Staff Security Engineer, Product Security jobs in United States
cer-icon
Apply on Employer Site
company-logo

Mozilla · 18 hours ago

Staff Security Engineer, Product Security

Mozilla Corporation is a non-profit-backed technology company known for its pioneering brands like Firefox. As a Staff Security Engineer, you'll be responsible for safeguarding user privacy and security by embedding security practices into products and the software development lifecycle.

Browser ExtensionsInternetOpen SourceSoftwareWeb Browsers
check
Comp. & Benefits
check
H1B Sponsor Likelynote

Responsibilities

Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products
Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC)
Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation
Perform security code reviews
Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts
Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early
Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases
Help define and enforce security policies and provide security guidance to development teams
Help shape Mozilla's security culture through collaboration, guidance, and education

Qualification

Application SecuritySecure Coding PracticesThreat ModelingSecurity TestingCI/CD AutomationPythonJavaJavaScriptCollaboration SkillsProblem-Solving Skills

Required

5+ years of relevant hands-on experience in product and application security
5+ years of experience and proficiency in secure coding practices, application security testing (SAST, DAST), threat modeling, and vulnerability assessment
Experience in one or more languages like Python, Go, Java, or JavaScript, required for automation and code review
Familiarity with security tools like Burp Suite, Nessus, and tools for CI/CD automation
Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams
Formal credentials are great, but real-world experience, curiosity, passion and a builder's mindset matter more

Benefits

Generous performance-based bonus plans to all eligible employees - we share in our success as one team
Rich medical, dental, and vision coverage
Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
Quarterly all-company wellness days where everyone takes a pause together
Country specific holidays plus a day off for your birthday
One-time home office stipend
Annual professional development budget
Quarterly well-being stipend
Considerable paid parental leave
Employee referral bonus program
Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

Company

Mozilla provides internet solutions and offers firefox, thunderbird, and raindrop.

H1B Sponsorship

Mozilla has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (2)
2024 (5)
2023 (4)
2022 (3)
2021 (2)
2020 (6)

Funding

Current Stage
Late Stage
Total Funding
$2.3M
Key Investors
AOL
2005-01-01Angel· $0.3M
2003-07-15Series Unknown· $2M

Leadership Team

leader-logo
John Shaughnessy
Manager, Engineering and Ecosystem Strategy
linkedin
Company data provided by crunchbase