
About Bugcrowd
Since 2012, Bugcrowd has been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology finds the perfect talent for every unique fight.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE), you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies' bug bounty programs.
- Work across hundreds of customer security programs
- Exposure to cutting-edge security testing methodologies and deep technical fluency in XSS, SQLi, XXE, IDOR, SSTI, SSRF, and other vulnerability classes
- Broad exposure across cars, IoT devices, embedded systems, mobile applications, and web apps
Essential Duties & Responsibilities
- Triage and validate incoming security vulnerability submissions for Bugcrowd-managed programs
- Curate submission data for validity, accuracy, and severity
- Communicate directly with Bugcrowd clients and security researchers when additional technical information is required
- Handle Incident Response escalations for critical and high-severity vulnerabilities
- Develop tools and scripting to improve the triage and validation lifecycle
Education, Experience, Skills & Abilities
- Bachelor’s degree in Computer Science/related discipline or equivalent security consulting experience
- Published research or demonstrated passion for security assessment research
- High proficiency with Burp Suite (or similar interception proxy) and practical experience with industry standard tools (e.g., nmap, sqlmap, Kali Linux suite)
- Solid working knowledge of the OWASP Top 10 vulnerabilities
- Proficiency in at least one scripting or development language for tooling and automation
- Strong organizational, influencing, and written/verbal communication skills
- Ability to execute on individual projects while contributing effectively to the team
Timezone overlap
UTC+8–+12
Open to
APAC
Sign in to track applications and earn points.