Remote job
Intermediate Security Analyst
Job details
About this role
Role overview An intermediate-level security analyst role embedded in a product security vulnerability operations function. The position focuses on protecting customers by triaging vulnerability reports, coordinating response workflows, and ensuring clear communication between external researchers and internal engineering teams. It is well suited to someone early in their cybersecurity career who enjoys investigative and coordination work.
Responsibilities - Review incoming bug bounty submissions, assess report quality, validate findings, and estimate potential impact. - De-duplicate reports and route them to the correct internal teams. - Triage vulnerabilities surfaced through ongoing vulnerability management activities and track them through to closure. - Partner with product security incident response engineers and developers to reproduce issues and clarify affected products, versions, and configurations. - Help produce clear status updates and written summaries for stakeholders.
Requirements - Early-career experience in cybersecurity or equivalent formal education in the field. - Strong written communication skills for drafting technical summaries and external-facing messages. - Analytical mindset with attention to detail when reviewing vulnerability reports. - Comfort working with engineers to reproduce and characterize software defects.
Nice to have - Familiarity with bug bounty platforms, CVSS scoring, or coordinated disclosure practices. - Exposure to web application security concepts such as OWASP Top 10 issues.