Bug Bounty Security Researcher identifying and reporting vulnerabilities in software applications and systems for Inspectiv. Contributing to improving security and participating in bug bounty programs.
Responsibilities
Conduct thorough research on target systems, applications, and networks to identify potential vulnerabilities.
Develop and execute custom attack vectors using various tools and techniques (e.g., fuzzing, SQL injection, Cross-Site Scripting (XSS), Server-Side-Request-Forgery (SSRF), Remote Code Execution).
Identify and exploit vulnerabilities in a responsible manner, ensuring that no harm is caused to the system or data being tested.
Document all findings, including detailed descriptions of discovered vulnerabilities, proof-of-concept code, and steps taken to reproduce the issue.
Participate in regular bug bounty programs and contribute to the improvement of our products and services.
Requirements
1 year of experience in security research, penetration testing, or vulnerability assessment.
Strong understanding of computer systems, networks, and software applications.
Some proficiency with programming languages (e.g., Python, C++, JavaScript, HTML) and offensive security tools (e.g., Burp Suite, OWASP ZAP, Nmap, Kali Linux).
Experience with bug bounty programs and responsible disclosure practices.
Excellent analytical and problem-solving skills.
Strong communication and documentation skills.
Relevant Application Security Certifications: BurpSuite Certified Practitioner (BSCP), Offensive Security Web Expert (OSWE), GIAC Web Application Penetration Tester (GWAPT), Offensive Security Certified Professional (OSCP).
3+ years of experience in security research, penetration testing, or vulnerability assessment.
Has an awarded and recognized public Bug Bounty profile.
Has recognized contributions to Common Vulnerabilities and Exposures (CVEs)
Benefits
Bounty awards for accepted vulnerabilities
Recognition for submitted reports on various leaderboards on and off platform
Experience in performing real-world penetration testing in Web Application, Mobile and Network Security
A collaborative and empathy-led culture that takes security seriously and is on a mission to Secure The Internet
A chance to participate in private, exclusive bug bounty programs
Bilingual Security Agent ensuring the safety of people and property for OPENLANE. Responsibilities include surveillance, access control, and customer service at the facility.
Staff Product Security Engineer ensuring security throughout the product development lifecycle at Affirm. Collaborating closely with product and engineering teams to improve security in financial products.
Agent de projets de sécurité pour l'Administration de la Chambre des communes. Mener des évaluations de sécurité et gérer plusieurs projets partout au Canada.
Information Security Advisor ensuring risk assessment and compliance for Sun Life business groups. Conducting risk assessments and advising on information security best practices.
Senior Hardware Security Engineer at Lime focusing on hardware security architecture and assessments. Collaborate with teams on product security across embedded systems and firmware.
Compliance Manager overseeing compliance processes and frameworks for Data Security Services at Entrust. Ensuring DSS products meet or exceed industry standards and mitigate compliance risks.
Product Security Engineer improving security of Lattice’s applications and services through engineering partnerships and security operations. Contributing to secure coding practices and AI/LLM security assessments.
Presales Security Expert at Fortinet developing secure platform solutions for Major Accounts. Seeking to safeguard people, devices, and data through innovative cybersecurity solutions
IT Security Specialist responsible for day - to - day support of Hudbay’s IT security program and monitoring security risks. Collaborating on various projects to ensure security best practices are followed across the organization.