10 hours ago
Remote, BrazilMid Level
Responsibilities
- Triage and validate incoming vulnerability submissions for Bugcrowd-managed programs.
- Curate submission data for validity, accuracy, and severity.
- Communicate with Bugcrowd clients and security researchers when additional information is needed.
- Handle incident response by escalating and communicating about the highest-severity vulnerabilities.
- Use scripting or development skills to assist with designing and developing triage and validation tooling.
- Execute individual projects while contributing to the broader team.
Requirements
- Bachelor’s degree or previous security consulting experience.
- Published and demonstrated passion for security assessment research.
- High proficiency with Burp Suite or another interception proxy.
- Working-level experience with industry-standard tools such as nmap, sqlmap, or tools included in Kali Linux.
- Strong knowledge of OWASP Top Ten vulnerabilities.
- Strong organization, influencing, communication, and time-management skills.
Benefits
- Fully remote, work-from-home position 100% of the time.
- Exposure to security programs spanning hundreds of companies and technologies including cars, IoT devices, embedded systems, and mobile applications.
- Opportunity to work with leading security researchers and develop expertise across many vulnerability types.
Categories
About Bugcrowd
Bugcrowd builds a crowdsourced security platform used by security teams to run bug bounty, vulnerability disclosure, and penetration testing programs. The service combines SaaS workflow and triage with access to a vetted hacker community, paying researchers per validated finding while customers subscribe to managed programs. Founded in 2012 and headquartered in San Francisco, the privately held company emphasizes AI-driven matching and signal processing to prioritize actionable vulnerabilities.
