3 hours ago
San José, Costa RicaMid Level
Responsibilities
- Partner with engineering to refine architecture, validate features, and drive security investment.
- Build secure defaults, internal libraries, and paved roads that eliminate classes of vulnerabilities.
- Tune SAST, DAST, SCA, and secret-scanning tooling to reduce noise and improve security feedback.
- Use Bugcrowd’s bug bounty program as a customer model and provide feedback on platform features.
- Lead cross-functional product-security projects from scoping through delivery and influence engineering and product roadmaps.
- Build code and automation that scales security coverage and reduces repetitive work.
- Communicate security risks clearly to technical and non-technical stakeholders.
Requirements
- At least 3 years of experience in product security, application security, or secure software development.
- Ability to review code, automate tasks, and build security tooling in at least one modern programming language such as Python, Go, Ruby, or Java.
- Hands-on experience with threat modeling, secure code review, automated testing, SAST, DAST, and SCA.
- Solid understanding of common vulnerability classes, including the OWASP Top 10.
- Ability to manage projects and influence partners across engineering, DevOps, and product.
- Bachelor’s degree in engineering, computer science, or a relevant field, or equivalent practical experience.
- Preferred experience with bug bounty or vulnerability disclosure programs.
- Preferred experience building secure-by-default internal libraries and paved roads.
- Preferred experience securing cloud-native platforms and infrastructure as code, including Terraform, AWS, GCP, Kubernetes, or Docker.
- Experience in a fast-paced, high-growth security or SaaS company is preferred.
Benefits
- The position is remote and work-from-home 100% of the time.
- Reasonable accommodations are available for qualified individuals with disabilities.
- Employment background checks may be conducted for this position.
Categories
About Bugcrowd
Bugcrowd builds a crowdsourced security platform used by security teams to run bug bounty, vulnerability disclosure, and penetration testing programs. The service combines SaaS workflow and triage with access to a vetted hacker community, paying researchers per validated finding while customers subscribe to managed programs. Founded in 2012 and headquartered in San Francisco, the privately held company emphasizes AI-driven matching and signal processing to prioritize actionable vulnerabilities.
