15 часов назад
Bug Bounty Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Bug Bounty Analyst (Cybersecurity): Managing vulnerability findings from bug bounty and vulnerability disclosure programs with an accent on CVSS assessment, remediation coordination, and security control improvements. Focus on analyzing application and infrastructure vulnerabilities, coordinating whitehat researchers and remediation owners, and aligning findings with PCI, GDPR, and NIST security frameworks.
Location: Leicester, United Kingdom
Company
provides payment technology and software solutions for credit, debit, prepaid, and merchant services, supporting millions of companies, financial institutions, and cardholders.
What you will do
- Assess reported vulnerabilities and support severity assignment using the Common Vulnerability Scoring System (CVSS).
- Coordinate findings from bug bounty and vulnerability disclosure programs with whitehat researchers, stakeholders, and remediation owners.
- Develop mitigation plans, track remediation timelines, and coordinate retesting through completion.
- Analyze visibility gaps in vulnerability scanners and identify missing security controls.
- Work with Risk Management, Legal, and Privacy teams when critical data is at risk.
- Maintain runbooks and help mature the program by onboarding new assets.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent relevant experience.
- At least 2 years of experience in vulnerability management or bug bounty program handling.
- Knowledge of network operations, system administration, security operations, intrusion detection, SIEM, penetration testing, web application assessment, secure coding, and cloud technologies.
- Understanding of vulnerability assessment and exploit methodologies.
- Knowledge of security frameworks and regulations including PCI, GDPR, PII, and NIST CSF.
- Strong written and verbal communication, attention to detail, and ability to facilitate resolution-oriented discussions.
Nice to have
- Security certifications such as Security+, PenTest+, SSCP, CISM, CISA, CEH, CCSLP, GWEB, eJPT, or OSCP.
- Experience with ServiceNow or JIRA.
- Knowledge of industry-standard security compliance programs.
Culture & Benefits
- Work within inclusive, global teams focused on collaboration and shared results.
- Access opportunities to learn from experienced security and industry professionals.
- Operate in an environment that values curiosity, innovation, ownership, and continuous improvement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Senior Security Analyst (Cybersecurity)
16 часов назад
Mid-level Cyber Security Analyst - Pentester (Fintech)
13 часов назад
Security Risk Analyst (Cybersecurity)
55 000GBP
5 часов назад
Senior Security Analyst (Cloud Security)
3 часа назад
Application Security Engineer (Cybersecurity)
4 часа назад