SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 120,000 - 155,000 / annual
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM), combining AI-powered platform capabilities with the world's largest community of security researchers. The company helps enterprises discover, validate, prioritize, and remediate security exposures across code, cloud, and AI systems through bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security solutions.
As a Product Security Analyst in the Technical Services organization, you will evaluate vulnerability reports submitted by security researchers, determine their validity, severity, exploitability, and business impact using established frameworks like CVSS. You will independently reproduce reported vulnerabilities across web and mobile applications to validate findings, identify root causes, and communicate impact clearly. You'll collaborate directly with security researchers to gather missing information and improve report quality while maintaining professional communication with customers.
Key responsibilities include creating technically accurate summaries for validated findings with reproduction steps and remediation guidance, adapting to evolving customer environments and emerging attack techniques, and leveraging automation and AI-enabled workflows to improve operational efficiency. You will partner cross-functionally with Technical Services teammates and customer-facing teams to ensure timely vulnerability handling and high-quality customer experience. You'll also proactively identify opportunities to improve internal processes, documentation, tooling, and triage workflows.
Note: This role requires working weekend shifts with compensatory weekday time off.
REQUIREMENTS:
Minimum Qualifications:
- 3+ years of hands-on experience performing security testing, vulnerability research, or ethical hacking on web and mobile applications
- Strong technical understanding of common application security vulnerabilities, including OWASP Top 10
- Experience using security testing tools such as Burp Suite
- Familiarity with vulnerability scoring frameworks including CVSS
- Excellent written and verbal communication skills in English, including ability to communicate technical concepts to both technical and non-technical audiences
- Ability and willingness to work weekend shifts
Preferred Qualifications:
- Experience participating in bug bounty or vulnerability disclosure programs
- Experience reproducing and validating vulnerabilities submitted by external researchers or customers
- Familiarity with scripting or automation used in security testing or operational workflows
- Demonstrated ability to manage competing priorities and maintain operational excellence in fast-paced, globally distributed environment