3 часа назад
Bug Bounty Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Bug Bounty Analyst (Cybersecurity): Coordinating the assessment, remediation, and retesting of vulnerabilities reported through bug bounty and vulnerability disclosure programs with an accent on CVSS-based severity assessment, stakeholder communication, and security control improvements. Focus on analyzing visibility gaps, tracking remediation across business and security teams, and applying PCI, GDPR, and NIST security frameworks.
Location: Leicester, United Kingdom
Company
provides payment technology and software solutions for buyers, sellers, financial institutions, and cardholders worldwide.
What you will do
- Assess reported vulnerabilities and support severity assignment using the Common Vulnerability Scoring System (CVSS).
- Coordinate triage, remediation, and retesting of findings from bug bounty and vulnerability disclosure programs.
- Communicate vulnerability findings, mitigation plans, and remediation timelines to technical and non-technical stakeholders.
- Work with white-hat researchers, business units, security champions, Risk Management, Legal, and Privacy teams.
- Analyze scanner visibility gaps and missing security controls, then track corrective actions to completion.
- Maintain runbooks and help mature the program by onboarding new assets.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent relevant experience.
- At least 2 years of experience in vulnerability management or bug bounty program operations.
- Knowledge of network operations, engineering, or system administration across Unix, Linux, macOS, or Windows.
- Knowledge of security operations, intrusion detection, SIEM, penetration testing, web application assessment, secure coding, and cloud technologies.
- Understanding of vulnerability assessment, exploit methodologies, and relevant security controls.
- Strong written and verbal communication, attention to detail, facilitation, and independent problem-solving skills.
Nice to have
- Security certifications such as Security+, PenTest+, SSCP, CISM, CISA, CEH, CCSLP, GWEB, eJPT, or OSCP.
- Knowledge of PCI, GDPR, and NIST Cybersecurity Framework compliance programs.
- Experience with ServiceNow or JIRA.
Culture & Benefits
- Work within the Security Operations organization in the payments technology industry.
- Collaborate with teams across multiple lines of business and security functions.
- Support the protection of payment assets and sensitive data at global scale.
- Continue developing knowledge of emerging threats, vulnerabilities, processes, and security technologies.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Vulnerability Manager (Cybersecurity)
14 часов назад
Director, Senior Security Architect (Cloud/Application Security)
5 дней назад
Head of Cyber Security Service Delivery and Advisory (Cybersecurity)
6 дней назад
Vulnerability Management Analyst (Cybersecurity)
3 дня назад
Head of Information Security (Deputy CISO)
7 дней назад