Bugcrowd

Application Security Engineer

Bugcrowd
Apply
10 hours ago
Remote, BrazilMid Level

Responsibilities

  • Triage and validate incoming vulnerability submissions for Bugcrowd-managed programs.
  • Curate submission data for validity, accuracy, and severity.
  • Communicate with Bugcrowd clients and security researchers when additional information is needed.
  • Handle incident response by escalating and communicating about the highest-severity vulnerabilities.
  • Use scripting or development skills to assist with designing and developing triage and validation tooling.
  • Execute individual projects while contributing to the broader team.

Requirements

  • Bachelor’s degree or previous security consulting experience.
  • Published and demonstrated passion for security assessment research.
  • High proficiency with Burp Suite or another interception proxy.
  • Working-level experience with industry-standard tools such as nmap, sqlmap, or tools included in Kali Linux.
  • Strong knowledge of OWASP Top Ten vulnerabilities.
  • Strong organization, influencing, communication, and time-management skills.

Benefits

  • Fully remote, work-from-home position 100% of the time.
  • Exposure to security programs spanning hundreds of companies and technologies including cars, IoT devices, embedded systems, and mobile applications.
  • Opportunity to work with leading security researchers and develop expertise across many vulnerability types.

Categories

Bugcrowd

About Bugcrowd

1,001-5,000 employees

Bugcrowd builds a crowdsourced security platform used by security teams to run bug bounty, vulnerability disclosure, and penetration testing programs. The service combines SaaS workflow and triage with access to a vetted hacker community, paying researchers per validated finding while customers subscribe to managed programs. Founded in 2012 and headquartered in San Francisco, the privately held company emphasizes AI-driven matching and signal processing to prioritize actionable vulnerabilities.

Contact me