Bugcrowd

Bugcrowd

Bugcrowd provides a crowdsourced cybersecurity platform that connects organizations with elite security researchers to enhance security measures through managed bug bounty programs, penetration testing, and vulnerability disclosure initiatives.

Internet Software & Services
1K-5K
Founded 2012
$79M raised

Description

  • Lead, grow, and mentor a geographically distributed team of product security engineers.
  • Set strategy and drive execution for application security, platform security, and FedRAMP programs.
  • Own and evolve the secure development lifecycle, including shift-left security initiatives.
  • Drive architecture reviews, threat modeling, SAST, DAST, continuous end-to-end testing, and advanced fuzzing efforts.
  • Design and launch a Security Foundations program focused on secure-by-default engineering.
  • Develop paved roads and developer guardrails to reduce classes of vulnerabilities across the engineering organization.
  • Own the security roadmap and day-to-day operations of the FedRAMP program.
  • Build strong partnerships with software engineering, DevOps, product management, and operations teams.
  • Drive sustained improvement across complex projects spanning multiple teams and business units.

Requirements

  • 7+ years of experience in cybersecurity with a focus on Product Security, Application Security, or Platform Security.
  • 2+ years of experience directly managing and mentoring security engineers.
  • Demonstrated experience managing complex projects and driving sustained improvement across multiple teams.
  • Excellent communication skills and proven ability to collaborate with engineering, DevOps, product, and operations teams.
  • Deep hands-on experience integrating security into modern CI/CD pipelines.
  • Strong proficiency in threat modeling, architecture reviews, and automated security testing, including SAST, DAST, SCA, and fuzzing.
  • Fluency in one or more modern programming languages such as Python, Go, Ruby, or Java.
  • Strong understanding of cloud-native architectures on AWS, GCP, or Azure.
  • Experience with Kubernetes, Docker, Linux, and Infrastructure as Code such as Terraform.
  • Practical experience supporting compliance requirements such as FedRAMP (preferred), PCI, SOC2, ISO27001, or NIST 800-53.
  • Preferred experience managing, triaging, or participating in bug bounty programs.
  • Preferred background building secure-by-default internal libraries or paved roads.
  • Preferred experience at a fast-paced, high-growth security or SaaS company.

Benefits

  • Base salary range of $176,000 to $242,000.
  • Eligibility for a discretionary bonus program or commission plan.
  • Opportunity to work for a company backed by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
  • Commitment to a collaborative, inclusive workplace culture.
  • Reasonable accommodations provided for candidates and employees with disabilities.
  • Background check process includes standard employment and education verification for applicable roles.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
2 days, 17 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
2 days, 17 hours ago

Lead Application Security Engineer

Remofirst 11-50 Professional Services

RemoFirst is hiring an application and cloud security engineer to secure its global Employer of Record platform, customer identity systems, infrastructure, and emerging AI initiatives across a distributed engineering organization.

AWS Django FastAPI Java Kafka Kubernetes MongoDB OpenID Connect Penetration Testing PostgreSQL Python RabbitMQ REST API SAML Secrets Management Spring Boot Terraform
2 days, 18 hours ago

Off-Cycle Fall 2026 Cybersecurity Internship

Galaxy 251-1K Capital Markets

Galaxy Digital is seeking a remote Cybersecurity Intern for its Product Security team to improve secure engineering standards and develop resources that help software and production engineers apply them effectively.

C++ Cybersecurity Python Rust
5 days, 18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers