Application Security Engineer II

Bugcrowd
Brazil
Workplace: RemoteFull timeFunction: CybersecurityEducation: bachelorsSkills: ["Organization","Communication","Influencing","Execution","Time management"]

Curate and manage incoming vulnerability submissions for Bugcrowd’s managed bug bounty programs, validating severity and accuracy and escalating high-impact issues through incident response. Work closely with clients and security researchers to request additional details and improve triage quality. Apply strong knowledge of OWASP Top Ten vulnerability classes and use tools like Burp Suite (or interception proxies) plus utilities from Kali Linux to support efficient triage and tooling development.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Bugcrowd
Bugcrowd
1 day ago

Application Security Engineer II

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Curate and manage incoming vulnerability submissions for Bugcrowd’s managed bug bounty programs, validating severity and accuracy and escalating high-impact issues through incident response. Work closely with clients and security researchers to request additional details and improve triage quality. Apply strong knowledge of OWASP Top Ten vulnerability classes and use tools like Burp Suite (or interception proxies) plus utilities from Kali Linux to support efficient triage and tooling development.
Location: Brazil
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Perform ongoing triage and validation for Bugcrowd managed security programs.
  • •Curate incoming submission data for validity, accuracy, and severity.
  • •Communicate directly with Bugcrowd’s clients or researchers to request additional information.
  • •Handle incident response by escalating and communicating highest severity bugs.
  • •Support triage/validation tooling through strong scripting/development skills.

Key Requirements

  • •Bachelor’s degree or previous security consulting experience.
  • •Published and demonstrated passion for security assessment research.
  • •High proficiency with Burp Suite (or another interception proxy) and working experience with tools such as nmap and sqlmap (from Kali Linux or similar).
  • •Strong knowledge of OWASP Top Ten–type vulnerabilities.
  • •Ability to complete individual projects on time while still contributing to the team.
Education:Bachelor's
Skills:OrganizationCommunicationInfluencingExecutionTime management
Languages:English
Tech Stack:Burp SuiteOWASP Top TenXSSSQLiXXEIDORSSTISSRFNmapSqlmapKali Linux

Company Brief

Bugcrowd
Provides a crowdsourced security platform offering bug bounty programs, vulnerability disclosure, and managed security testing to help organizations find and remediate security weaknesses through a global community of security researchers.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn