11 hours ago
Remote, BrazilMid Level
Responsibilities
- Triage and validate incoming vulnerability submissions for Bugcrowd-managed programs.
- Curate submissions for validity, accuracy, and severity.
- Communicate with clients and security researchers when additional information is needed.
- Handle incident response by escalating and communicating high-severity vulnerabilities to clients.
- Use scripting or development skills to help design or develop tools that improve the triage and validation process.
Requirements
- Bachelor’s degree or previous security consulting experience.
- Published and demonstrated passion for security assessment research.
- High proficiency with Burp Suite or another interception proxy.
- Working-level experience with industry-standard security tools including nmap, sqlmap, or tools included in Kali Linux.
- Strong knowledge of OWASP Top Ten-type vulnerabilities.
- Ability to execute individual projects while contributing to a team.
- Strong organization, influencing, and communication skills, with the ability to complete tasks on time.
Benefits
- Fully remote, work-from-home position.
- Exposure to security programs across web applications, mobile applications, cars, IoT devices, and embedded systems.
- Opportunity to work with security researchers and learn advanced vulnerability testing methodologies.
- Bugcrowd offers team perks and an inclusive, diverse workplace culture.
Categories
About Bugcrowd
Bugcrowd builds a crowdsourced security platform used by security teams to run bug bounty, vulnerability disclosure, and penetration testing programs. The service combines SaaS workflow and triage with access to a vetted hacker community, paying researchers per validated finding while customers subscribe to managed programs. Founded in 2012 and headquartered in San Francisco, the privately held company emphasizes AI-driven matching and signal processing to prioritize actionable vulnerabilities.
