SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bugcrowd is a crowdsourced security platform that helps organizations manage vulnerability discovery and remediation at scale. Since 2012, the company has built a network of elite security researchers and a data-driven platform to identify and validate security weaknesses across diverse technology landscapes.
As an Application Security Engineer (ASE), you will be responsible for triaging, validating, and managing incoming security vulnerability submissions from Bugcrowd's managed bug bounty programs. You will work with submissions from some of the world's largest companies, gaining exposure to hundreds of different security programs and attack surfaces.
Key responsibilities include:
- Curating and validating incoming vulnerability submissions for accuracy, validity, and severity assessment
- Communicating with Bugcrowd clients and security researchers to gather additional information when needed
- Handling incident response for high-severity vulnerabilities, escalating and communicating critical issues to clients
- Developing deep technical fluency in OWASP Top Ten vulnerability types (XSS, SQLi, XXE, IDOR, SSTI, SSRF, and others)
- Contributing to the design and development of tooling to improve the triage and validation process
- Working across diverse technology domains including web applications, mobile apps, IoT devices, embedded systems, and automotive security
This role offers exceptional learning opportunities. You will be exposed to cutting-edge security testing methodologies from the Internet's best security researchers and work on security programs spanning hundreds of organizations. The position is ideal for security professionals looking to deepen their expertise and take their skills to the next level.
You will report to the Director of Technical Operations and work as part of a collaborative team that values both individual project execution and team contribution.
REQUIREMENTS:
- Bachelor's degree OR previous security consulting experience
- Published and demonstrated passion for security assessment research
- High proficiency with Burp Suite (or equivalent interception proxy)
- Working-level experience with industry standard tools (nmap, sqlmap, Kali Linux tools)
- Strong skill set in at least one scripting/development language
- Ability to execute on individual projects while contributing to team goals
- Ability to complete tasks on time
- Strong organization, influencing, and communication skills