Staff Security Engineer - Product Security (Remote)
About the Role
Mozilla is hiring a full-time Staff Security Engineer - Product Security to join our dynamic team. This Staff Security Engineer remote position allows you to work from anywhere in the UK, contributing to the security of Mozilla's products and services.
What You'll Do
- Lead security initiatives across product teams, ensuring that security is integrated into the development lifecycle.
- Conduct security assessments and threat modeling for new products and features.
- Collaborate with engineering teams to implement security best practices and mitigate risks.
- Develop and maintain security tools and frameworks to enhance product security.
- Provide guidance and mentorship to junior security engineers and other team members.
Requirements
- 5+ years of experience in security engineering or related field.
- Strong understanding of application security, secure coding practices, and threat modeling.
- Experience with security tools and technologies such as static analysis, dynamic analysis, and penetration testing.
- Knowledge of security frameworks and compliance standards (e.g., OWASP, NIST).
- Excellent communication skills and ability to work collaboratively in a remote environment.
Nice to Have
- Experience with cloud security and DevSecOps practices.
- Familiarity with programming languages such as Python, Java, or JavaScript.
- Certifications such as CISSP, CISM, or CEH.
What We Offer
- Competitive salary range of £81,000 - £108,000 per year.
- Flexible working hours and remote work opportunities.
- Comprehensive health and wellness benefits.
- Professional development and training budget.
- Collaborative and inclusive company culture.
This Staff Security Engineer position at Mozilla offers a competitive salary and the flexibility of remote work. Join a reputable company focused on product security.
Who Will Succeed Here
Proficient in Threat Modeling and Penetration Testing using tools like OWASP ZAP and Burp Suite, with a deep understanding of secure coding practices and application security vulnerabilities.
Self-motivated and disciplined to excel in a fully remote environment, demonstrating strong time management skills and the ability to collaborate effectively with cross-functional teams across different time zones.
Extensive experience (5+ years) in DevSecOps practices, with a mindset focused on integrating security into CI/CD pipelines, leveraging tools such as Jenkins and Docker for secure deployments.
Learning Resources
Career Path
Market Overview
Skills & Requirements
Domain Trends
Industry News
Loading latest industry news...
Finding relevant articles from the last 6 months