Application Security Engineer
Bugcrowd
We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:
- A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
- As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
- You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
- We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
- Bachelor’s degree or previous security consulting experience
- Published and demonstrated passion for security assessment research
- High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
- Ability to execute on individual projects but still contribute to the team
- Ability to complete tasks on time
- Strong organization, influencing, and communication skills
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at Ver o e-mail no codingjobboard.com.
Culture
- At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
- We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
- Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here: .
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:
- ...manufacturing capacity. Xometry is seeking a Security Engineer - Vulnerability Remediation to join... ...critical role in safeguarding our web applications and services, which are primarily... .... Develop, test and implement secure code solutions to remediate vulnerabilities...Trabalho remoto
- ...exploit real weaknesses, and then engineer automations and agents to... ...at scale, turning offensive security knowledge into defensive engineering... ...things that matter. Pentest applications across our stack, identifying... ...exploitation techniques, and secure coding practices. You can...
- ...public cloud, data science, AI, engineering innovation, and IoT. Our... ...is looking for exceptional security-focused software engineers to... ...exceptional security-focused software engineer, passionate about open... ...your identity, we will give your application fair consideration....
- A Inloco é uma empresa de inteligência que usa dados de localização para tornar aplicativos mais relevantes e seguros para seus usuários. Temos sede em Recife e São Paulo, e nossa empresa-irmã, Incognia, tem escritórios em Palo Alto e Nova Iorque. Atualmente nossa...Trabalho remoto
- ...a skilled & hands-on Senior Security Architect for Kraken Security... ...embedded in the different engineering teams and do not mind hands-... ...blockchain teams, ensuring secure operational practices What... ...with a strong background in application security Experience in security...
- ...public cloud, data science, AI, engineering innovation, and IoT. Our... ...already an outstanding Python engineer. Canonical works across... ...Performance engineering and security experience What we offer... ...identity, we will give your application fair consideration. #LI-remote...
- ...Conscientização: Disseminar a cultura de segurança para toda a companhia. Principais responsabilidades: Experiência sólida em Cyber Security, com foco em segurança de aplicações e nuvem. Familiaridade com frameworks de mercado (OWASP Top 10, NIST, ISO 27001)....
- ...Senior Software Engineer Position: Senior Software Engineer Location: Remote from... ...: Proven experience developing modern applications with a heavy emphasis on backend system... ..., distributed systems architecture, and secure API management. Scale & Platform Reliability...Trabalho remoto
- ...nossas aplicações, APIs e ambientes estejam preparados contra adversários sofisticados. Se você é apaixonado por hacking ético, mobile security e quer atuar em projetos que impactam milhões de pessoas, esta vaga é para você. Responsabilidades e Atribuições: Conduzir...Trabalho remoto
- ...trading backend services such as the matching engine, market data gateways, internal and... ..., develop, and maintain high-quality applications using React Set the standard for high... ...ecosystem ~ Strong experience of API design, security, and performance optimization ~...
- ...results and customer lives? Join our Collection team as a Software Engineer and help shape the future of debt recovery at CloudWalk! You... ...AI tools and models, ready to integrate them into real-world applications. Are Genuinely Curious: Have authentic interest in credit,...
- ...model for creativity. We are seeking an experienced Staff Data Engineer to architect, scale, and operationalize the data systems that... ...We will never ask for personal information, such as your Social Security number, bank account number, or password, through email. If you...
- ...independent team of data & AI experts, engineers, and designers who build... ...products. Whether you are a Senior Engineer, Tech Lead, or DevOps Engineer, you... ...cutting-edge technologies to build secure, high-performance applications. Our Nearform engineers are known for...
- ...Sebastián Mejía (Rappi). Jeeves is looking for a Senior Backend Engineer to join our LATAM engineering team. You will design and build... ...through deployment, monitoring, and iteration. Implement security best practices: authentication, authorization, input validation...
- ...This is a general track for applications to any team at Canonical that works with the Linux... ...here if you are an exceptional software engineer who wants to work on both stable and... ...as possible, with a 10 year enterprise security commitment. The Canonical Linux Kernel...
- ...Job Title Python Engineer – (DevOps/Internal Tools) FULLLY REMOTE Job Description... ...the development of critical APIs and applications. This role requires actual engineering... ...facing APIs and infrastructure tools Security practices and vulnerability prevention...
- ...About Converge Converge fuses cyber insurance security and technology to provide businesses with clear, confident cyber protection... ...In this technical role, you will be part of the Converge Engineering team. You will mange our support queue, develop & maintain Python...Trabalho remoto
- ...redefine Cloud, Network and Data Security. Since 2012, we have built... ...Netskope Cloud Data Plane engineers architect and design one of... ...performance. ~ Knowledge of secure web development practices.... ...opportunities for all employees and applicants for employment. Netskope does...Trabalho remoto
- ...enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's... ...metal to containers. Our goal is to revolutionise open source application and infrastructure operations. We want to transform the world...
- ...Position: Senior Fullstack Engineer Location: Remote from LATAM Contract Type: Full... ...-edge project focused on data-driven applications and scalable architecture. You will join... ...performance. System Integration: Develop secure APIs and integrate various third-party...Trabalho remoto
- ...scalable and resilient CI/CD pipelines for data applications and infrastructure, with a focus on Snowflake,... ...warehouse environments, ensuring optimal performance, security, and cost-effectiveness. Collaborate with data engineers and data scientists to understand their...Trabalho remoto
- ...public cloud, data science, AI, engineering innovation and IoT. Our... ...are an exceptional software engineer who prefers to work in Go. After... ...for you to progress your application based on your personal interests... ...where performance and security are primary considerations....
- ...help finance teams move faster. We're looking for a Senior AI Engineer who is obsessed with building AI systems that actually work in... ...production. ~ Hands-on experience building and deploying LLM-powered applications using APIs such as OpenAI, Anthropic, or Cohere in a...
- ...Solution Engineer – Oracle Database Expert Shape the Future of Cloud Technology with Cintra! Who We Are Cintra is an award... ...AWS, and Google Cloud , we help businesses seamlessly migrate applications and databases to private and public clouds. Our global team operates...
€ 45.000 a € 50.000 por año
...are looking for a highly capable Founding Full Stack Engineer / Technical Lead to work directly with the founders and... ...architecture of the platform as it scales, including application design, infrastructure, security, performance, reliability, and AWS-based cloud decisions...Trabalho remoto- ...are currently looking for a Lead Data Engineer to join our external team in a full-time... ...we will not be moving forward with any applicants who do not meet the following mandatory... ...identity verification due to the end client’s security requirements. Candidates located near...
- ...Year for 2023. The Role We are looking for a Senior Backend Engineer to join our team that owns the end-to-end shopping experience... ...that support every stage of the customer journey. Own the security, reliability, and performance of our backend stack, ensuring a...Trabalho remoto
- ...Full remote THE OPPORTUNITY We are hiring a Software Engineer Manager to our Darwin | CXTech team in Brazil ! The... ...knowledge of React and extensive experience building type-safe applications with TypeScript . Polyglot Backend Mindset: Experience or...Trabalho remoto
- ...zerohash is looking for a Senior Software Engineer to architect and build new features, as... ...meeting the highest standards for security, risk management, and regulatory oversight... ..., WhatsApp, or Telegram. Official Applications: Only apply directly through our careers...Trabalho remoto
- ...API Team designs and develops scalable, secure system architectures and APIs that empower... ...are looking for a Software Development Engineer who will: Develop RESTful APIs and... ...or Go. Integrate APIs with front-end applications and support CI/CD workflows. Review code...Trabalho remoto
Deseja receber mais vagas?
Assine e receba vagas semelhantes a Application Security Engineer. Seja o primeiro a se candidatar!
