Senior Security Engineer, Bug Bounty
Bangun dan perbaiki keamanan produk Mozilla sebagai Security Engineer
Sebagai Security Engineer di Mozilla, kamu akan memimpin program bug bounty web, bekerja sama dengan tim produk dan SIRT untuk mengurangi risiko insiden keamanan. Kamu akan bertanggung jawab untuk strategi, prioritas, dan peningkatan terus-menerus program ini. Mozilla adalah perusahaan teknologi non-profit yang fokus pada privasi dan keamanan pengguna.
Kenapa Menarik?
Mozilla adalah perusahaan non-profit yang fokus pada privasi dan keamanan pengguna
Tanggung Jawab Utama
- Mengelola dan mengembangkan program bug bounty web Mozilla
- Membuat strategi, prioritas, dan KPI untuk program bug bounty
- Bekerja sama dengan tim produk dan SIRT untuk mengurangi risiko insiden keamanan
- Menjadi titik kontak utama dengan peneliti keamanan eksternal
- Mengidentifikasi dan mengatasi masalah keamanan pada produk Mozilla
Persyaratan
- Pengalaman dalam keamanan web dan program bug bounty
- Kemampuan untuk bekerja sama dengan tim produk dan keamanan
- Pengalaman dalam strategi dan manajemen program
- Kemampuan untuk mengidentifikasi dan mengatasi masalah keamanan
Skills Wajib
Konteks Indonesia
- Overlap Jam Kerja:
- Fleksibel — atur jam kerjamu sendiri
Keywords
Lihat Deskripsi Asli dari Greenhouse Boards
Deskripsi asli dari Greenhouse Boards
<div class="gmail_default" style="font-size: small;"> <div> <div>To learn the Hiring Ranges for this position, please select your location from the <strong>Apply Now</strong> dropdown menu.</div> <p style="text-align: justify; line-height: 1;">To learn more about our Hiring Range System, please click this <a href="https://docs.google.com/document/d/1ylUe7Ou0EbsOtGRBtUv1sSld3lbZ4mrYzo59tEkSjY8/edit?usp=sharing" target="_blank"><span style="text-decoration: underline;"><strong>link.</strong></span></a></p> <p><strong>Why Mozilla?</strong></p> <p><span style="font-weight: 400;">Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people. </span></p> <p><span style="font-weight: 400;">The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms. </span></p> <p><strong>About this team and role:</strong></p> <p><span style="font-weight: 400;">At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you'll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events. </span></p> <p><strong>What you’ll do:</strong></p> <ul> <li style="font-weight: 400;"><span style="font-weight: 400;">Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Identify root causes and systemic issues, and influence long-term improvements in secure development practices</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Develop or leverage tooling to improve triage efficiency, signal quality, and program insights</span></li> </ul> <p><strong>What you’ll bring:</strong></p> <ul> <li style="font-weight: 400;"><span style="font-weight: 400;">3+ years of demonstrated ability in a security engineering role.</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Experience analyzing code and systems to move from vulnerability → root cause → prevention</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Real-world experience in software development and/or engineering operations</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.</span></li> </ul> <p><strong>What you’ll get:</strong></p> <ul> <li style="font-weight: 400;"><span style="font-weight: 400;">Generous performance-based bonus plans to all eligible employees - we share in our success as one team</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Rich medical, dental, and vision coverage</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Quarterly all-company wellness days where everyone takes a pause together</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Country specific holidays plus a day off for your birthday</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">One-time home office stipend</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Annual professional development budget</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Quarterly well-being stipend</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Considerable paid parental leave</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Employee referral bonus program</span></li> <li style="font-weight: 400;"><span style="font-weight: 400;">Other benefits (life/AD&D, disability, EAP, etc. - varies by country)</span></li> </ul> <p><strong>About Mozilla </strong></p> <p>Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.</p> <p><strong>Commitment to diversity, equity, inclusion, and belonging</strong></p> <p>Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientation<span style="color: #003366;">s, </span>gender identities, and expressions.</p> <p>We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at <a class="external-link" href="mailto:hiringaccommodation@mozilla.com">hiringaccommodation@mozilla.com</a> to request accommodation.</p> <p>We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.</p> <p>Group: D</p> <p>#LI-DNI</p> <p>Req ID: R3105</p> </div> </div>
Konteks Gaji
Posisi Engineering serupa di LokerDollar dibayar sekitar $197.5k/yr (kisaran $38.623k–395k/yr, dari 273 listing aktif).
Perekrutan di Mozilla
Mozilla punya 15 lowongan aktif lain di LokerDollar dan telah merekrut di sini sejak 2 Mei 2026 — di kategori Engineering.
Lihat semua lowongan Mozilla →Akun gratis · tanpa kartu kredit · Masuk
Pro Rp39rb/bln · lamar tanpa batas + resume AI
Pertanyaan yang sering diajukan
- Apakah Senior Security Engineer, Bug Bounty di Mozilla bisa dikerjakan remote?
- Ya. Senior Security Engineer, Bug Bounty di Mozilla adalah posisi remote yang terbuka untuk kandidat di seluruh dunia.
- Jenis pekerjaan apa Senior Security Engineer, Bug Bounty di Mozilla?
- Posisi ini adalah pekerjaan full time.
- Bagaimana cara melamar?
- Klik tombol "Lamar" pada halaman ini untuk menuju halaman aplikasi resmi Mozilla.
Jelajahi lebih lanjut
Data & laporan pasar
Riset gaji & permintaan skill dari data lowongan kami sendiri.
- Lowongan IT Indonesia vs Remote Global (2026)Analisis data primer 2.049 lowongan: metodologi, klasifikasi, dataset bisa diunduh.
- Permintaan Skill AI: Indonesia vs Global (2026)10.000+ lowongan, classifier taxonomy-first, Wilson CI, pra-registrasi sebelum analisis.
- Laporan Hiring Indonesia: Tech vs Non-TechPermintaan lowongan per bidang dari hitungan agregat — bukan listing per-listing.
- Benchmark Gaji IndonesiaKisaran gaji agregat lintas peran, dengan metodologi dan dataset terbuka.
- Indeks Gaji & Permintaan Kerja Remote untuk IndonesiaBerapa banyak lowongan remote global yang terbuka untuk Indonesia, dan gajinya (USD) per bidang.
- Laporan Kuartalan Pasar Kerja IndonesiaPHK, pendanaan, gaji & skill per kuartal — agregat terbuka.
- Laporan Pasar Remote per PeranLaporan otomatis per kelompok peran — skill, senioritas, perusahaan, gaji.
- Benchmark Gaji Remote GlobalGaji tahunan per bidang & mata uang, plus porsi lowongan terbuka untuk seluruh dunia.
Dari blog kami
- 10 Remote Jobs Nobody Wants (Yet!)Ada lowongan remote yang sepi pelamar? Kami tunjukkan 10 posisi yang permintaannya tinggi, tapi pasokannya minim – dan kenapa skill-mu mungkin cocok.
- Tren Lowongan Freelance Juni 2026Analisis pasar kerja freelance remote berdasarkan 7 lowongan terbaru di Loker Dollar. Range gaji, contrarian take, dan rekomendasi apply.
- Loker Remote Juli 2026Temukan lowongan kerja remote USD terbaru di Juli 2026 untuk developer, desainer, dan profesional lainnya. Gaji dan tips apply!
Akun gratis · tanpa kartu kredit · Masuk
Pro Rp39rb/bln · lamar tanpa batas + resume AI