Назад
Company hidden
4 дня назад

Intermediate Security Analyst (Vulnerability Operations)

115 000 - 150 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Intermediate Security Analyst (Vulnerability Operations) (Cybersecurity): Triaging bug bounty reports and vulnerabilities, coordinating remediation, and supporting CVE assignment and customer-facing security communications with an accent on vulnerability assessment, PSIRT operations, and coordinated disclosure. Focus on validating security findings, reproducing issues, assessing severity, maintaining accurate records, and improving operational runbooks and response workflows.

Location: Remote in Canada or the United States. Candidates across North America are eligible; West Coast US or British Columbia candidates are encouraged to support Pacific Time Zone coverage.

United States base salary: $115,000–$150,000 USD per year. The range applies to US residents and excludes bonuses, equity, and benefits.

Company

hirify.global provides an intelligent orchestration platform for DevSecOps, helping organizations improve developer productivity and software security.

What you will do

  • Triage bug bounty reports by validating findings, assessing impact, identifying duplicates, and routing issues.
  • Manage vulnerabilities through assessment, remediation tracking, closure, and follow-up.
  • Collaborate with PSIRT engineers and development teams to reproduce issues and clarify affected products, versions, and configurations.
  • Support CVE assignment and hirify.global's CVE Numbering Authority operations.
  • Coordinate vulnerability communications with security researchers, customers, Legal, Support, Customer Success, and Communications.
  • Monitor operational metrics and improve runbooks, documentation, procedures, and response workflows.

Requirements

  • Early-career experience or equivalent education in cybersecurity, software engineering, information technology, or a related field.
  • Foundational knowledge of software vulnerabilities, web applications, APIs, CI/CD environments, authentication, and authorization.
  • Familiarity with CVE, CVSS, CWE, OWASP Top 10, and coordinated vulnerability disclosure.
  • Experience with a bug bounty or vulnerability disclosure platform such as HackerOne or Bugcrowd.
  • Strong attention to detail, organization, prioritization, and written and verbal communication skills.
  • Must be eligible to work remotely from Canada or the United States.

Nice to have

  • Basic scripting, log analysis, issue tracking, or data analysis experience.
  • Experience writing technical documentation, customer communications, support responses, or operational procedures.
  • Experience with CVE assignment, CNA processes, security advisories, or vulnerability databases.

Culture & Benefits

  • Fully remote work with collaboration across a globally distributed team.
  • Flexible paid time off.
  • Health, financial, well-being, and parental leave benefits.
  • Equity compensation and an employee stock purchase plan.
  • Growth and development fund.
  • Team member resource groups and a culture of continuous knowledge exchange.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →