Bugcrowd

Bugcrowd

Bugcrowd provides a crowdsourced cybersecurity platform that connects organizations with elite security researchers to enhance security measures through managed bug bounty programs, penetration testing, and vulnerability disclosure initiatives.

Internet Software & Services
1K-5K
Founded 2012
$79M raised

Description

  • Lead, grow, and mentor a geographically distributed team of product security engineers.
  • Set strategy and drive execution for application security, platform security, and FedRAMP programs.
  • Own and evolve the secure development lifecycle, including shift-left security initiatives.
  • Drive architecture reviews, threat modeling, SAST, DAST, continuous end-to-end testing, and advanced fuzzing efforts.
  • Design and launch a Security Foundations program focused on secure-by-default engineering.
  • Develop paved roads and developer guardrails to reduce classes of vulnerabilities across the engineering organization.
  • Own the security roadmap and day-to-day operations of the FedRAMP program.
  • Build strong partnerships with software engineering, DevOps, product management, and operations teams.
  • Drive sustained improvement across complex projects spanning multiple teams and business units.

Requirements

  • 7+ years of experience in cybersecurity with a focus on Product Security, Application Security, or Platform Security.
  • 2+ years of experience directly managing and mentoring security engineers.
  • Demonstrated experience managing complex projects and driving sustained improvement across multiple teams.
  • Excellent communication skills and proven ability to collaborate with engineering, DevOps, product, and operations teams.
  • Deep hands-on experience integrating security into modern CI/CD pipelines.
  • Strong proficiency in threat modeling, architecture reviews, and automated security testing, including SAST, DAST, SCA, and fuzzing.
  • Fluency in one or more modern programming languages such as Python, Go, Ruby, or Java.
  • Strong understanding of cloud-native architectures on AWS, GCP, or Azure.
  • Experience with Kubernetes, Docker, Linux, and Infrastructure as Code such as Terraform.
  • Practical experience supporting compliance requirements such as FedRAMP (preferred), PCI, SOC2, ISO27001, or NIST 800-53.
  • Preferred experience managing, triaging, or participating in bug bounty programs.
  • Preferred background building secure-by-default internal libraries or paved roads.
  • Preferred experience at a fast-paced, high-growth security or SaaS company.

Benefits

  • Base salary range of $176,000 to $242,000.
  • Eligibility for a discretionary bonus program or commission plan.
  • Opportunity to work for a company backed by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
  • Commitment to a collaborative, inclusive workplace culture.
  • Reasonable accommodations provided for candidates and employees with disabilities.
  • Background check process includes standard employment and education verification for applicable roles.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
15 hours, 22 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
16 hours, 7 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 15 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers