Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Analyst (Bug Bounty): Managing the end-to-end lifecycle of security vulnerability reports and researcher engagement with an accent on triage, root cause analysis, and program optimization. Focus on bridging the gap between external security researchers and internal engineering teams to drive rapid remediation and systemic security improvements.
Location: Remote (North America/LATAM)
Company
Stripe is a global financial infrastructure platform for businesses, dedicated to increasing the GDP of the internet.
What you will do
- Analyze, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
- Communicate effectively with security researchers to drive report clarity and engagement.
- Identify root causes of vulnerabilities and advise product teams on mitigation strategies.
- Coordinate the full lifecycle of submissions through to resolution with internal stakeholders.
- Conduct data analysis on vulnerability patterns to identify systemic risks.
- Implement improvements to the bug bounty program and contribute to security workflow automation.
Requirements
- Proven ability to accurately triage security vulnerabilities.
- Familiarity with web security issues and exploit methodologies like OWASP Top 10.
- Competence in offensive security tools such as Burp Suite and custom scripting.
- Ability to think like an attacker to assess vulnerability impact.
- Experience in bug bounty programs or security vulnerability triaging.
- Proficiency in clear technical communication with diverse stakeholders.
Nice to have
- Experience analyzing source code for security vulnerabilities.
- Proficiency in scripting languages like Python or Ruby for automation.
- Familiarity with cloud-based services such as AWS or GCP.
- Relevant certifications such as OSWA or BSCP.
Culture & Benefits
- Opportunity to work on critical security infrastructure for a global financial platform.
- Collaborative environment focused on continuous security excellence.
- Autonomy to implement improvements to security programs and workflows.
- Exposure to large-scale, complex financial systems and security challenges.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →