Remote job
Application Security Engineer
Job details
About this role
Role overview Curate and manage incoming vulnerability submissions for large-scale crowdsourced application security programs across web, mobile, IoT, embedded systems, and other targets. The role combines deep technical triage, validation, and incident response with direct communication between security researchers and client stakeholders.
Responsibilities - Triage and validate vulnerability submissions for managed programs, assessing validity, accuracy, and severity. - Communicate directly with clients and researchers to gather additional context and clarify findings. - Handle incident response by escalating and reporting the highest-severity bugs to clients. - Maintain strong working knowledge of OWASP Top Ten vulnerability classes such as XSS, SQLi, XXE, IDOR, SSTI, and SSRF. - Build or extend tooling that improves the triage and validation workflow using at least one scripting or development language. - Contribute to individual projects while supporting broader team objectives and on-time delivery.
Requirements - Bachelor's degree or equivalent previous security consulting experience. - Demonstrated passion for security assessment research, ideally with published work. - High proficiency with Burp Suite or comparable interception proxies and working familiarity with other industry-standard tools such as nmap, sqlmap, and the Kali Linux toolkit. - Strong organizational, influencing, and communication skills. - Ability to execute independently while contributing to a distributed team.
Nice to have - Exposure to a wide range of assessment targets including connected vehicles, IoT devices, and embedded systems.
Benefits and work setup - Fully remote, work-from-home position (100% remote). - Reasonable accommodations available for candidates with disabilities. - Equal opportunity employer committed to a diverse and inclusive workplace.