code review.
  • Experience with cloud security (e.g., AWS, GCP, Azure), including securing cloud-native applications and infrastructure.
  • Familiarity with security architecture, design principles, and common cryptographic protocols.
  • Excellent communication and collaboration skills, with the ability to articulate complex security concepts to both technical and non-technical audiences.
  • Experience with security engineering and operations in a fast-paced environment.
Job Category: N/A
Job Type: Remote
Job Location: USA
Organization: Job Hunting U

Apply for this position

Allowed Type(s): .pdf, .doc, .docx