
Application Security Engineer at Bugcrowd
Bugcrowd empowers organizations to stay ahead of threat actors by uniting the collective ingenuity of customers and elite hackers with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers uncovers hidden weaknesses, adapting swiftly to evolving threats, including zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology finds the perfect talent for your unique security challenges. We aim to create a new era of modern crowdsourced security that outpaces threat actors.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE), you will curate and manage incoming security vulnerability submissions for some of the world’s biggest companies’ bug bounty programs.
Why join Bugcrowd as an ASE?
- Broad Exposure: Work on security programs for potentially hundreds of companies, not just one.
- Cutting-Edge Research: Be exposed to the Internet’s best security researchers and their advanced testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types.
- Diverse Systems: You will be exposed to things outside of your comfort zone, routinely running security programs for cars, IoT devices, embedded systems, mobile applications, and more.
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will:
- Take incoming submission data and curate it for validity, accuracy, and severity.
- Communicate directly with Bugcrowd’s clients or researchers when additional information is required.
- Handle Incident Response, escalating and communicating about the highest severity bugs to clients.
ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. This position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
- Bachelor’s degree or previous security consulting experience
- Published and demonstrated passion for security assessment research
- High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
- Ability to execute on individual projects but still contribute to the team
- Ability to complete tasks on time
- Strong organization, influencing, and communication skills
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
- Sitting and/or standing: Must be able to remain in a stationary position 50% of the time.
- Carrying and/or lifting: Must be able to carry/move laptop as needed throughout the work day.
- Environment: Remote, work-from-home 100% of the time.
Culture
At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to ensure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work. Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point. We value the perspectives and experiences people from underrepresented backgrounds bring, believing that solving security threats relevant to everyone takes all kinds of backgrounds.
Timezone overlap
UTC-6–-3
Open to
LATAM
Sign in to track applications and earn points.