Security Engineer, Product Security
Chainlink Labs- Full Time 
- Mid-level (3 to 4 years), Senior (5 to 8 years) 
Candidates must have proven experience with vulnerability disclosure and bug bounty programs, along with hands-on experience in security testing or ethical hacking on web and mobile applications. A strong technical understanding of OWASP Top 10, proficiency with security testing tools like Burpsuite, experience using frameworks such as CVSS, and excellent written and verbal communication skills are essential. The role requires fluency in English, self-motivation, time management skills, and the ability to work 4-5 days a week in the Pune office.
The Product Security Analyst will evaluate assigned vulnerability reports to determine validity, risk, and severity for customers. They will collaborate with hackers to gather missing information, educate community members on invalid reports, and compose technical summaries for valid findings, including impact, reproduction steps, and remediation advice. This role involves ensuring clear communication between hackers and customers, proactively identifying and solving issues, and independently reproducing reported vulnerabilities in a test environment.
Platform connecting ethical hackers with brands
HackerOne provides a platform that connects global brands with ethical hackers to improve their cybersecurity. The platform allows companies to identify and monitor risks in their digital assets by utilizing the skills of ethical hackers who conduct penetration tests to find vulnerabilities. Clients can import their asset data and use the platform to rank the risk of exploitable assets, ensuring a proactive approach to application security. Unlike many competitors, HackerOne offers 24/7 security coverage and the ability to scale services based on client needs. The goal of HackerOne is to promote a proactive security culture by encouraging companies to implement bug bounty programs as part of their cybersecurity strategy.