Security Analyst, Bug Bounty

Posted 4 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Security Analyst triaging bug bounty vulnerabilities for Stripe’s financial infrastructure platform. Driving researcher engagement, remediation coordination, vulnerability analysis, and bug bounty program improvements.

Responsibilities

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program
  • Communicate with security researchers to clarify reports and increase engagement with top hackers
  • Understand vulnerability root causes and advise product and engineering teams on mitigation strategies
  • Drive submissions through resolution with product and engineering stakeholders
  • Bridge external researchers and internal teams to facilitate rapid remediation
  • Analyze bug-report data and vulnerability patterns to identify systemic risks and inform security initiatives
  • Provide tactical support for vulnerability-management triage processes
  • Implement improvements to the bug bounty program, including researcher campaigns and scoring transparency
  • Provide feedback and requirements for tool development and leverage automation opportunities

Requirements

  • Proven ability to follow bug reports and accurately triage security vulnerabilities
  • Familiarity with web security issues and exploit methodologies, including OWASP Top 10 and CWEs
  • Competence with offensive security tools, such as Burp Suite and custom scripting
  • Ability to think like an attacker to understand vulnerability impact
  • Proficiency in clear communication of technical concepts to various stakeholders
  • Experience in bug bounty programs or triaging security vulnerability reports, or knowledge of Stripe products and general security expertise
  • Preferred: experience in technical support, operations, or similar technical systems roles
  • Preferred: prior participation in or experience with bug bounty programs
  • Preferred: experience analyzing source code for security vulnerabilities
  • Preferred: proficiency in Python or Ruby for automation
  • Preferred: familiarity with AWS or GCP
  • Preferred: OSWA or BSCP certifications

Job type

Full Time

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

AWSGoogle Cloud PlatformPythonRuby

Location requirements

RemoteNorth America

Report this job

Found something wrong with the page? Please let us know by submitting a report below.