
Application Security Engineer
Bugcrowd
- Location
- India
- Posted
Application Security Engineer at Bugcrowd: Curate and manage security vulnerability submissions for top companies
Bugcrowd
Application Security Engineer at Bugcrowd: Curate and manage security vulnerability submissions for top companies
CoinsPaid
Business System Analyst at CoinsPaid: Design and implement impactful features using their tools, collaborate with passionate colleagues, and shape the future of AI.
Yuno
Senior AI Engineer with LLM expertise needed for payment orchestration platform
360Learning
Lead self-serve business growth strategy, define roadmap, and optimize sales funnel for 360Learning
Cyberhaven
Senior HR Business Partner for global engineering teams, driving people strategies and fostering high-performance culture in a rapidly growing startup.
Stripe
Join Stripe's Product Legal team as a Product Lawyer to advise on payment products, collaborate with cross-functional teams, and ensure regulatory compliance.
CoachHub
Senior HR Business Partner role at CoachHub, a fast-growing, award-winning company
ElevenLabs
Design intuitive marketing pages for voice technology company ElevenLabs, collaborate with global teams, and drive engagement and conversions.
Branch
Join Branch as a data model developer and contribute to empowering workers with financial freedom through accessible and free financial services.
Rocket Money
Join Rocket Money as an Analytics Engineer to build data models that empower users to make informed financial decisions. Collaborate with teams to enable product analytics and use cutting-edge tools like BigQuery, Looker, and DBT.
Kraken
Integrate Kraken's systems with new blockchains, develop secure applications, and protect client funds as a Blockchain Engineer at Kraken. Utilize your expertise in backend development and cryptographic concepts to support crypto operations and ensure high availability and security.
Canonical
Support the Ubuntu community by facilitating technical projects, creating engaging content, and representing Canonical at events. Utilize your expertise in Linux and related technologies to foster collaboration and innovation within the open-source ecosystem.
Sporty Group
Join Sporty Group as an Android Engineer and develop impactful features for their mobile app. Collaborate with cross-functional teams, mentor less experienced team members, and contribute to the company's mission to create value for users.
Red Canary
Join Red Canary as a Sales Engineer and help guide customers through their security journey with our innovative solutions. Use your technical expertise in networking, endpoint security, cloud infrastructure, and scripting to deliver impactful presentations and facilitate proof-of-concepts while collaborating with Account Executives.
Monzo
Senior Finance Business Partner (EU) at Monzo: lead forecasting, drive growth, optimize pricing models
Gurobi Optimization
Field Marketing Manager for APJ region at Gurobi Optimization, driving marketing campaigns and events to support rapid growth in Australia, New Zealand, and India.
Mercury
Senior Risk Investigator role at Mercury Card Fraud team, focusing on transaction monitoring, loss mitigation, and fraud trend identification.
Presto
Business Operations Manager for Flipster, leading strategic partnerships & influencer engagement in cryptocurrency market.
Welocalize
Digital Content Evaluation Specialist - Review high-quality digital content in Australian English for end-users worldwide.
Presto
Business Operations Manager for Flipster, leading strategic partnerships & influencer engagement in cryptocurrency market
Bugcrowd
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE), you will curate and manage incoming security vulnerability submissions to some of the world's biggest companies' bug bounty programs. You will be exposed to cutting-edge security testing methodologies, obscure/complex vulnerabilities, and a variety of industries such as cars, IoT devices, embedded systems, mobile applications, and more. Our team is awesome, with tons of perks, including being selected as one of 'The 10 Coolest Security Startups Of 2016' by crn.com. You will have the opportunity to take your skills to the next level and contribute to groundbreaking projects. With a remote work option, you can thrive in our fast-paced environment. We value strong knowledge of OWASP Top Ten type vulnerabilities, proficiency with industry-standard tools, and excellent communication skills. If you're passionate about security assessment research and want to make a difference, we encourage you to apply.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:
A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.
**Please note we are only considering candidates located in India at this time
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Bachelor’s degree or previous security consulting experience
Published and demonstrated passion for security assessment research
High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
Ability to execute on individual projects but still contribute to the team
Ability to complete tasks on time
Strong organization, influencing, and communication skills
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.