Search Remote Jobs

Security Analyst, Bug Bounty

Job not on LinkedIn

🔥 8 minutes ago

🏈 North America – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Stripe

Stripe

1001 - 5000 employees

Founded 2010

💳 Fintech

🛍️ eCommerce

🤝 B2B

💰 Venture Round on 2021-05

Fintech • eCommerce • B2B

Stripe is a global payments processing platform that enables businesses to accept online and in-person payments. It offers a comprehensive suite of financial services, including payment processing, billing, and revenue management tools, aimed at businesses of all sizes, from startups to enterprises. By providing a developer-friendly API, Stripe allows businesses to streamline their payment operations and embed financial services directly into their applications, facilitating both B2B and B2C transactions.

📋 Description

• Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program. • Communicate clearly and effectively with security researchers to follow up on unclear reports, drive report clarity, and increase engagement with top hackers. • Understand the root cause of security vulnerabilities to help product and engineering teams fix them, and advise on the right mitigation strategies. • Drive the lifecycle of submissions through to resolution, coordinating with product and engineering stakeholders. • Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation. • Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives. • Provide tactical support for vulnerability management triage processes to augment the team as needed. • Prepare and implement improvements to the overall bug bounty program. • Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation.

🎯 Requirements

• Proven ability to follow bug reports, reproduce, and accurately triage security vulnerabilities. • Deep familiarity with web security issues, attack vectors, and exploit methodologies (e.g., OWASP Top 10, CWEs, CVEs). • Competent in offensive security tools to reproduce issues (e.g., Burp Suite, Nuclei, custom scripting). • Ability to think like an attacker to understand the impact of vulnerabilities. • Proficient in clear and concise written and verbal communication, with the ability to convey complex technical concepts to both technical and non-technical stakeholders. • Experience in one of the following areas: • Direct experience in a bug bounty program or triaging security vulnerability reports. • Direct, deep knowledge of Stripe products and assets, coupled with strong general security knowledge.

🏖️ Benefits

• Competitive salary • Health insurance • Retirement plans • Professional development opportunities

Apply Now