Перейти к основному содержимому
HackerOne

Product Security Analyst

УдалённоUnited States, United Kingdom только
Опубликовано
Роль
Безопасность
Опыт
Мидл
Занятость
Полная занятость
$135k–$155k/yr
Проверьте доступность

Доступно для: US, GB only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Product Security Analyst with 3+ years of hands-on web and mobile application security experience. Must be located within ~50 miles of Boston, Austin, Washington DC, Seattle, or the San Francisco Bay Area (US) and able to work occasional weekend shifts. Needs practical experience with OWASP Top 10, Burp Suite, and CVSS for vulnerability triage and validation.

Ключевые навыки

web application securitymobile application securityvulnerability validation

Обязательные навыки

OWASP Top 10Burp SuiteCVSSVulnerability triage

Желательные навыки

Bug bounty participationscripting or automation used in security testing or operational workflowsexperience reproducing and validating vulnerabilities submitted by external researchers

Обязательные языки

English Fluent

Чем предстоит заниматься

  • Evaluate vulnerability reports submitted by security researchers to determine validity, severity, exploitability, and business impact for HackerOne customers using Data-Driven Decision Making and established security frameworks such as CVSS.
  • Independently reproduce reported vulnerabilities across web and mobile applications, applying First Principles Problem Solving to validate findings, identify root causes, and clearly communicate impact.
  • Collaborate directly with security researchers to gather missing information, clarify technical details, and improve report quality while maintaining clear and professional communication with customers.
  • Create concise, technically accurate summaries for validated findings, including reproduction steps, impact analysis, and remediation guidance.
  • Adapt to evolving customer environments, changing program scopes, emerging attack techniques, and shifting operational priorities.
  • Leverage automation and AI-enabled workflows to improve operational efficiency, report analysis, and vulnerability triage quality.
  • Partner cross-functionally with Technical Services teammates and customer-facing teams to ensure timely handling of vulnerabilities and a high-quality customer experience.
  • Proactively identify opportunities to improve internal processes, documentation, tooling, and triage workflows to enhance scalability and consistency across the Technical Services organization.
  • Work occasional weekend shifts as required.
  • Evaluate vulnerability reports from security researchers for validity, severity, exploitability, and business impact
  • Reproduce reported vulnerabilities across web and mobile applications
  • Validate findings, identify root causes, and communicate impact
  • Collaborate with security researchers to gather missing information and improve report quality
  • Create technical summaries with reproduction steps, impact analysis, and remediation guidance
  • Adapt to changing customer environments, program scopes, attack techniques, and priorities
  • Use automation and AI-enabled workflows to improve report analysis and vulnerability triage quality
  • Partner with Technical Services and customer-facing teams to ensure timely handling of vulnerabilities
  • Improve internal processes, documentation, tooling, and triage workflows
  • Work some weekend shifts

Что требуется

  • 3+ years of hands-on experience performing security testing, vulnerability research, or ethical hacking on web and mobile applications.
  • Strong technical understanding of common application security vulnerabilities, including the OWASP Top 10.
  • Experience using security testing tools such as Burp Suite and familiarity with vulnerability scoring frameworks including CVSS.
  • Excellent written and verbal communication skills in English, including the ability to communicate technical concepts clearly to both technical and non-technical audiences.
  • Ability and desire to work weekend shifts from time to time.
  • Preferred: Experience participating in bug bounty or vulnerability disclosure programs.
  • Preferred: Experience reproducing and validating vulnerabilities submitted by external researchers or customers.
  • Preferred: Familiarity with scripting or automation used in security testing or operational workflows.
  • Preferred: Demonstrated ability to manage competing priorities and maintain operational excellence in a fast-paced, globally distributed environment.
  • 3+ years of hands-on experience performing security testing, vulnerability research, or ethical hacking on web and mobile applications
  • Strong technical understanding of common application security vulnerabilities, including the OWASP Top 10
  • Experience using security testing tools such as Burp Suite
  • Familiarity with vulnerability scoring frameworks including CVSS
  • Excellent written and verbal communication skills in English
  • Ability to communicate technical concepts clearly to technical and non-technical audiences
  • Ability and desire to work weekend shifts from time to time
  • Experience participating in bug bounty or vulnerability disclosure programs is preferred
  • Experience reproducing and validating vulnerabilities submitted by external researchers or customers is preferred
  • Familiarity with scripting or automation used in security testing or operational workflows is preferred
  • Ability to manage competing priorities in a fast-paced, globally distributed environment is preferred

Преимущества

  • Health (medical, vision, dental), life, and disability insurance
  • Equity stock options
  • Retirement plans
  • Paid public holidays and unlimited PTO
  • Paid maternity and parental leave
  • Leaves of absence (including caregiver leave and leave under CO's Healthy Families and Workplaces Act)
  • Employee Assistance Program
  • Health, vision, dental, life, and disability insurance
  • Paid public holidays
  • Unlimited PTO
  • Leaves of absence, including caregiver leave

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with a large community of security researchers to discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems.

Cybersecurityhackerone.com

Детали

Спонсорство визыНет
Также опубликовано ещё в 1 канале
$135k–$155k/yr