Mozilla

Salary
$137,000–$183,000
Posted
Jul 20, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This role centers on running Mozilla's web bug bounty program — handling researcher relationships, triaging and validating incoming vulnerability reports, and driving remediation with engineering teams. The position also involves collaborating with the incident response team, conducting targeted code reviews in JavaScript and Python, and building tooling to improve program efficiency. It suits a security engineer with hands-on bug bounty or vulnerability management experience.

Mid level · 3+ years · Remote · Full-time

Pay in the description: $116,000–$183,000

Must have (4)
HackerOneAWS, GCP, Azure or HerokuJavaScriptPython
Nice to have (3)
BugzillaGoRust

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 6,900 people nationally plausibly meet what this posting asks for (information security analysts). range 2,900–12,500

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
JavaScript62%Python51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

Compensation is tiered by US geography: Tier 1 $137K–$183K, Tier 2 $126K–$168K, Tier 3 $116K–$155K. The min/max fields reflect the full US range ($116K–$183K).

The role is fully remote (#LI-REMOTE) with no specific metro required.

Bug bounty program experience is listed in the 'What you'll bring' requirements section alongside the 3+ years gate, so it is treated as a hard requirement.

Cloud platform experience (AWS, GCP, Azure, Heroku) is required; the specific platforms are listed as examples, so they are captured as alternatives to each other.

JavaScript and Python are called out explicitly as the primary code-review languages in the requirements section.

Go, Rust, and Bugzilla appear in the requirements section but in a softer context: Go and Rust are listed alongside Python/JavaScript as examples of languages for optional tool-building ('is a plus, but not required'), and Bugzilla appears as an intake channel in the responsibilities narrative rather than a stated requirement.

The posting explicitly states formal credentials (degrees, certifications) are less important than real-world experience, so the degree requirement is set to None.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): bug bounty program management.

This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗