Senior Security Engineer

Bugcrowd
Summary
Join Bugcrowd as a Senior Security Engineer and contribute to the organization's security efforts, acting as the last line of defense for a major crowdsourced security platform. You will proactively improve our security posture, working with developers to enhance security controls and architect solutions. This role demands a motivated individual who thrives in a challenging environment, possesses excellent communication skills, and is comfortable mentoring others. The position requires experience in application security testing, incident response, risk management, and penetration testing. You will also be responsible for creating internal security tools and contributing to the continuous improvement of cybersecurity policies and standards. Bugcrowd offers a remote work environment.
Requirements
- 5+ experience in a similar role or its equivalent
- Familiarity with application security testing techniques (can perform a security assessment and code review should they be given a product, identifying weaknesses, ability to document findings, exploit development experience is a bonus)
- Knowledge of OWASP Top 10 and common security vulnerabilities of modern web apps
- Knowledge of Incident Response and operating systems as this role requires responding to incidents within the specified timezone
- Knowledge of threat intelligence
- Ability to understand a vulnerability and work with developers to patch it
- Knowledge and proficiency with coding in at least two of: Python, JavaScript, Ruby, Golang
- Great communicator who is comfortable communicating across multiple teams
- Self motivated, autonomous and organized - must be able to operate from a calendar, be punctual, and being able to manage timelines of projects/tasks for self and others
- Cloud experience (AWS preferred)
- Understanding of Identity and Access Management (IAM)
- Ability to proactively find solutions ie. figure things out for themselves (look at configurations, learn what they mean, document potential solutions to solve the problems)
- Has the ability to be self-sufficient
- Has some prior red teaming knowledge
- Familiarity with git and pull requests is a must
- Familiarity with a ticketing system / issue tracking system is a must (e.g: Notion and Jira)
Responsibilities
- Work with developers to uplift the current security controls and architecting solutions
- Create tools used internally for securing the company, majorly in Python and Golang
- Aid with the process of Incident Response, and security operational activities when required
- Assess the risk behind security issues, and track core metrics
- Perform security assessments of Bugcrowd assets (and vendors)
- Contribute to the continual improvement of the Cybersecurity teamβs policies and standards of practice
Preferred Qualifications
Bachelors Degree in Computer Science, MIS or equivalent experience
Benefits
Remote, work-from-home 100% of the time