Bugcrowd

Application Security Engineer

Bugcrowd
Apply
11 hours ago
Remote, BrazilMid Level

Responsibilities

  • Triage and validate incoming vulnerability submissions for Bugcrowd-managed programs.
  • Curate submissions for validity, accuracy, and severity.
  • Communicate with clients and security researchers when additional information is needed.
  • Handle incident response by escalating and communicating high-severity vulnerabilities to clients.
  • Use scripting or development skills to help design or develop tools that improve the triage and validation process.

Requirements

  • Bachelor’s degree or previous security consulting experience.
  • Published and demonstrated passion for security assessment research.
  • High proficiency with Burp Suite or another interception proxy.
  • Working-level experience with industry-standard security tools including nmap, sqlmap, or tools included in Kali Linux.
  • Strong knowledge of OWASP Top Ten-type vulnerabilities.
  • Ability to execute individual projects while contributing to a team.
  • Strong organization, influencing, and communication skills, with the ability to complete tasks on time.

Benefits

  • Fully remote, work-from-home position.
  • Exposure to security programs across web applications, mobile applications, cars, IoT devices, and embedded systems.
  • Opportunity to work with security researchers and learn advanced vulnerability testing methodologies.
  • Bugcrowd offers team perks and an inclusive, diverse workplace culture.

Categories

Bugcrowd

About Bugcrowd

1,001-5,000 employees

Bugcrowd builds a crowdsourced security platform used by security teams to run bug bounty, vulnerability disclosure, and penetration testing programs. The service combines SaaS workflow and triage with access to a vetted hacker community, paying researchers per validated finding while customers subscribe to managed programs. Founded in 2012 and headquartered in San Francisco, the privately held company emphasizes AI-driven matching and signal processing to prioritize actionable vulnerabilities.

Contact me