
Bugcrowd empowers organizations to stay ahead of threats by uniting the collective ingenuity of elite hackers with our patented data and AI-powered Security Knowledge Platform™. We aim to create a new era of modern crowdsourced security that outpaces threat actors.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE), you will curate and manage incoming security vulnerability submissions for some of the world’s biggest companies’ bug bounty programs.
Working at Bugcrowd offers unique opportunities:
- Work on security programs for potentially hundreds of companies.
- Be exposed to the Internet’s best security researchers and their cutting-edge testing methodologies, quickly becoming technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types.
- Gain exposure to diverse systems, including cars, IoT devices, embedded systems, and mobile applications.
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will:
- Take incoming submission data and curate it for validity, accuracy, and severity.
- Communicate directly with Bugcrowd’s clients or researchers when additional information is required.
- Handle Incident Response, escalating and communicating about the highest severity bugs to clients.
- Assist with the design or development of tooling for improving the triage/validation process, often requiring strong skills in a scripting/development language.
Education, Experience, Skills, & Abilities
- Bachelor’s degree or previous security consulting experience
- Published and demonstrated passion for security assessment research
- High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
- Ability to execute on individual projects but still contribute to the team
- Ability to complete tasks on time
- Strong organization, influencing, and communication skills
- Strong knowledge of OWASP Top Ten type vulnerabilities
Culture
At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work. We value the perspectives and experiences people from underrepresented backgrounds bring.
Timezone overlap
UTC-6–-3
Benefits
Open to
LATAM
Sign in to track applications and earn points.