Назад
Company hidden
3 часа назад

Bug Bounty Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Bug Bounty Analyst (Cybersecurity): Coordinating the assessment, remediation, and retesting of vulnerabilities reported through bug bounty and vulnerability disclosure programs with an accent on CVSS-based severity assessment, stakeholder communication, and security control improvements. Focus on analyzing visibility gaps, tracking remediation across business and security teams, and applying PCI, GDPR, and NIST security frameworks.

Location: Leicester, United Kingdom

Company

hirify.global provides payment technology and software solutions for buyers, sellers, financial institutions, and cardholders worldwide.

What you will do

  • Assess reported vulnerabilities and support severity assignment using the Common Vulnerability Scoring System (CVSS).
  • Coordinate triage, remediation, and retesting of findings from bug bounty and vulnerability disclosure programs.
  • Communicate vulnerability findings, mitigation plans, and remediation timelines to technical and non-technical stakeholders.
  • Work with white-hat researchers, business units, security champions, Risk Management, Legal, and Privacy teams.
  • Analyze scanner visibility gaps and missing security controls, then track corrective actions to completion.
  • Maintain runbooks and help mature the program by onboarding new assets.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent relevant experience.
  • At least 2 years of experience in vulnerability management or bug bounty program operations.
  • Knowledge of network operations, engineering, or system administration across Unix, Linux, macOS, or Windows.
  • Knowledge of security operations, intrusion detection, SIEM, penetration testing, web application assessment, secure coding, and cloud technologies.
  • Understanding of vulnerability assessment, exploit methodologies, and relevant security controls.
  • Strong written and verbal communication, attention to detail, facilitation, and independent problem-solving skills.

Nice to have

  • Security certifications such as Security+, PenTest+, SSCP, CISM, CISA, CEH, CCSLP, GWEB, eJPT, or OSCP.
  • Knowledge of PCI, GDPR, and NIST Cybersecurity Framework compliance programs.
  • Experience with ServiceNow or JIRA.

Culture & Benefits

  • Work within the Security Operations organization in the payments technology industry.
  • Collaborate with teams across multiple lines of business and security functions.
  • Support the protection of payment assets and sensitive data at global scale.
  • Continue developing knowledge of emerging threats, vulnerabilities, processes, and security technologies.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →