Search Remote Jobs

Security Analyst, Bug Bounty

🔥 12 hours ago

🏈 North America – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Stripe

Stripe

1001 - 5000 employees

Founded 2010

💳 Fintech

🛍️ eCommerce

🤝 B2B

💰 Venture Round on 2021-05

Fintech • eCommerce • B2B

Stripe is a global payments processing platform that enables businesses to accept online and in-person payments. It offers a comprehensive suite of financial services, including payment processing, billing, and revenue management tools, aimed at businesses of all sizes, from startups to enterprises. By providing a developer-friendly API, Stripe allows businesses to streamline their payment operations and embed financial services directly into their applications, facilitating both B2B and B2C transactions.

📋 Description

• Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program • Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers • Understand the root cause of security vulnerabilities to help product and engineering teams fix them, and advise on the right mitigation strategies • Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders • Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation • Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives • Provide tactical support for vulnerability management triage processes to augment the team as needed • Prepare and implement improvements to the overall bug bounty program • Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation

🎯 Requirements

• Proven ability to follow bug reports and accurately triage security vulnerabilities • Familiarity with web security issues and exploit methodologies (e.g., OWASP Top 10, CWEs) • Competent in offensive security tools (e.g., Burp Suite, custom scripting) • Ability to think like an attacker to understand the impact of vulnerabilities • Proficient in clear communication, conveying technical concepts to various stakeholders • Experience in one of the following areas • Bug bounty program or triaging security vulnerability reports • Knowledge of Stripe products and general security expertise • Prior participation in or experience with bug bounty programs • Experience analyzing source code for security vulnerabilities • Proficiency in scripting languages (e.g., Python, Ruby) for automation • Familiarity with cloud-based services (e.g., AWS, GCP) • Certifications such as OSWA or BSCP

🏖️ Benefits

• healthcare benefits • flexible work arrangements • professional development opportunities

Apply Now