12 дней назад
Security Triage Analyst (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Triage Analyst (AI): Validating and classifying vulnerability reports across multi-tenant GPU infrastructure, cloud services, APIs, and management planes with an accent on reproduction, severity assessment, and customer-impact analysis. Focus on applying CVSS in complex cloud environments, distinguishing real vulnerabilities from duplicates and false positives, and turning findings into actionable engineering tickets.
Location: London, UK; hybrid work with 3 days per week in the London office.
Company
is building a full-stack AI cloud spanning data centers, hardware, cloud services, and infrastructure for AI teams.
What you will do
- Review vulnerability reports from researchers, bug bounty and disclosure programs, penetration tests, AI-assisted testing platforms, and internal assessments.
- Validate findings by checking affected assets, reproducing issues safely, and confirming realistic impact in 's environment.
- Classify reports as valid vulnerabilities, duplicates, false positives, accepted risks, out of scope, or requiring more information.
- Assess severity with CVSS and -specific context, including multi-tenancy, customer data, infrastructure access, and privilege boundaries.
- Communicate with researchers, triage partners, vendors, and engineering teams, including handling clarifications, decisions, and appeals.
- Improve triage workflows, report templates, severity rules, duplication logic, metrics, and handling of sensitive vulnerability material.
Requirements
- 5+ years of experience in vulnerability triage, application security, penetration testing, security operations, or a related security role.
- Ability to understand and validate incomplete, unclear, automated, and poorly written technical vulnerability reports.
- Practical knowledge of web application and API security, including authentication, authorization, access control, CORS, rate limiting, SSRF, injection, file handling, and business logic flaws.
- Cloud and infrastructure security knowledge covering network exposure, internal services, storage, identity, Kubernetes, management interfaces, and multi-tenant environments.
- Ability to reproduce findings with Burp Suite, curl, browser developer tools, API clients, logs, and basic scripting.
- Strong judgement, attention to detail, and professional communication when reviewing evidence, duplicates, disputed reports, and appeals.
Nice to have
- Experience operating bug bounty or vulnerability disclosure platforms such as YesWeHack, HackerOne, or Bugcrowd.
- Background with cloud service providers, hosting, infrastructure, or multi-tenant platforms.
- Familiarity with Kubernetes, object storage, IAM, VPNs, APIs, and customer-facing cloud consoles.
- Basic Python, Bash, or other scripting for reproducing issues and automating repetitive triage tasks.
- Experience with AI-assisted security testing or reviewing AI-generated vulnerability reports.
Culture & Benefits
- Full-time, permanent employment.
- Cash and equity compensation with healthcare, lunch, wellbeing, and other benefits.
- Profitable operations with rapid, sustained growth.
- Work alongside engineers, researchers, partners, and colleagues from more than 40 nationalities across the AI ecosystem.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Senior Application Security Architect (AI & API)
5 дней назад
AI Security Engineer
80 000 - 105 000$
5 дней назад
Application Security Engineer (AI)
85 000 - 105 000$
13 дней назад
Security Engineer, Application
77 800 - 117 000$
13 дней назад
Staff+ Software Engineer, Agentic Software Security
200 000 - 300 000$
10 дней назад
Senior Product Security Engineer (AI)
148 000 - 247 000$