
Application Security Engineer II – Contract, 6 months
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Oversee and manage incoming security vulnerability reports for Bugcrowd-administered bug bounty initiatives.
• Assess and validate submissions for authenticity, precision, and severity level.
• Engage directly with clients or researchers when further information is needed.
• Manage incident response by escalating and communicating about critical bugs to clients.
• Utilize extensive knowledge of OWASP Top Ten vulnerabilities.
• Support the design or development of tools to enhance the triage and validation workflow.
• Operate under the guidance of the Director of Technical Operations.
• A Bachelor’s degree or prior experience in security consulting.
• Published work and a proven enthusiasm for security assessment research.
• High level of proficiency with Burp Suite or similar interception proxies.
• Hands-on experience with industry-standard tools like nmap, sqlmap, and tools available in Kali Linux.
• Comprehensive understanding of OWASP Top Ten vulnerabilities.
• Strong capabilities in at least one scripting or programming language.
• Ability to manage individual projects while also collaborating effectively with the team.
• Capacity to meet deadlines consistently.
• Excellent organizational, influencing, and communication skills.
• Capability to fulfill all physical requirements with or without reasonable accommodations.
• Must be able to remain in a stationary position for 50% of the time.
• Must be able to transport or move a laptop as necessary throughout the workday.
• Applicants must have the integrity to keep confidential information secure.
• Background checks may encompass Social Security verification, prior employment verification, references, educational verification, and criminal history.
• Gain exposure to security programs for numerous companies and a variety of technologies.
• Interact with Internet security researchers and advanced security testing methodologies.
• Access learning opportunities across various vulnerability types including XSS, SQLi, XXE, IDOR, SSTI, SSRF, and more.
• Experience security programs related to vehicles, IoT devices, embedded systems, mobile applications, and additional areas.
• Reasonable accommodations available for qualified individuals with disabilities.
Nord Security
PowerSchool
PowerSchool
Thermal Scientific Works
Get handpicked remote jobs straight to your inbox weekly.