Product Security Analyst

HackerOne
Boston, Austin, Washington, Seattle, San Francisco
Workplace: RemoteFull timeUSD 120,000 - 155,000 annuallyFunction: CybersecurityExperience: 3+ yearsSkills: ["Communication","Problem-solving","Collaboration","Written communication"]

Join HackerOne as a Product Security Analyst to validate, reproduce, and communicate security findings across bug bounty and disclosure programs. Work with a global team to deepen expertise in web and mobile application security, leveraging AI-enabled workflows, data-driven decision making, and collaboration with security researchers to deliver high-quality remediation guidance.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
HackerOne
HackerOne
2 months ago

Product Security Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Join HackerOne as a Product Security Analyst to validate, reproduce, and communicate security findings across bug bounty and disclosure programs. Work with a global team to deepen expertise in web and mobile application security, leveraging AI-enabled workflows, data-driven decision making, and collaboration with security researchers to deliver high-quality remediation guidance.
Location: Boston, Austin, Washington, Seattle, San Francisco
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Evaluate vulnerability reports submitted by security researchers to determine validity, severity, exploitability, and business impact for HackerOne customers using data-driven decision making and CVSS.
  • •Independently reproduce reported vulnerabilities across web and mobile applications, applying first principles problem solving to validate findings, identify root causes, and communicate impact.
  • •Collaborate directly with security researchers to gather missing information, clarify technical details, and improve report quality while maintaining clear and professional communication with customers.
  • •Create concise, technically accurate summaries for validated findings, including reproduction steps, impact analysis, and remediation guidance.
  • •Demonstrate Change Agility by adapting to evolving customer environments, changing program scopes, emerging attack techniques, and shifting priorities.

Pay and Benefits

Salary: USD 120,000 - 155,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceEquityRetirementPaid LeaveParital LeaveDisability Insurance

Key Requirements

  • •3+ years of hands-on experience performing security testing, vulnerability research, or ethical hacking on web and mobile applications.
  • •Strong technical understanding of common application security vulnerabilities, including the OWASP Top 10.
  • •Experience using security testing tools such as Burp Suite and familiarity with vulnerability scoring frameworks including CVSS.
  • •Excellent written and verbal communication skills in English, including the ability to communicate technical concepts clearly to both technical and non-technical audiences.
Experience:3+ yearsCybersecuritySecurityCTEMOffensive security
Skills:CommunicationProblem-solvingCollaborationWritten communication
Languages:English
Tech Stack:Burp SuiteCVSSOWASP Top 10

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

HackerOne
Provides a platform for coordinated vulnerability disclosure, bug bounty programs, and continuous threat exposure management by connecting organizations with a global community of security researchers to find and remediate software, cloud, and AI vulnerabilities.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2012
Glassdoor
Glassdoor: 3.9
WebsiteLinkedInGlassdoor