Senior Application Security Engineer
M&T BankFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
Candidates must have a minimum of 2 years of professional working experience and 3 years of hands-on security testing or ethical hacking experience on web and mobile applications. A strong technical understanding of OWASP Top 10, comfort using security testing tools like Burp Suite, and experience with frameworks such as CVSS are essential. Proven experience with vulnerability disclosure and bug bounty programs is required, with experience managing a bug bounty program being a plus. Excellent written and verbal communication skills, self-motivation, and the ability to manage time and energy output sustainably are also necessary.
The Product Security Analyst will evaluate assigned vulnerability reports to determine their validity, risk, and severity for HackerOne customers. They will collaborate with hackers to obtain missing information and educate the community on invalid reports. Responsibilities include composing technical summaries for valid reports, detailing impact, reproduction steps, and remediation advice, and ensuring clear communication between hackers and customers. The analyst will also proactively identify and solve issues, respond to delegated work, and assess vulnerability findings against program policies, scope, and impact. Reproducing reported vulnerabilities in a test environment independently is also a key duty.
Platform connecting ethical hackers with brands
HackerOne provides a platform that connects global brands with ethical hackers to improve their cybersecurity. The platform allows companies to identify and monitor risks in their digital assets by utilizing the skills of ethical hackers who conduct penetration tests to find vulnerabilities. Clients can import their asset data and use the platform to rank the risk of exploitable assets, ensuring a proactive approach to application security. Unlike many competitors, HackerOne offers 24/7 security coverage and the ability to scale services based on client needs. The goal of HackerOne is to promote a proactive security culture by encouraging companies to implement bug bounty programs as part of their cybersecurity strategy.