Security Analyst, Bug Bounty

3 weeks ago
Mid Level
Cybersecurity
Stripe

Stripe

Stripe is a global technology company that provides financial infrastructure for the internet. They offer a suite of APIs and tools for businesses to accept online and in-person payments, automate financial processes, and embed financial services in th...

Diversified Financial Services
5K-10K
Founded 2009
$8700M raised

Description

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate with security researchers to clarify reports, improve report quality, and deepen engagement with top contributors.
  • Determine root causes of vulnerabilities and help product and engineering teams apply effective fixes and mitigations.
  • Drive submissions through the full resolution lifecycle and coordinate with product and engineering stakeholders.
  • Act as a bridge between external researchers and internal teams to support rapid remediation.
  • Conduct data analysis on bug reports and vulnerability patterns to identify systemic risks and guide new security initiatives.
  • Support vulnerability management triage processes as needed to help the team scale.
  • Improve the overall bug bounty program through continuous enhancements such as researcher campaigns and scoring transparency.
  • Provide feedback and requirements for tool development and automation to improve triage and security workflows.

Requirements

  • Proven ability to follow bug reports and accurately triage security vulnerabilities.
  • Familiarity with web security issues and exploit methodologies, including OWASP Top 10 and CWEs.
  • Competence with offensive security tools such as Burp Suite and custom scripting.
  • Ability to think like an attacker to assess the impact of vulnerabilities.
  • Strong communication skills and ability to explain technical concepts to different stakeholders.
  • Experience in bug bounty program work or triaging security vulnerability reports.
  • Knowledge of Stripe products and general security expertise is acceptable as an alternative area of experience.
  • Experience in technical support, operations, or similar roles with technical systems exposure is preferred.
  • Experience analyzing source code for security vulnerabilities is preferred.
  • Proficiency in scripting languages such as Python or Ruby for automation is preferred.
  • Familiarity with cloud-based services such as AWS or GCP is preferred.
  • Certifications such as OSWA or BSCP are preferred.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Sr. Cyber Analyst, Digital Forensics Incident Response

At-Bay 251-1K Insurance

At-Bay is hiring a Digital Forensics and Incident Response (DFIR) team member to support incident investigation, response, and recovery for insured small businesses.

AWS Azure GCP Linux Unix
1 day, 16 hours ago

Cyber Analyst, Digital Forensics Incident Response

At-Bay 251-1K Insurance

At-Bay is hiring a Cybersecurity Analyst focused on digital forensics and incident response to investigate and help recover from security incidents for its insured small-business customers.

AWS Azure Cybersecurity GCP
1 day, 16 hours ago

Manager, Governance, Risk & Compliance

Ultimate Medical Academy is hiring a remote Manager, Governance, Risk & Compliance to lead its institution-wide GRC and information security programs in support of a national higher-education environment.

Cybersecurity HIPAA Network Security Penetration Testing
2 days, 16 hours ago

Sr. Insider & Data Risk Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Senior Insider & Data Risk Analyst to lead insider risk investigations and strengthen data loss prevention and risk management across its global brokerage infrastructure.

AWS Azure Cybersecurity Elasticsearch GCP Python SIEM Splunk SQL
3 days, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers