Security Analyst, Bug Bounty

1 month, 1 week ago
Mid Level
Cybersecurity
Stripe

Stripe

Stripe is a global technology company that provides financial infrastructure for the internet. They offer a suite of APIs and tools for businesses to accept online and in-person payments, automate financial processes, and embed financial services in th...

Diversified Financial Services
5K-10K
Founded 2009
$8700M raised

Description

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate with security researchers to clarify reports, increase engagement, and improve report quality.
  • Investigate the root cause of vulnerabilities and advise product and engineering teams on mitigation strategies.
  • Drive vulnerability submissions through the full resolution lifecycle with internal stakeholders.
  • Act as a bridge between external researchers and internal teams to support rapid remediation.
  • Conduct data analysis on bug reports and vulnerability patterns to identify systemic risks and inform security initiatives.
  • Provide tactical support for vulnerability management triage processes as needed.
  • Improve the overall bug bounty program through continuous enhancements.
  • Provide feedback and requirements for triage tooling and automation to improve security workflows.

Requirements

  • Proven ability to follow bug reports and accurately triage security vulnerabilities.
  • Familiarity with web security issues and exploit methodologies, including OWASP Top 10 and CWEs.
  • Competence with offensive security tools such as Burp Suite and custom scripting.
  • Ability to think like an attacker to assess the impact of vulnerabilities.
  • Strong communication skills with the ability to convey technical concepts to different stakeholders.
  • Experience in bug bounty programs or in triaging security vulnerability reports.
  • Knowledge of Stripe products and general security expertise.
  • Experience in technical support, operations, or similar roles with technical systems exposure (preferred).
  • Prior participation in or experience with bug bounty programs (preferred).
  • Experience analyzing source code for security vulnerabilities (preferred).
  • Proficiency in scripting languages such as Python or Ruby for automation (preferred).
  • Familiarity with cloud-based services such as AWS or GCP (preferred).
  • Certifications such as OSWA or BSCP (preferred).

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Technology Operations Support Analyst

Facet 251-1K Capital Markets

Facet is hiring an IT/Security Operations Analyst to support internal users, manage access and endpoint operations, and help secure the company’s systems in a fast-growing fintech environment.

Cybersecurity JIRA macOS Salesforce
1 day, 22 hours ago

Associate, Vulnerability Assessment

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a Vulnerability Assessment Associate to identify, analyze, and report security vulnerabilities across systems, networks, and applications while supporting remediation and risk reduction efforts for clients.

AWS Azure Bash Cybersecurity GCP HIPAA PowerShell Python SOC
2 days, 22 hours ago

Information Security Analyst

Media.Monks 5K-10K Media

Monks is hiring an Information Security Analyst to protect customer and company data and support the organization’s security and compliance posture across a global business.

AWS Azure Cybersecurity Encryption GCP Linux macOS OpenID Connect SAML
2 days, 22 hours ago

Malware & Abuse Engineer

Kinsta® 251-1K IT Services

Kinsta is hiring a remote Malware & Abuse Engineer to protect its WordPress hosting platform by monitoring, investigating, and remediating malware, spam, abuse, and compliance issues for customers.

CDN DNS JavaScript Linux MariaDB MySQL Nginx PHP WordPress
2 days, 22 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers