Bug Bounty Security Researcher identifying and reporting vulnerabilities in software applications and systems for Inspectiv. Contributing to improving security and participating in bug bounty programs.
Responsibilities
Conduct thorough research on target systems, applications, and networks to identify potential vulnerabilities.
Develop and execute custom attack vectors using various tools and techniques (e.g., fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side-Request-Forgery (SSRF), Remote Code Execution).
Identify and exploit vulnerabilities in a responsible manner, ensuring that no harm is caused to the system or data being tested.
Document all findings, including detailed descriptions of discovered vulnerabilities, proof-of-concept code, and steps taken to reproduce the issue.
Participate in regular bug bounty programs and contribute to the improvement of our products and services.
Requirements
1 year of experience in security research, penetration testing, or vulnerability assessment.
Strong understanding of computer systems, networks, and software applications.
Some proficiency with programming languages (e.g., Python, C++, JavaScript, HTML) and offensive security tools (e.g., Burp Suite, OWASP ZAP, Nmap, Kali Linux).
Experience with bug bounty programs and responsible disclosure practices.
Excellent analytical and problem-solving skills.
Strong communication and documentation skills.
Relevant Application Security Certifications: BurpSuite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), Offensive Security Certified Professional (OSCP).
3+ years of experience in security research, penetration testing, or vulnerability assessment.
Has an awarded and recognized public Bug Bounty profile.
Has recognized contributions to Common Vulnerabilities and Exposures (CVEs)
Benefits
Bounty awards for accepted vulnerabilities
Recognition for submitted reports on various leaderboards on and off platform
Experience in performing real-world penetration testing in Web Application, Mobile and Network Security
A collaborative and empathy-led culture that takes security seriously and is on a mission to Secure The Internet
A chance to participate in private, exclusive bug bounty programs
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.