SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bugcrowd is a crowdsourced security platform that helps organizations manage vulnerability disclosure and bug bounty programs at scale. Since 2012, the company has built a network of elite security researchers and a data-driven platform to identify and validate security vulnerabilities.
As an Application Security Engineer (ASE), you will be responsible for triaging, validating, and managing incoming security vulnerability submissions from Bugcrowd's managed bug bounty programs. You will work with some of the world's largest companies, handling submissions across diverse attack surfaces including web applications, mobile apps, IoT devices, embedded systems, and automotive security.
Key responsibilities include:
- Curating and validating incoming vulnerability submissions for accuracy, validity, and severity classification
- Communicating with Bugcrowd clients and security researchers to gather additional information when needed
- Handling incident response for high-severity vulnerabilities, escalating and communicating critical findings to clients
- Developing deep technical expertise in OWASP Top Ten vulnerabilities and emerging attack vectors (XSS, SQLi, XXE, IDOR, SSTI, SSRF, and others)
- Contributing to the design and development of tooling to improve the triage and validation process
- Working under the direction of the Director of Technical Operations
This role offers exceptional learning opportunities. You will be exposed to cutting-edge security research methodologies from the Internet's best security researchers and will work across hundreds of different security programs, gaining exposure to diverse technologies and vulnerability types that few other organizations encounter.
The position is fully remote and ideal for security professionals looking to advance their technical expertise and deepen their understanding of real-world vulnerability assessment and management.
REQUIREMENTS:
- Bachelor's degree or equivalent previous security consulting experience
- Published and demonstrated passion for security assessment research
- High proficiency with Burp Suite (or equivalent interception proxy)
- Working-level experience with industry standard security tools (nmap, sqlmap, Kali Linux tools)
- Strong proficiency in at least one scripting or development language
- Ability to execute on individual projects while contributing effectively to team efforts
- Ability to meet deadlines and manage tasks independently
- Strong organizational, communication, and influencing skills