Назад
Company hidden
12 дней назад

Security Triage Analyst (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Finland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Triage Analyst (AI): Validating and classifying vulnerability reports across multi-tenant GPU infrastructure, cloud services, APIs, and management planes with an accent on reproduction, severity assessment, and customer-impact analysis. Focus on applying CVSS in complex cloud environments, distinguishing real vulnerabilities from duplicates and false positives, and turning findings into actionable engineering tickets.

Location: London, UK; hybrid work with 3 days per week in the London office.

Company

hirify.global is building a full-stack AI cloud spanning data centers, hardware, cloud services, and infrastructure for AI teams.

What you will do

  • Review vulnerability reports from researchers, bug bounty and disclosure programs, penetration tests, AI-assisted testing platforms, and internal assessments.
  • Validate findings by checking affected assets, reproducing issues safely, and confirming realistic impact in hirify.global's environment.
  • Classify reports as valid vulnerabilities, duplicates, false positives, accepted risks, out of scope, or requiring more information.
  • Assess severity with CVSS and hirify.global-specific context, including multi-tenancy, customer data, infrastructure access, and privilege boundaries.
  • Communicate with researchers, triage partners, vendors, and engineering teams, including handling clarifications, decisions, and appeals.
  • Improve triage workflows, report templates, severity rules, duplication logic, metrics, and handling of sensitive vulnerability material.

Requirements

  • 5+ years of experience in vulnerability triage, application security, penetration testing, security operations, or a related security role.
  • Ability to understand and validate incomplete, unclear, automated, and poorly written technical vulnerability reports.
  • Practical knowledge of web application and API security, including authentication, authorization, access control, CORS, rate limiting, SSRF, injection, file handling, and business logic flaws.
  • Cloud and infrastructure security knowledge covering network exposure, internal services, storage, identity, Kubernetes, management interfaces, and multi-tenant environments.
  • Ability to reproduce findings with Burp Suite, curl, browser developer tools, API clients, logs, and basic scripting.
  • Strong judgement, attention to detail, and professional communication when reviewing evidence, duplicates, disputed reports, and appeals.

Nice to have

  • Experience operating bug bounty or vulnerability disclosure platforms such as YesWeHack, HackerOne, or Bugcrowd.
  • Background with cloud service providers, hosting, infrastructure, or multi-tenant platforms.
  • Familiarity with Kubernetes, object storage, IAM, VPNs, APIs, and customer-facing cloud consoles.
  • Basic Python, Bash, or other scripting for reproducing issues and automating repetitive triage tasks.
  • Experience with AI-assisted security testing or reviewing AI-generated vulnerability reports.

Culture & Benefits

  • Full-time, permanent employment.
  • Cash and equity compensation with healthcare, lunch, wellbeing, and other benefits.
  • Profitable operations with rapid, sustained growth.
  • Work alongside engineers, researchers, partners, and colleagues from more than 40 nationalities across the AI ecosystem.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →