Overview
Security Analyst for Attack Surface Management, validating vulnerability findings and driving them to closure with engineering teams.
What you'll do
- Triages and validates inbound Bugcrowd submissions by reproducing, confirming/rejecting, deduplicating, and determining payout-relevant severity.
- Independently assesses vulnerability impact using factors such as exploitability, asset exposure, data sensitivity, authentication requirements, and existing controls.
- Tracks High and Medium findings from red team engagements/adversary simulations through remediation, including retest and closure verification.
- Evaluates and documents compensating controls when fixes are not immediately viable, with expiry conditions.
- Writes remediation guidance engineers can act on.
- Escalates Critical findings to Incident Response with reproduction detail and blast radius assessment.
- Flags newly surfaced externally exposed attack surface for assessment and maintains visibility into such assets.
What you'll need
- Two or more years in application security, vulnerability management, penetration testing, or bug bounty work.
- Working proficiency in web application and API penetration testing.
- Ability to independently reproduce a submitted finding, escalate undersold findings, and prove false positives.
- Practical knowledge of OWASP Top 10 and OWASP API Security Top 10, including what remediation looks like.
- Familiarity with MITRE ATT&CK techniques and ability to link findings to attacker chaining.
- Hands-on experience with Burp Suite and standard web/API testing tooling.
- Clear written communication.
Nice to have
- Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti.
- Experience triaging submissions from the program side.
- Cloud security exposure across AWS or Azure, especially identity and storage misconfigurations.
- Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT.
- A public bug bounty profile.
- Scripting in Python for reproduction harnesses and finding automation.
Details
Read the full description and apply on the company’s own careers page.