Remote job
Application Security Engineer
Job details
About this role
Role overview This role handles triage and validation of vulnerability submissions on a crowdsourced application security platform that runs bug bounty programs for many client organisations. Day-to-day work blends hands-on security analysis with direct communication to clients and external security researchers, performed fully remotely.
Responsibilities - Review incoming vulnerability submissions for validity, accuracy, and severity. - Liaise with clients and researchers to gather additional information or clarification. - Coordinate incident response for the highest-severity findings. - Apply working knowledge of common web and application flaws such as XSS, SQL injection, XXE, IDOR, SSTI, and SSRF. - Build or extend tooling that improves the triage and validation workflow, typically using a scripting or general-purpose language. - Assess a diverse range of targets including web apps, mobile apps, IoT devices, embedded systems, and connected vehicles.
Requirements - Bachelor's degree or equivalent security consulting experience. - Strong proficiency with an interception proxy such as Burp Suite and working familiarity with tools like nmap, sqlmap, and other utilities found in Kali Linux. - Solid understanding of OWASP Top Ten style vulnerability classes. - At least one scripting or development language used to support tooling work. - Clear organisation, communication, and influencing skills, with the ability to deliver solo projects while remaining a team contributor. - Consistent track record of completing tasks on time.
Nice to have - Published security research or other visible demonstrations of passion for offensive security assessment.
Benefits and work setup - 100% remote, work-from-home environment. - Reasonable accommodations available for candidates with disabilities. - Equal opportunity employer with a stated commitment to diversity and inclusion.