Security Engineer - Bug Bounty (Remote)
Crowdstrike- Full Time
- Senior (5 to 8 years)
Candidates should have proven experience with vulnerability disclosure and bug bounty, with experience managing a bug bounty program being a plus. They need hands-on experience with security testing or ethical hacking on web and mobile applications, strong technical knowledge of OWASP top 10, and comfort using security testing tools such as Burpsuite. Excellent written and verbal communication skills and experience using frameworks like CVSS are also required, along with self-motivation and the ability to manage time effectively.
The Product Security Analyst will evaluate assigned vulnerability reports to determine validity and risk, collaborate with hackers to gather missing information and educate the community, compose technical summaries for valid reports with clear details and remediation advice, and ensure efficient communication between hackers and customers. They will proactively identify and solve issues, accept delegated work, assess vulnerability findings, independently reproduce reported vulnerabilities, and maintain a consistent operational rhythm.
Platform connecting ethical hackers with brands
HackerOne provides a platform that connects global brands with ethical hackers to improve their cybersecurity. The platform allows companies to identify and monitor risks in their digital assets by utilizing the skills of ethical hackers who conduct penetration tests to find vulnerabilities. Clients can import their asset data and use the platform to rank the risk of exploitable assets, ensuring a proactive approach to application security. Unlike many competitors, HackerOne offers 24/7 security coverage and the ability to scale services based on client needs. The goal of HackerOne is to promote a proactive security culture by encouraging companies to implement bug bounty programs as part of their cybersecurity strategy.