Avatar for Bugcrowd
Bugcrowd
Actively Hiring
When the hackers work for you, you know you're up to date. Manage highly sensitive data with ease
  • 4.1
    Highly rated
    Bugcrowd is highly rated on Glassdoor, with 4.1 out of 5 stars

Security Engineer

Posted: 1 month ago
Visa Sponsorship

Not Available

Hires remotely
Everywhere
RelocationAllowed

About the job

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

The Security Engineer’s role is to aid the security efforts of Bugcrowd, while proactively making changes to further improve our security posture.

To achieve this goal, we require a motivated team member who is willing to push their own boundaries and step out of their comfort zone.You will be challenged on a regular basis, especially because you are the last line of defense for one of the largest crowdsourced security platforms! The Security Engineer will provide mentoring to multiple junior security engineers and will work closely with other team members on a daily basis.

***Please note this role will be working PST business hours*

Essential Duties and Responsibilities

  • Aiding within the Incident Response process
  • Threat hunting
  • Developing patches and security controls within a Ruby on Rails application, Golang application, and Kotlin application
  • Communicating across multiple teams converting technical knowledge into palatable words for multiple audiences.
  • Significant familiarity with AWS and network security controls
  • Identifying vulnerability root causes
  • Performing basic risk assessments and triaging
  • Educating developers on security best practices
  • Architecting solutions with developers to remediate any security concerns
  • Performing basic red team assessments (including but not limited to phishing, vishing, spoofing technologies, etc.)
  • Testing new features within the platform and services
  • Automating security tasks to increase workflow efficiency
  • Mentoring other team members

Education

  • Bachelor's Degree in a relevant field or commensurate experience
  • 3 - 5+ years of professional experience in a similar role or its equivalent.

Knowledge, Skills, and Abilities

  • Experience with writing IR plans and operating within an IR practice (experience responding to incidents)
  • Working knowledge of Threat Intelligence and how it can be used to proactively create security controls (automation)
  • Familiarity with Pentesting techniques and OWASP Top 10
  • Ability to understand a vulnerability and work with developers to patch it
  • Scripting knowledge in at least one of: Bash, Python, JavaScript, Ruby
  • Self motivated and organized - must be able to operate from a calendar and be punctual
  • Cloud security experience or holds cloud certifications (AWS strongly preferred)
  • Experience with Identity and Access Management (IAM) controls
  • Ability to work autonomously within a global company, and critically think without intervention
  • Familiarity with git
  • Familiarity with a ticketing system / issue tracking system is a must (e.g: Jira)

Working Conditions & Physical Requirements

Sitting and / or standing - Must be able to remain in a stationary position 50% of the time

Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement: Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at [email protected].

Pay Range Disclosure: The base pay range for this role takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to Qualifications, Geographical Location, Education/certifications, Experience, Skill Sets, Training, and other business and organizational needs.

A reasonable estimate of the current range for the position of Security Engineer base is: $97,000- $106,000.

This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Apply at: https://www.bugcrowd.com/about/careers/

About the company

Bugcrowd company logo

Bugcrowd

Actively Hiring
When the hackers work for you, you know you're up to date. Manage highly sensitive data with ease201-500 Employees
  • 4.1
    Highly rated
    Bugcrowd is highly rated on Glassdoor, with 4.1 out of 5 stars
Learn more about Bugcrowd image

Funding

AMOUNT RAISED
$78.7M
FUNDED OVER
6 rounds
Rounds
D
$30,000,000
Series D - Apr 2020+5

Perks

Quality Benefits
We’ve got you covered with leading medical, dental, vision, and additional benefits that allow you to continue to be amazing!
Flex Time
We want our employees to stay on top of their game. We give you the flexibility to take time off when you need it, as you need it.
Perks
We enjoy catered meals, and an ample variety of drinks and snacks. We also allow dogs to hang with us in the office.
Events
We’re committed to bringing our people together to celebrate our accomplishments through various team off-sites and Brews & Qs.
Great People
Our people are our greatest asset! And we consider ourselves lucky to be able to join forces with talented, enthusiastic teammates.

Similar Jobs

GVOS  company logo
GVOS
An Edge Cloud for Autonomous Driving
Hive company logo
Hive
Cloud-based AI solutions to understand, search, and generate content
Gridspace company logo
Gridspace
State of the art voice technology and automation for customers, patients, and call centers
Applied Intuition company logo
Applied Intuition
Safely develop, test, and deploy autonomous vehicles at scale
TRM Labs company logo
TRM Labs
Building a safer financial system for billions of people
Roblox company logo
Roblox
Build and share your own multiplayer video games
Custodia Bank company logo
Custodia Bank
Digital asset banking, custody, and payment solutions