Security Engineer - Bug Bounty (Remote)
Crowdstrike- Full Time
- Senior (5 to 8 years)
Candidates must have at least 1 year of experience working on vulnerability disclosure and bug bounty programs and 1 year of experience in web application security testing. A basic understanding of web and mobile application security, including familiarity with the OWASP Top 10, is required. Experience using basic security testing tools such as Burpsuite is necessary. Candidates should possess strong attention to detail, excellent written and verbal communication skills, and be self-motivated with a willingness to learn. Decision-making skills are essential, and fluency in English is required. Candidates must be able to work from the HackerOne office in Pune and be available for shift work.
As a Triage Analyst, you will receive and process incoming vulnerability reports, conducting preliminary assessments to identify false positives. You will collaborate with the triage team for smooth handoffs and follow up on additional information from hackers. Maintaining accurate documentation of report intake and initial findings is essential, as is providing clear communication with hackers regarding their submissions. Continuous learning about the latest security trends and validating quick wins in vulnerability assessment will be part of your role.
Platform connecting ethical hackers with brands
HackerOne provides a platform that connects global brands with ethical hackers to improve their cybersecurity. The platform allows companies to identify and monitor risks in their digital assets by utilizing the skills of ethical hackers who conduct penetration tests to find vulnerabilities. Clients can import their asset data and use the platform to rank the risk of exploitable assets, ensuring a proactive approach to application security. Unlike many competitors, HackerOne offers 24/7 security coverage and the ability to scale services based on client needs. The goal of HackerOne is to promote a proactive security culture by encouraging companies to implement bug bounty programs as part of their cybersecurity strategy.